This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

25 instances of rundll32.exe & 13 of svchost.exe Processes Running

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My windows vista computer that is about two years old is running very slow due to their being so many instances of rundll32.exe (25 as of right now) and svchost.exe (13 as of right now) processes running. Please help and thanks so much in advance!

Here's my HijackThis! log file:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:32:18 PM, on 6/20/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\MHotKey.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\CNYHKey.exe
C:\Program Files (x86)\DocuSign Print Driver\DocuSignExpress.exe
C:\Program Files (x86)\DocuSign Professional\DocuSign.DSPro.Spooler.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Windows\SysWOW64\WDBtnMgr.exe
C:\Program Files (x86)\Common Files\Research in Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files (x86)\Portrait Displays\Pivot Software\floater.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Windows\ModLedKey.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Windows\ChiFuncExt.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\AustinGood\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ntreis.marketlinx.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [LchDrvKey] LchDrvKey.exe
O4 - HKLM\..\Run: [LedKey] CNYHKey.exe
O4 - HKLM\..\Run: [Smart Copy] "C:\Program Files (x86)\IOI\Smart Copy\ButtonMonitor.exe" -A
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT GWY] "C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe" -GWY
O4 - HKLM\..\Run: [BrStsWnd] "C:\Program Files (x86)\Brownie\BrstsW64.exe" Autorun
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files (x86)\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=1800
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [EPSON WorkForce 500 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEQA.EXE /FU "C:\Users\AUSTIN~1\AppData\Local\Temp\E_S445A.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [\\MAC-LAPTOP\Epson Workforce 500 - On the Study PC] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEQA.EXE /FU "C:\Windows\TEMP\E_SDAB8.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [cdloader] "C:\Users\AustinGood\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\AustinGood\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [googletalk] C:\Users\AustinGood\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: DisplayKEY eSYNC Info.lnk = C:\Program Files (x86)\GE Security Supra\SyncInfoApp.exe
O4 - Global Startup: DocuSign Print Driver.lnk = C:\Program Files (x86)\DocuSign Print Driver\DocuSignExpress.exe
O4 - Global Startup: DocuSign Professional.lnk = C:\Program Files (x86)\DocuSign Professional\DocuSign.DSPro.Spooler.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files (x86)\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://www.infinityarts.com
O16 - DPF: RemotePrintControlCab - https://payrollapp2.com/@57128e25-bfc9-4da2…tControlCab.CAB
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} (QuickBooks Online Edition Utilities Class v10) - https://qbo.intuit.com/c28/v33.140/qboax10.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~4\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\ASTSRV.EXE
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - PCTEL - C:\Program Files (x86)\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: AT&T Con App Svc (CAATT) - PCTEL - C:\Program Files (x86)\AT&T\Communication Manager\ConAppsSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NeatWorks Database Controller (NeatWorksDatabaseController) - The Neat Company - C:\Program Files (x86)\NeatWorks\exec\NeatWorksDatabaseController.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 16555 bytes
Hi,

No obvious signs of malware there, but we need a deeper look to be sure. You may just have a lot of programs running in the background


Please do the following:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Ok, Done.

Here's the OTL.Txt contents:

OTL logfile created on: 6/22/2010 12:13:18 PM - Run 1
OTL by OldTimer - Version 3.2.6.1 Folder = C:\Users\AustinGood\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 51.00% Memory free
10.00 Gb Paging File | 7.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): c:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.40 Gb Total Space | 504.65 Gb Free Space | 86.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 7.56 Gb Total Space | 5.00 Gb Free Space | 66.09% Space Free | Partition Type: FAT32

Computer Name: STUDY-PC
Current User Name: AustinGood
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\AustinGood\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Common Files\Research in Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\DocuSign Print Driver\DocuSignExpress.exe (DocuSign, Inc.)
PRC - C:\Program Files (x86)\DocuSign Professional\DocuSign.DSPro.Spooler.exe (DocuSign, Inc.)
PRC - C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Windows\SysWOW64\WDBtnMgr.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Program Files (x86)\Portrait Displays\Pivot Software\Floater.exe ()
PRC - C:\Program Files (x86)\Portrait Displays\Pivot Software\wpCtrl.exe ()
PRC - C:\Windows\ModLEDKey.exe (Chicony)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\AustinGood\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files (x86)\Portrait Displays\Pivot Software\Winphook.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NitroDriverReadSpool) – C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe (Nitro PDF Software)
SRV:64bit: - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV:64bit: - (ETService) – C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:64bit: - (TabletServicePen) – C:\Windows\SysNative\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (LPDSVC) – C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (yksvc) – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (AffinegyService) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (astcc) – C:\Windows\SysWOW64\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (NeatWorksDatabaseController) – C:\Program Files (x86)\NeatWorks\exec\NeatWorksDatabaseController.exe (The Neat Company)
SRV - (UpdateCenterService) – C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (nTuneService) – C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (ATTRcAppSvc) – C:\Program Files (x86)\AT&T\Communication Manager\RcAppSvc.exe (PCTEL)
SRV - (CAATT) – C:\Program Files (x86)\AT&T\Communication Manager\ConAppsSvc.exe (PCTEL)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (DTSRVC) – C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (swmsflt) – C:\Windows\SysNative\drivers\swmsflt.sys ()
DRV:64bit: - (RTL8187B) – C:\Windows\SysNative\DRIVERS\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\DRIVERS\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (PCTINDIS5X64) – C:\Windows\SysNative\PCTINDIS5X64.SYS (PCTEL Inc.)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV:64bit: - (PdiPorts) – C:\Windows\SysNative\DRIVERS\PdiPorts.sys (Portrait Displays, Inc.)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\DRIVERS\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\Drivers\RootMdm.sys (Microsoft Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\DRIVERS\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\DRIVERS\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80) – C:\Windows\SysNative\DRIVERS\swumx80.sys (Sierra Wireless Inc.)
DRV:64bit: - (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80) – C:\Windows\SysNative\DRIVERS\swnc8u80.sys (Sierra Wireless Inc.)
DRV:64bit: - (AmdLLD64) – C:\Windows\SysNative\DRIVERS\AmdLLD64.sys (AMD, Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\DRIVERS\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\DRIVERS\WacomVKHid.sys (Wacom Technology)
DRV - (NVR0FLASHDev) – C:\Windows\nvflsh64.sys (NVIDIA Corp.)
DRV - (NVR0Dev) – C:\Windows\nvoclk64.sys (NVIDIA Corp.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Afc) – C:\Windows\SysWOW64\drivers\afc.sys (Arcsoft, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…amp;m=dx4200-09

