This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Security Suite Virus

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here again, on my husband's laptop this time.

He has a Window's Security virus where there are false popups. I tried to run Avast and Malware Bytes, following instructions on www.bleepingcomputer.com/virus-removal, (changed LAN settings to keep from being redirected to a proxy, used rkill.com, and ran malware bytes in safe mode, but the malware bytes didn't find anything, and I know the computer is still infected. Am honestly sick to my stomach from the idea of having to deal with another virus - this is a relatively new computer though, and has never had a virus before.

Here is the hijackthis log. Edited to add: When I ran this, there was a message at the beginning that said something like "for some reason, Hijack this was denied access to the Host files" and gave some additional instructions for if I needed to bypass this somehow.



aLogfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:29:14 PM, on 8/14/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe
C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarDriverAdapter_550vista.exe
C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe
C:\Program Files (x86)\CE\nmSvc.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\CE\nmFlt.exe
C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\James Angehr\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: GuardId.MSIEBrowser.BHO - {5b0a01d2-b8a0-4e56-9e6b-cba0ef4b4eb5} - mscoree.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files (x86)\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\MediaShow" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [Readycomm] "C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe"
O4 - HKLM\..\Run: [OnekeyDM] C:\Program Files (x86)\Lenovo\OnekeyDM\OnekeyDM.exe
O4 - HKLM\..\Run: [VeriFaceManager] "C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe"
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [EnergyUtility] "C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
O4 - HKLM\..\Run: [Energy Management] "C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
O4 - HKLM\..\Run: [Lenovo SlideNav] "C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NMSVC] C:\Program Files (x86)\CE\nmSvc.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [WordPerfect Office 1215] "C:\Program Files (x86)\WordPerfect Office 12\Programs\Registration.exe" /title="WordPerfect Office 12" /date=112009 serial=WS12WRX-0041342-FPL lang=EN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [aqormobi] C:\Users\James Angehr\AppData\Local\mnlpsrxej\punhcdmshdw.exe
O4 - Startup: MLB.TV NexDef Plug-in.lnk = C:\Users\James Angehr\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: ID Vault.lnk = C:\Program Files (x86)\ID Vault\IDVault.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files (x86)\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O10 - Unknown file in Winsock LSP: cespy.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: FHPService - Unknown owner - C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IDVault Service (IDVaultSvc) - White Sky, Inc. - C:\Program Files (x86)\ID Vault\IDVaultSvc.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxeb_device - - C:\Windows\system32\lxebcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11733 bytes
Hi,

Please do the following:
  • Download OTL to your desktop.
  • Right click on the icon then choose Run as Administrator to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Random info - the computer runs fine after rkill, but after restart, the virus always comes back up.


OTL.Txt:

OTL logfile created on: 8/16/2010 8:40:22 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\James Angehr\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 187.74 Gb Total Space | 36.13 Gb Free Space | 19.25% Space Free | Partition Type: NTFS
Drive D: | 30.38 Gb Total Space | 28.53 Gb Free Space | 93.91% Space Free | Partition Type: NTFS
Drive E: | 7.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAMESANGEHR-PC
Current User Name: James Angehr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\CE\nmSvc.exe ()
PRC - C:\Program Files (x86)\CE\nmFlt.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
PRC - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
PRC - C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarDriverAdapter_550vista.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
PRC - C:\Windows\SysWOW64\IgrsSvcs.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:64bit: - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:64bit: - (lxeb_device) – C:\Windows\SysNative\lxebcoms.exe ( )
SRV:64bit: - (System_Repair_UpdateMonitor) – C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IDVaultSvc) – C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
SRV - (DDNIService) – C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
SRV - (DDNIMSGService) – C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
SRV - (lxeb_device) – C:\Windows\SysWow64\lxebcoms.exe ( )
SRV - (IGRS) – C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (FHPService) – C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
SRV - (GameConsoleService) – C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe (WildTangent, Inc.)
SRV - (IncSvc) – C:\Windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ACPIVPC) – C:\Windows\SysNative\DRIVERS\AcpiVpc.sys (Lenovo Corporation)
DRV:64bit: - (tvtumon) – C:\Windows\SysNative\DRIVERS\tvtumon.sys (Lenovo)
DRV:64bit: - (WSVD) – C:\Windows\SysNative\drivers\WSVD.sys (CyberLink)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (usbsmi) – C:\Windows\SysNative\DRIVERS\SMIksdrv.sys (SMI)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\DRIVERS\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (enecirhid) – C:\Windows\SysNative\DRIVERS\enecirhid.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (enecirhidma) – C:\Windows\SysNative\DRIVERS\enecirhidma.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\DRIVERS\wimfltr.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/24 19:35:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/24 19:35:19 | 000,000,000 | —D | M]