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ntreis.marketlinx.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/25 15:50:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/13 17:47:43 | 000,000,000 | —D | M]

[2010/06/21 17:16:43 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/03 15:16:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/27 11:33:58 | 000,184,320 | —- | M] ( ) – C:\Program Files (x86)\Mozilla Firefox\plugins\npxsciter.dll

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [AT&T Communication Manager] C:\Program Files (x86)\AT&T\Communication Manager\ATTCM.exe (ATT)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe (brother)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DT GWY] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [EarthLink Installer] File not found
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [P2Go_Menu] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files (x86)\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [Smart Copy] C:\Program Files (x86)\IOI\Smart Copy\ButtonMonitor.exe (IOI)
O4 - HKLM..\Run: [WD Button Manager] C:\Windows\SysWow64\WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKCU..\Run: [\\MAC-LAPTOP\Epson Workforce 500 - On the Study PC] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATIEQA.EXE File not found
O4 - HKCU..\Run: [cdloader] C:\Users\AustinGood\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [EPSON WorkForce 500 Series] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATIEQA.EXE File not found
O4 - HKCU..\Run: [googletalk] C:\Users\AustinGood\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWow64\Macromed\Flash\NPSWF32_FlashUtil.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O9 - Extra Button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files (x86)\iMacros\imacros.dll (iOpus Software GmbH)
O9 - Extra 'Tools' menuitem : iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - Reg Error: Value error. File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: infinityarts.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: infinityarts.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/x64/RACtrl.cab (Performance Viewer Activex Control)
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} https://qbo.intuit.com/c28/v33.140/qboax10.cab (QuickBooks Online Edition Utilities Class v10)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (RIM AxLoader)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: RemotePrintControlCab https://payrollapp2.com/@57128e25-bfc9-4da2…tControlCab.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~4\GOEC62~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O33 - MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\Shell\phone\command - "" = K:\autorun.exe – File not found
O33 - MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\Shell - "" = AutoRun
O33 - MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\Shell\AutoRun\command - "" = I:\WIN\setup.exe – File not found
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O33 - MountPoints2\K\Shell\phone\command - "" = K:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 000,000,000 | —D | M]

Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\Windows\SysWow64\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/06/22 12:10:13 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Users\AustinGood\Desktop\OTL.exe
[2010/06/20 17:30:13 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\AustinGood\Desktop\HiJackThis.exe
[2010/06/17 18:06:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\MySQL
[2010/05/20 11:07:54 | 000,000,000 | —D | C] – C:\Users\AustinGood\Desktop\SMB
[2010/05/19 14:46:17 | 000,000,000 | —D | C] – C:\ProgramData\Belkin
[2010/05/19 14:46:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Belkin
[2010/05/19 14:41:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Belkin
[2010/05/19 14:41:19 | 000,000,000 | —D | C] – C:\ProgramData\Affinegy
[2010/05/19 14:41:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/05/19 11:21:00 | 000,000,000 | —D | C] – C:\ProgramData\KONICA MINOLTA
[2010/05/19 11:21:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\KONICA MINOLTA
[2010/05/19 11:20:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\KONICA MINOLTA
[2010/05/19 11:18:26 | 000,000,000 | —D | C] – C:\Program Files\KONICA MINOLTA
[2010/05/07 15:10:48 | 000,000,000 | —D | C] – C:\ProgramData\Nuance
[2010/05/07 15:10:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/05/07 14:37:50 | 000,000,000 | —D | C] – C:\Users\Public\Documents\ntr
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysWow64\vi-VN
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysNative\vi-VN
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysWow64\eu-ES
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysNative\eu-ES
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ca-ES
[2010/05/03 15:45:51 | 000,000,000 | —D | C] – C:\Windows\SysNative\ca-ES
[2010/05/03 15:18:39 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2010/04/12 10:56:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/04/12 10:56:07 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/04/12 10:56:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/12 10:52:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/04/05 11:06:34 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/05 11:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/05 11:06:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Carbonite
[2010/04/02 16:13:08 | 000,000,000 | —D | C] – C:\Users\AustinGood\Documents\New Folder
[2010/03/30 10:41:12 | 000,000,000 | —D | C] – C:\ProgramData\Research In Motion
[2010/03/30 10:41:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/22 12:13:33 | 004,980,736 | -HS- | M] () – C:\Users\AustinGood\NTUSER.DAT
[2010/06/22 12:10:15 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\AustinGood\Desktop\OTL.exe
[2010/06/22 12:06:01 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/22 12:06:01 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/22 12:01:58 | 001,411,051 | —- | M] () – C:\Users\AustinGood\Desktop\936_Remington_Executed_Contract.pdf
[2010/06/22 11:51:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/22 11:30:06 | 000,000,928 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-552224322-3192167460-1727280319-1000UA.job
[2010/06/22 00:30:00 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-552224322-3192167460-1727280319-1000Core.job
[2010/06/21 23:51:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/21 14:56:17 | 000,886,646 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/21 14:56:17 | 000,731,752 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/21 14:56:17 | 000,155,490 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/21 10:07:03 | 000,002,407 | —- | M] () – C:\Users\Public\Desktop\RolEDX Advantage.lnk
[2010/06/20 17:30:13 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\AustinGood\Desktop\HiJackThis.exe
[2010/06/18 12:50:50 | 000,000,091 | —- | M] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/06/17 18:06:03 | 000,000,411 | —- | M] () – C:\Windows\ODBCINST.INI
[2010/06/17 18:05:57 | 000,000,522 | —- | M] () – C:\Users\AustinGood\Desktop\Mojo Sales Engine.lnk
[2010/06/17 08:20:29 | 000,000,153 | —- | M] () – C:\Windows\win.ini
[2010/06/17 08:20:15 | 000,000,482 | —- | M] () – C:\Windows\Brownie.ini
[2010/06/17 08:05:17 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2010/06/17 08:05:17 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2010/06/17 08:05:09 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/17 08:05:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/17 08:05:03 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2010/06/16 18:08:53 | 000,524,288 | -HS- | M] () – C:\Users\AustinGood\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/06/16 18:08:53 | 000,065,536 | -HS- | M] () – C:\Users\AustinGood\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/06/16 18:06:07 | 005,153,698 | -H– | M] () – C:\Users\AustinGood\AppData\Local\IconCache.db
[2010/06/10 15:23:21 | 000,002,583 | —- | M] () – C:\Users\Public\Desktop\DocuSign Professional.lnk
[2010/06/09 16:09:47 | 000,087,456 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIRfsClientNP.dll
[2010/06/09 16:09:46 | 000,080,768 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIinit.dll
[2010/06/09 16:09:46 | 000,033,152 | —- | M] (LogMeIn, Inc.) – C:\Windows\SysNative\LMIport.dll
[2010/06/08 22:25:28 | 000,002,069 | —- | M] () – C:\Users\AustinGood\Desktop\Google Chrome.lnk
[2010/06/08 22:25:28 | 000,002,031 | —- | M] () – C:\Users\AustinGood\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/05/28 13:30:16 | 000,000,472 | —- | M] () – C:\Windows\BRWMARK.INI
[2010/05/27 16:18:36 | 000,181,681 | —- | M] () – C:\Users\AustinGood\Documents\5304 Ravensthorpe Seller's Disclosure.pdf
[2010/05/27 15:44:45 | 000,014,518 | —- | M] () – C:\Users\AustinGood\Documents\701 Villanova Floor Plan.pdf
[2010/05/27 15:44:15 | 000,011,046 | —- | M] () – C:\Users\AustinGood\Documents\701 Villanova Utilities.pdf
[2010/05/27 14:20:32 | 000,022,839 | —- | M] () – C:\Users\AustinGood\Documents\Floor Plan.pdf
[2010/05/21 15:54:47 | 000,072,080 | —- | M] () – C:\Users\AustinGood\g2mdlhlpx.exe
[2010/05/20 11:16:02 | 000,480,536 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/19 14:41:35 | 000,000,051 | —- | M] () – C:\Windows\SysNative\drivers\etc\lmhosts
[2010/05/13 17:48:04 | 000,052,180 | —- | M] () – C:\Windows\unins000.dat
[2010/05/13 10:43:27 | 000,064,204 | —- | M] () – C:\Users\AustinGood\Documents\520 Plantation Delinquent Tax Statement.pdf
[2010/05/11 18:08:18 | 000,138,448 | —- | M] () – C:\Users\AustinGood\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/11 15:56:28 | 000,002,076 | —- | M] () – C:\Users\AustinGood\Desktop\QuickBooks Pro 2010.lnk
[2010/05/11 15:45:13 | 000,002,335 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2010/05/11 15:33:09 | 000,000,100 | —- | M] () – C:\Windows\SysNative\RPCS.ini
[2010/05/11 15:33:09 | 000,000,070 | —- | M] () – C:\Windows\SysNative\ricdb.ini
[2010/05/11 13:50:00 | 000,065,114 | —- | M] () – C:\Users\AustinGood\Documents\repair amendment.pdf
[2010/05/05 11:17:10 | 000,695,602 | —- | M] () – C:\Windows\unins000.exe
[2010/05/03 16:01:04 | 000,839,216 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/03 15:27:03 | 000,002,006 | —- | M] () – C:\Users\Public\Desktop\goodshomes.com Calendar.lnk
[2010/05/03 15:27:03 | 000,001,972 | —- | M] () – C:\Users\Public\Desktop\goodshomes.com Email.lnk
[2010/05/03 15:27:03 | 000,001,960 | —- | M] () – C:\Users\Public\Desktop\goodshomes.com Docs.lnk
[2010/04/27 11:49:50 | 000,900,248 | —- | M] (Top Producer Systems Inc.) – C:\Windows\SysWow64\sciter-wp.dll
[2010/04/27 11:49:48 | 002,641,048 | —- | M] (Top Producer Systems) – C:\Windows\SysWow64\xsciter.dll
[2010/04/27 11:49:48 | 000,629,912 | —- | M] (Top Producer Systems Inc.) – C:\Windows\SysWow64\sciter-bn.dll
[2010/04/13 15:43:28 | 000,001,919 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2010/04/05 16:27:54 | 001,160,897 | —- | M] () – C:\Users\AustinGood\Documents\520 plantation Executed Lease Docs.pdf
[2010/04/05 11:06:09 | 000,001,898 | —- | M] () – C:\Users\Public\Desktop\Carbonite Online Backup Setup.lnk
[2010/03/30 15:49:31 | 000,012,009 | —- | M] () – C:\Users\AustinGood\Documents\Exhibit A.docx
[2010/03/30 10:41:24 | 000,001,901 | —- | M] () – C:\Users\Public\Desktop\Desktop Manager.lnk
[2010/03/29 16:36:10 | 000,033,280 | —- | M] () – C:\Users\AustinGood\Documents\520 plantation Invoice.xls
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/22 12:01:58 | 001,411,051 | —- | C] () – C:\Users\AustinGood\Desktop\936_Remington_Executed_Contract.pdf
[2010/05/27 16:18:36 | 000,181,681 | —- | C] () – C:\Users\AustinGood\Documents\5304 Ravensthorpe Seller's Disclosure.pdf
[2010/05/27 15:44:45 | 000,014,518 | —- | C] () – C:\Users\AustinGood\Documents\701 Villanova Floor Plan.pdf
[2010/05/27 15:44:15 | 000,011,046 | —- | C] () – C:\Users\AustinGood\Documents\701 Villanova Utilities.pdf
[2010/05/27 14:20:32 | 000,022,839 | —- | C] () – C:\Users\AustinGood\Documents\Floor Plan.pdf
[2010/05/13 10:43:27 | 000,064,204 | —- | C] () – C:\Users\AustinGood\Documents\520 Plantation Delinquent Tax Statement.pdf
[2010/05/11 15:56:28 | 000,002,076 | —- | C] () – C:\Users\AustinGood\Desktop\QuickBooks Pro 2010.lnk
[2010/05/11 13:50:00 | 000,065,114 | —- | C] () – C:\Users\AustinGood\Documents\repair amendment.pdf
[2010/05/07 15:13:08 | 000,002,335 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2010/05/03 15:27:03 | 000,002,006 | —- | C] () – C:\Users\Public\Desktop\goodshomes.com Calendar.lnk
[2010/05/03 15:27:03 | 000,001,972 | —- | C] () – C:\Users\Public\Desktop\goodshomes.com Email.lnk
[2010/05/03 15:27:03 | 000,001,960 | —- | C] () – C:\Users\Public\Desktop\goodshomes.com Docs.lnk
[2010/05/03 15:03:30 | 4294,107,136 | -HS- | C] () – C:\hiberfil.sys
[2010/04/05 16:27:54 | 001,160,897 | —- | C] () – C:\Users\AustinGood\Documents\520 plantation Executed Lease Docs.pdf
[2010/04/05 11:06:09 | 000,001,898 | —- | C] () – C:\Users\Public\Desktop\Carbonite Online Backup Setup.lnk
[2010/03/29 17:57:25 | 000,012,009 | —- | C] () – C:\Users\AustinGood\Documents\Exhibit A.docx
[2010/03/29 16:36:09 | 000,033,280 | —- | C] () – C:\Users\AustinGood\Documents\520 plantation Invoice.xls
[2010/02/03 15:07:26 | 000,057,016 | —- | C] () – C:\Windows\SysWow64\imsys.dll
[2010/02/03 15:07:25 | 000,343,224 | —- | C] () – C:\Windows\SysWow64\iimds.dll
[2010/02/03 15:07:25 | 000,233,144 | —- | C] () – C:\Windows\SysWow64\IMImage.dll
[2010/02/03 15:07:25 | 000,014,848 | —- | C] () – C:\Windows\SysWow64\iimir.dll
[2010/01/06 12:09:10 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/01/06 12:08:27 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/09/11 10:52:10 | 000,000,091 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/09/09 18:29:40 | 000,000,062 | —- | C] () – C:\Windows\Personal Logger.INI
[2009/07/27 15:13:17 | 000,000,050 | —- | C] () – C:\Windows\TPDataTransfer.ini
[2009/07/27 15:13:11 | 000,061,440 | —- | C] () – C:\Windows\SysWow64\Gif89.dll
[2009/07/23 17:25:40 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\libssl32.dll
[2009/07/10 16:05:27 | 000,009,853 | —- | C] () – C:\Windows\HL-2170W.INI
[2009/06/17 11:13:30 | 000,508,224 | —- | C] () – C:\Windows\SysWow64\ICCProfiles.dll
[2009/05/19 12:34:51 | 000,839,216 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/05/07 14:05:05 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\brlmw03a.ini
[2009/05/06 16:52:35 | 000,000,472 | —- | C] () – C:\Windows\BRWMARK.INI
[2009/05/06 16:50:14 | 000,000,152 | —- | C] () – C:\Windows\BRVIDEO.INI
[2009/05/06 16:50:14 | 000,000,000 | —- | C] () – C:\Windows\brmx2001.ini
[2009/05/06 16:49:25 | 000,000,482 | —- | C] () – C:\Windows\Brownie.ini
[2009/04/26 23:13:36 | 000,000,326 | —- | C] () – C:\Windows\primopdf.ini
[2009/04/19 10:31:24 | 000,000,284 | —- | C] () – C:\Windows\{12EC5660-A8D7-11DC-97AD-D55156D89593}_WiseFW.ini
[2009/04/03 02:15:00 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\M1690RES.dll
[2009/04/03 02:11:00 | 000,031,910 | —- | C] () – C:\Windows\MSUMLT0H.INI
[2009/03/02 01:46:51 | 000,000,248 | —- | C] () – C:\Windows\wininit.ini
[2009/02/25 20:05:04 | 000,002,304 | —- | C] () – C:\Windows\SysWow64\Machnm32.sys
[2009/01/19 06:16:35 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/01/19 06:16:35 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/06/05 09:58:26 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/12/11 03:09:11 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\IPPCallAnalysis5.dll
[2007/08/06 11:07:30 | 000,008,784 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2005/03/29 00:58:20 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\ssleay32.dll
[2005/03/29 00:58:10 | 000,847,872 | —- | C] () – C:\Windows\SysWow64\libeay32.dll
[1998/12/08 19:09:44 | 000,338,944 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[1998/12/08 19:09:44 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\LFKODAK.DLL
[1998/12/08 19:09:44 | 000,088,576 | —- | C] () – C:\Windows\SysWow64\lffpx90n.dll
[1996/04/01 12:00:00 | 000,000,200 | —- | C] () – C:\Windows\SysWow64\CAPTURE2.INI