[2009/10/23 17:46:45 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Extensions
[2010/08/15 12:51:37 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions
[2010/04/26 22:20:08 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/23 19:32:52 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/20 08:10:10 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [lxebmon.exe] C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Unattend0000000001{2F0CCE2D-26B0-45A0-90A2-BEE09B5FC562}] C:\Windows\test.bat File not found
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4 - HKLM..\Run: [IdeaNotesUser] C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Lenovo SlideNav] C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NMSVC] C:\Program Files (x86)\CE\nmSvc.exe ()
O4 - HKLM..\Run: [OnekeyDM] C:\Program Files (x86)\Lenovo\OnekeyDM\OnekeyDM.exe ()
O4 - HKLM..\Run: [Readycomm] C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordPerfect Office 1215] C:\Program Files (x86)\WordPerfect Office 12\Programs\Registration.exe (Corel Corporation)
O4 - HKCU..\Run: [aqormobi] C:\Users\James Angehr\AppData\Local\mnlpsrxej\punhcdmshdw.exe ()
O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - Startup: C:\Users\James Angehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk = C:\Users\James Angehr\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/13 18:11:22 | 000,000,073 | R— | M] () - E:\AUTORUN.INF – [ UDF ]
O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.EXE id= ver=1.0.0.0 – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.clmp3enc - C:\Program Files (x86)\Lenovo\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/13 18:33:23 | 000,000,000 | —D | C] – C:\Users\James Angehr\AppData\Roaming\Malwarebytes
[2010/08/13 18:33:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/13 18:33:10 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/13 11:02:43 | 000,000,000 | —D | C] – C:\Users\James Angehr\AppData\Local\mnlpsrxej
[2010/08/11 09:37:35 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 09:37:35 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/08/11 09:36:57 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/08/11 09:36:55 | 004,697,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 09:36:41 | 002,335,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/11 09:36:39 | 000,706,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/08/11 09:36:39 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2010/08/11 09:36:38 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2010/08/11 09:36:36 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2010/08/11 09:36:36 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/08/11 09:36:36 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 09:36:36 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 09:36:36 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2010/08/11 09:36:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2010/08/11 09:36:36 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2010/08/11 09:36:36 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2010/08/11 09:36:36 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2010/08/11 09:36:36 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/11 09:36:35 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/08/11 09:36:35 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 09:36:35 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 09:36:35 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/08/11 09:36:35 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2010/08/11 09:36:35 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2010/08/11 09:36:35 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2010/08/11 09:36:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2010/08/11 09:36:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/07/18 07:52:48 | 000,000,000 | —D | C] – C:\ProgramData\Ezprint
[2010/07/17 15:14:52 | 000,796,160 | —- | C] ( ) – C:\Windows\SysNative\lxebcoin.dll
[2010/07/17 15:14:51 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lxk_g.dll
[2010/07/17 15:14:45 | 000,983,121 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lxk_gf.dll
[2010/07/17 15:14:04 | 000,510,464 | —- | C] (Lexmark International, Inc.) – C:\Windows\SysNative\LXEBwupd.dll
[2010/07/17 15:14:04 | 000,295,592 | —- | C] (Lexmark International, Inc.) – C:\Windows\SysNative\LXEBwupd.exe
[2010/07/17 15:13:30 | 000,000,000 | —D | C] – C:\Program Files\Lexmark
[2010/07/17 15:13:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lexmark Toolbar
[2010/07/17 15:13:10 | 000,000,000 | —D | C] – C:\Program Files\Lexmark Printable Web
[2010/07/17 15:13:01 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxebinpa.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] ( ) – C:\Windows\SysWow64\lxebiesc.dll
[2010/07/17 15:13:01 | 000,126,976 | —- | C] (Lexmark International Inc.) – C:\Windows\SysWow64\lxeblnks.dll
[2010/07/17 15:13:00 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxebusb1.dll
[2010/07/17 15:13:00 | 000,651,264 | —- | C] ( ) – C:\Windows\SysWow64\lxebpmui.dll
[2010/07/17 15:12:59 | 001,056,768 | —- | C] ( ) – C:\