========== LOP Check ==========

[2010/06/16 18:08:57 | 000,032,570 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/03/03 20:51:35 | 000,001,024 | —- | M] () – C:\.rnd
[2009/05/25 14:28:09 | 000,000,020 | -HS- | M] () – C:\ArcDeviceInfo
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/11/03 15:21:30 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/06/17 08:05:03 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/11/03 16:39:31 | 000,000,165 | —- | M] () – C:\Labelprint.log
[2008/11/03 16:43:39 | 000,000,106 | —- | M] () – C:\ms.log
[2005/09/23 03:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2010/06/17 08:05:01 | 1996,488,703 | -HS- | M] () – C:\pagefile.sys
[2008/04/08 16:46:34 | 000,007,163 | —- | M] () – C:\pdiports.cat
[2008/04/08 16:46:14 | 000,002,853 | —- | M] () – C:\pdiports64.inf
[2009/02/25 20:04:28 | 000,000,173 | —- | M] () – C:\pdisdk.log
[2009/02/25 20:05:05 | 000,000,184 | —- | M] () – C:\pivot.log
[2009/01/19 06:11:50 | 000,000,838 | —- | M] () – C:\RHDSetup.log
[2010/01/29 16:06:23 | 000,026,503 | —- | M] () – C:\spi.scanning.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 01:26:45 | 000,648,704 | —- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 – C:\Windows\SysWOW64\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/20 21:50:35 | 000,179,200 | —- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B – C:\Windows\SysWOW64\ws2_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
< End of report >


and here's the Extras.Txt output:

OTL Extras logfile created on: 6/22/2010 12:13:18 PM - Run 1
OTL by OldTimer - Version 3.2.6.1 Folder = C:\Users\AustinGood\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 51.00% Memory free
10.00 Gb Paging File | 7.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): c:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.40 Gb Total Space | 504.65 Gb Free Space | 86.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 7.56 Gb Total Space | 5.00 Gb Free Space | 66.09% Space Free | Partition Type: FAT32

Computer Name: STUDY-PC
Current User Name: AustinGood
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 28 AB E7 DC 03 EB CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\AT&T\Communication Manager\SwiApiMux.exe" = C:\Program Files (x86)\AT&T\Communication Manager\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)
"C:\Program Files (x86)\AT&T\Communication Manager\SwiApiMux.exe" = C:\Program Files (x86)\AT&T\Communication Manager\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01D79C10-D7B5-48C1-A915-8C07BD002800}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{134B9771-4014-455B-AB27-DD88DCE4D8FB}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{1574FD45-F25A-499F-87D8-E2EBD83D5C70}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1651C268-5C48-4649-8C26-4EEB2D1D40E5}" = rport=138 | protocol=17 | dir=out | app=system |
"{2CDE6028-5718-46D5-97E8-A702908E49AF}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{312C7061-E959-43E3-BDEA-A2212B95EFE1}" = lport=445 | protocol=6 | dir=in | app=system |
"{34AA7AA8-91D3-4199-9A10-99EB863FA920}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3CABD0D0-8A61-4493-9165-FD31CD11CBE3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{440C403C-D4FD-4027-92E7-38C11EFC2686}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4444E018-8735-4A7F-A2AC-14106F05A260}" = rport=10244 | protocol=6 | dir=out | app=system |
"{4DFE9CA4-AB2D-4E74-95E2-45675F94EF59}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4F1DB0D9-8129-4F4F-B8C5-6C14D0D2FAF8}" = lport=10244 | protocol=6 | dir=in | app=system |
"{4F28F74F-5E0C-4BC8-A81C-647C7AB3601A}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{52F8A2E2-3C7C-4ECF-9AF1-9E93B7FEA4FA}" = lport=137 | protocol=17 | dir=in | app=system |
"{643691C0-F485-4215-A7C8-2DD7C1EA746B}" = lport=3390 | protocol=6 | dir=in | app=system |
"{66C461FA-49A7-4B58-BFCC-2AFA3C5379AE}" = rport=10244 | protocol=6 | dir=out | app=system |
"{6F442322-1CE4-4785-BBBC-D020632B86C5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{786845EB-2935-40BB-BCAF-E83C6300CE7D}" = rport=445 | protocol=6 | dir=out | app=system |
"{7DDED29B-2C26-45ED-9CC3-43E859E2305B}" = rport=139 | protocol=6 | dir=out | app=system |
"{92CA9948-CFB5-4050-9AF2-01978B67BA3D}" = lport=138 | protocol=17 | dir=in | app=system |
"{96244FF1-ABF9-4B9E-80D0-F73B157C33FA}" = lport=3390 | protocol=6 | dir=in | app=system |
"{9756EAE7-CFE0-46D3-8FF4-80D890181278}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{9969617E-C5AF-4579-B607-4D232F76D9E0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9A17F64E-1D97-4753-982E-D02B1B05F214}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A10D4851-B6BC-46F9-B256-99497A48C937}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AAF44DD5-EFE8-44E6-9257-728C520BB430}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AB9DC4A7-540E-4DE0-A4CF-0DB005214076}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ACFE5DC1-D3C3-4D74-9F01-67A9E88F5C4A}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{BA86A815-504B-488B-A8F0-EC041FF9EA19}" = lport=139 | protocol=6 | dir=in | app=system |
"{C9EB1D9E-4FAC-405C-9521-0F71EB484C8E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CD4E259C-603A-4C7C-82E1-4663F3B7FEA6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CF960CD0-490A-4B7E-AF5A-6D770C05393B}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{D2E5AA6F-9076-4A74-B2D4-7A33FE5380F0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D6479249-5C8B-4DEA-B55D-99F55A0202D7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E17946A0-0D8F-4698-B221-B99CD5FF9163}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E1866FF6-BA2E-4841-8B1A-A0610D413BAC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EDA7F928-EF1E-4154-BD91-A99E9BC4732E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F24123CD-ABF9-4808-BAEA-47786B91B466}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F2F651E6-78AF-4C26-B321-CE5526C59085}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5CB0C01-CD6E-4836-9065-A233C44451CF}" = rport=137 | protocol=17 | dir=out | app=system |
"{F70314D9-2924-4DCF-9BFF-642BEBA69C5E}" = lport=10244 | protocol=6 | dir=in | app=system |
"{FF1966A6-45A5-44CB-A2A9-9906E49BD110}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{044D6DFC-28B4-4FD7-8261-EE31EC06F9FC}" = protocol=6 | dir=in | app=c:\users\austingood\appdata\roaming\mjusbsp\magicjack.exe |
"{04EC1287-F412-4195-B623-1162E8F5856D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0E9C4DB1-4353-4D6F-9153-4BCD528A7E90}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1AD69FD5-7390-4D43-921A-F32E1B43DD46}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1D4423F1-D3B8-496E-BDE5-D71A410D285F}" = protocol=6 | dir=in | app=c:\users\austingood\appdata\roaming\mjusbsp\magicjack.exe |
"{1D5A7778-2C6F-4E17-AC75-230621E7E18F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1F74F198-249D-47F6-BC2A-51C72FED7033}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{2C83A4C5-5D54-4690-9AFE-A380D1033FAE}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{302A9B87-F574-4537-B203-5FA0DD60BD88}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{32360529-BF85-472B-99B1-141578F83061}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{33AA0F9D-DF4D-4D2E-A308-AD63F92A38FC}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{3B4F0797-4E9B-4357-8A25-29409394CEC3}" = protocol=6 | dir=in | app=c:\program files (x86)\mirabyte\feed writer\feedwriter.exe |
"{43AFB6C5-038C-449C-B075-98F3F3DEB8A0}" = protocol=17 | dir=in | app=c:\users\austingood\appdata\roaming\mjusbsp\magicjack.exe |
"{454BCA85-3286-49A4-925D-BC41710A6AD3}" = protocol=6 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{54AE68FF-8271-4F37-81CD-4C2D0AE191CD}" = protocol=6 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{58E35CEE-3489-407E-8575-7B1B2B65B924}" = protocol=17 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{5C7D01DA-68BB-46BD-93CF-89F144B3FD15}" = dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{69D7A59B-3202-4E68-ADCB-CBA077252A4B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7D144B2B-C5AC-4CC0-8765-0F648D7CADCB}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{81A43986-023F-4926-B244-5F631370D7CE}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{8282FA64-0C57-4B0B-BE48-0166821AFD52}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{840AFBF6-2D3F-47A3-9F0A-2FCA5D173143}" = protocol=17 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{84175201-8DCF-444F-B4EB-A01740CE67EF}" = protocol=17 | dir=in | app=c:\users\austingood\appdata\roaming\mjusbsp\magicjack.exe |
"{8472D312-9FC0-4FD7-853A-45EEE25EFE76}" = protocol=17 | dir=in | app=c:\program files (x86)\mirabyte\feed writer\feedwriter.exe |
"{88EF5587-AD05-42DB-95C2-C6EE5C1F1A04}" = protocol=17 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{9272DDC9-3431-4ADC-B646-C389A3A00278}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{97B746CA-0356-4882-BE84-3A71048B9D24}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A1E85613-7524-4CCE-9439-C325EF4DCB15}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A490E25E-C0D4-468C-B775-A4D63E10C249}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{AA2FAD78-6037-43C3-820D-F58319131394}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{B072B199-F15C-48BD-A9E0-3EE178B903DB}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{B4C5C65D-4641-4ECD-A4C0-5A5953076B68}" = protocol=6 | dir=in | app=c:\users\austingood\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{BF4664CB-9093-48A8-AF08-A35CA45830E7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C4D9751E-64A3-499B-AFC0-2E450E072986}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{C8A097EA-4A22-42EE-8B19-9FE8610BB24E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CAC79D38-BB28-4CDE-B45E-E5B506CC8AD2}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D2924E90-7A3A-4784-A624-DF4556480B6B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{D78D9F33-499A-4E66-9FEB-979CB3C90C01}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{E05EC6EA-ACB4-4520-8D39-74069316D139}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe |
"{E0654B6C-E7E6-40DF-A38E-1FEC29ACB4A8}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{E81E91BD-C55F-4313-8622-2BF6A2658FD9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{FB5E6C70-F227-474E-A9C5-82FE1ECCF215}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"TCP Query User{2CCDD3C8-4F61-41DF-9B4D-CDC411AFD33F}C:\program files (x86)\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"TCP Query User{66E1417F-E49D-4B54-A4E0-234C929972E8}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{42434761-CC83-472A-B002-87715CE39C15}C:\program files (x86)\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"UDP Query User{848F853B-9A25-49A9-91BD-2767D31DE900}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D8363B3-74C6-4F66-86D0-7250F02FC5DF}" = AT&T Communication Manager
"{19E74155-1CA2-4807-9BF5-1AAB4F876E1A}" = Motorola Driver Installation
"{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst
"{23E68747-DA44-4EF1-A70E-3ECC8A5F7A6B}" = KONICA MINOLTA magicolor 1690MF Scanner
"{4C00EC96-D644-41AD-91D3-A9CE4382C80E}" = Driver Installer
"{634A0A5C-9B34-11DE-87AE-C7A555D89593}" = Nitro PDF Professional
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{7EA2D88A-C8B7-4102-8644-0A437B6FC143}" = Neat Mobile Scanner Driver
"{816EB8D3-C431-5997-8A7B-99EED8D88C99}" = ATI Catalyst Install Manager
"{86177DAE-38B1-49DD-912E-35CB703AB779}" = Microsoft SQL Server VSS Writer
"{8A2BC7D4-A7D3-45D5-B3D2-394718C53C41}" = Neat ADF Scanner Driver
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1108D4B-72F8-419F-88C5-ABB8DC09B3C7}" = Neat Mobile Scanner (Silver) Driver
"{DDE25FC9-892D-4D24-9325-3BAA5C15ACA9}" = Neat Mobile Scanner 2008 Driver
"{F3888C51-DCE0-4FF1-923B-56546F6E95C2}" = WD Drive Manager (x64)
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"EPSON WorkForce 500 Series" = EPSON WorkForce 500 Series Printer Uninstall
"KONICA MINOLTA magicolor 1690MF" = KONICA MINOLTA magicolor 1690MF
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0217E1D1-BCEF-4A61-AF6D-F7740F65A066}" = Pivot Software
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{0700E22B-A422-40A5-BD20-04BF618CA0F9}" = QuickBooks Pro 2010
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{12EC5660-A8D7-11DC-97AD-D55156D89593}" = mirabyte Feed Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{194BFA8B-8ABF-43F4-A4B5-A38F6B21C3C2}" = Google AdWords Editor
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29042B1C-0713-4575-B7CA-5C8E7B0899D4}" = MySQL Connector/ODBC 5.1
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (NR2007)
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{34FF0741-EC67-4C05-AC2A-6D257123DF2E}" = BigFix
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4761EB82-E8BD-45A4-B19B-586FA9D1D7E6}" = Camtasia Studio 6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}" = Microsoft Money Shared Libraries
"{5FC6E15E-B897-46C4-84D1-15E23AAC2E8A}" = MojoSoap30
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F69C969-2942-4E7B-B594-75B37664B8BA}" = NVIDIA System Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7BD1EAE4-2E08-4087-8600-44B0ACB0C887}" = NeatWorks Core Files
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D8DE8D1-95CF-4C63-84B0-3EE3A7FA7C20}" = TrueForms 4.5 for FNF
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{A064BD13-723E-48CD-A68C-9FEB4DF70A42}" = PPC Campaign Builder
"{A0D66C5B-A622-475D-AD04-4B9E80F7DBB9}" = Microsoft adCenter Add-in for Excel 2.0 (Beta)
"{A351224F-533A-4EED-89F4-0BF3417FD31D}" = WD Backup
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.2
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC76BA86-7AD7-5670-0000-800000000003}" = Korean Fonts Support For Adobe Reader 8
"{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1
"{B6B45398-B8E9-4BA2-ACD8-65D61C65B8AE}" = MyVirtualHome
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{BFB7485D-A200-33CA-A2E1-E1600CA76484}" = Google Talk Plugin
"{C0EED196-57F3-46B7-AC3B-B2DD45B01A43}" = MySQL Connector/ODBC 3.51
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C66FE99D-7C15-40A0-AE4A-A1A3900D9EE3}" = MyVirtualHome
"{C8E95BF5-C07F-4D98-BB42-F58FC98BC03E}" = Google Apps
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D3F323F3-AA43-4C35-8C48-EA259BA270F0}" = Brother HL-2170W
"{D58B35B7-92DC-401F-8BF3-C5D64366E363}" = DocuSign Professional
"{DB75941E-30C4-4D97-B000-D17C764B998C}" = Brother BRAdmin Light 1.11
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{E518C80C-C549-40E1-844C-669ED64195D3}" = FTP Surfer
"{E6B4F1D6-A245-4A78-BB91-A34905DD6551}" = RolEDX Advantage
"{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"{EA1A669B-302B-4E6E-BD23-FA5572A7A85C}" = AMD Power Monitor
"{EBDBF856-D945-4625-BACE-427559C161D0}" = DocuSign Print Driver
"{ED5DCA6F-5FEA-47CB-83DB-210A468C298B}" = KB0817 Keyboard Driver
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
"{F4955758-B754-471D-9091-7CE2C3D9E9AA}" = EzTune
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe SVG Viewer" = Adobe SVG Viewer 6.0
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"Carbonite Setup Lite" = Carbonite Online Backup Setup
"DisplayKEY Sync_is1" = DisplayKEY USB Cradle version 0.7.2.1
"EPSON Scanner" = EPSON Scan
"Foxit PDF Editor" = Foxit PDF Editor
"Google Desktop" = Google Desktop
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IIM5_is1" = iMacros V6.88
"InstallShield_{23E68747-DA44-4EF1-A70E-3ECC8A5F7A6B}" = KONICA MINOLTA magicolor 1690MF Scanner
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{6F69C969-2942-4E7B-B594-75B37664B8BA}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"LimeWire" = LimeWire 5.1.2
"Making Sales Happen_is1" = Making Sales Happen 2.3.24
"Marvell Miniport Driver" = Marvell Miniport Driver
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mojo Sales Engine_is1" = Mojo Sales Engine 2.2.91
"Money2007b" = Microsoft Money Essentials
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NeatWorks" = NeatWorks
"Nvu_is1" = Nvu 1.0PR
"OpenSSL_is1" = OpenSSL 0.9.7f
"Pen Tablet Driver" = Pen Tablet
"PersonalLogger" = Personal Logger 3.0
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"Quick Screen Capture 3.0_is1" = Quick Screen Capture 3.0
"RainMaker_0" = RainMaker AutoPoster [removed]
"RainMaker_1" = RainMaker AutoPoster [removed]
"Smart Copy" = Smart Copy [removed]
"TOP PRODUCER Data Transfer Wizard" = TOP PRODUCER Data Transfer Wizard
"Top Producer Editor_is1" = Top Producer Editor
"WildTangent gateway Master Uninstall" = Gateway Games
"WinGimp-2.0_is1" = GIMP 2.6.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinWget_is1" = WinWget version 0.20 beta
"zipForm6" = zipForm6

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 4.5.0.457
"magicJack Outlook Add-In" = magicJack Outlook Add-In 1.0.3.521

========== Last 10 Event Log Errors ==========

[ adSage Events ]
Error - 4/17/2009 12:00:14 PM | Computer Name = Study-PC | Source = adSage | ID = 0
Description =

Error - 4/17/2009 12:01:26 PM | Computer Name = Study-PC | Source = adSage | ID = 0
Description =

[ Application Events ]
Error - 5/11/2010 4:54:16 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:54:16 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:54:16 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:55:49 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:55:49 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:55:49 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:56:44 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:56:44 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 4:56:44 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 5/11/2010 6:57:13 PM | Computer Name = Study-PC | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Pro 2010": PrintCheck
returned failure resu

[ Media Center Events ]
Error - 6/9/2009 3:18:21 PM | Computer Name = Study-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 9/29/2009 3:05:09 PM | Computer Name = Study-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 1/22/2010 3:46:38 PM | Computer Name = Study-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.WaitForUploadComplete failed. Please
try to ping www.msn.com prior to filing a bug.; Win32 GetLastError returned 10000109
Process: DefaultDomain Object Name: Media Center Guide

Error - 1/22/2010 3:49:20 PM | Computer Name = Study-PC | Source = McrMgr | ID = 109
Description =

Error - 1/28/2010 4:34:56 PM | Computer Name = Study-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 4/19/2010 1:26:18 PM | Computer Name = Study-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/22/2010 7:50:41 PM | Computer Name = Study-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 4/24/2010 1:42:26 AM | Computer Name = Study-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/18/2010 5:58:40 PM | Computer Name = Study-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

[ OSession Events ]
Error - 5/21/2009 4:39:32 PM | Computer Name = Study-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.3820.1003, Microsoft Office Version: 12.0.3820.1004. This session lasted 54
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7/10/2009 1:40:48 PM | Computer Name = Study-PC | Source = netbt | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 7/10/2009 1:41:05 PM | Computer Name = Study-PC | Source = netbt | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 7/10/2009 1:41:17 PM | Computer Name = Study-PC | Source = netbt | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 7/10/2009 2:03:39 PM | Computer Name = Study-PC | Source = HTTP | ID = 15016
Description =

Error - 7/10/2009 2:05:11 PM | Computer Name = Study-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/10/2009 2:05:11 PM | Computer Name = Study-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/10/2009 2:05:11 PM | Computer Name = Study-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/10/2009 2:22:12 PM | Computer Name = Study-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/10/2009 2:22:12 PM | Computer Name = Study-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/10/2009 2:23:42 PM | Computer Name = Study-PC | Source = HTTP | ID = 15016
Description =


< End of report >
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O33 - MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
    O33 - MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\Shell\phone\command - "" = K:\autorun.exe – File not found
    O33 - MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\Shell - "" = AutoRun
    O33 - MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\Shell\AutoRun\command - "" = I:\WIN\setup.exe – File not found
    O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
    O33 - MountPoints2\K\Shell\phone\command - "" = K:\autorun.exe – File not found
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT




Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
The Log from OTL is: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b3e4cee5-03a1-11de-b89b-002268484e05}\ not found. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3e4cee5-03a1-11de-b89b-002268484e05}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b3e4cee5-03a1-11de-b89b-002268484e05}\ not found. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb3f8fff-01e3-11de-aab5-002268484e05}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb3f8fff-01e3-11de-aab5-002268484e05}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fb3f8fff-01e3-11de-aab5-002268484e05}\ not found. File I:\WIN\setup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully. File K:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found. File K:\autorun.exe not found. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: AustinGood User: Default User: Default User User: Mcx1 User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: AustinGood ->Temp folder emptied: 9557111 bytes ->Java cache emptied: 88758880 bytes ->FireFox cache emptied: 58745380 bytes ->Google Chrome cache emptied: 58339259 bytes User: Default ->Temp folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes User: Mcx1 ->Temp folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2330 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3840935 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 18621338 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 227.00 mb OTL by OldTimer - Version 3.2.6.1 log created on 06222010_192833 Files\Folders moved on Reboot… File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. Registry entries deleted on Reboot… Also when I rebooted, on startup I received an error: "SyncInfoApp.exe - Common Language Runtime Debugging Services" "Application Has Generated An Exception That Could Not Be Handled" "Process id = 0xfbc(4028), Thread id = 0xfc0(4028)" <— could have been 4032 I can't remember and I cant read my handwriting sorry. "Click Ok to Terminate. Click Cancel To Debug" When I clicked Cancel it pulled another error that said "Registered jit Debugger Disabled" Not sure if this helps you but I want to give you all the info. I will do the other things tomorrow, I just wanted to give you an update on that. Thanks for your help so far!
Here's My Malwarebytes' Anti-Malware Log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4230

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

6/23/2010 4:36:23 PM
mbam-log-2010-06-23 (16-36-23).txt

Scan type: Quick scan
Objects scanned: 141889
Time elapsed: 4 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 20
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I will move on to the next step and post my results. Thanks for your help so far!
Here's my Kaspersky Log Report Findings: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, June 24, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, June 23, 2010 18:56:53 Records in database: 4314807 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Objects scanned: 418582 Threats found: 9 Infected objects found: 12 Suspicious objects found: 0 Scan duration: 04:13:34 File name / Threat / Threats count C:\Austin\Internet Marketing1\Website Design (Templates, Graphics, ect.)\Graphics\1600BSG\Sales Page.html Infected: Trojan-Clicker.JS.Iframe.cb 1 C:\Program Files (x86)\Rain-Clouds\RainMaker AutoPoster 1.1.0.2\Uninstall.exe Infected: HackTool.Win32.Flooder.q 1 C:\ProgramData\cladgenius.com\CLADGenius\updates\cafw1212.exe Infected: Trojan-Downloader.Win32.Onestage.aot 1 C:\Users\All Users\cladgenius.com\CLADGenius\updates\cafw1212.exe Infected: Trojan-Downloader.Win32.Onestage.aot 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\148D3062-0000136F.eml Infected: Packed.Win32.Krap.w 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\1F781A17-00001373.eml Infected: Packed.Win32.Krap.w 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\2D1A0195-000012E6.eml Infected: Backdoor.Win32.Bredolab.bts 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\4B881290-00002878.eml Infected: Packed.Win32.Krap.an 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\3EAF3E35-00001E67.eml Infected: Packed.Win32.Krap.an 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\5EF96661-0000165A.eml Infected: Trojan-Dropper.Win32.Agent.blua 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\630D7773-00001FC7.eml Infected: Trojan.Win32.Oficla.bd 1 C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\13F45279-000012CC.eml Infected: Trojan.Win32.VBKrypt.ln 1 Selected area has been scanned. I will await your response with further instructions. Thank you so much again for all your help up to this point!
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Austin\Internet Marketing1\Website Design (Templates, Graphics, ect.)\Graphics\1600BSG\Sales Page.html 
    C:\Program Files (x86)\Rain-Clouds\RainMaker AutoPoster 1.1.0.2\Uninstall.exe 
    C:\ProgramData\cladgenius.com\CLADGenius\updates\cafw1212.exe 
    C:\Users\All Users\cladgenius.com\CLADGenius\updates\cafw1212.exe 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\148D3062-0000136F.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\1F781A17-00001373.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\2D1A0195-000012E6.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\4B881290-00002878.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\3EAF3E35-00001E67.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\5EF96661-0000165A.eml
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\630D7773-00001FC7.eml 
    C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\13F45279-000012CC.eml 
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


Next

  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features
  • A list of installed programs will populate
  • Remove the following program:

Java™ 6 Update 5


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Please advise how your computer is running now and if there are any outstanding issues.
Here's the OTL log: All processes killed ========== FILES ========== C:\Austin\Internet Marketing1\Website Design (Templates, Graphics, ect.)\Graphics\1600BSG\Sales Page.html moved successfully. File\Folder C:\Program Files (x86)\Rain-Clouds\RainMaker AutoPoster 1.1.0.2\Uninstall.exe not found. C:\ProgramData\cladgenius.com\CLADGenius\updates\cafw1212.exe moved successfully. File\Folder C:\Users\All Users\cladgenius.com\CLADGenius\updates\cafw1212.exe not found. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\148D3062-0000136F.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\1F781A17-00001373.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\2D1A0195-000012E6.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\123HomeSolu ff6\4B881290-00002878.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\3EAF3E35-00001E67.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\5EF96661-0000165A.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\Austin@Good 739\630D7773-00001FC7.eml moved successfully. C:\Users\AustinGood\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\13F45279-000012CC.eml moved successfully. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: AustinGood User: Default User: Default User User: Mcx1 User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: AustinGood ->Temp folder emptied: 213013 bytes ->Java cache emptied: 128094 bytes ->FireFox cache emptied: 63562666 bytes ->Google Chrome cache emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes User: Mcx1 ->Temp folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 15968 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 114822 bytes RecycleBin emptied: 122116157 bytes Total Files Cleaned = 178.00 mb OTL by OldTimer - Version 3.2.6.1 log created on 06242010_211454 Files\Folders moved on Reboot… File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. Registry entries deleted on Reboot… I will let you know how it runs in the next day or so as I want to give it sufficient time to see the difference. Thanks for your help so far and I will report back to you in a day or two.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI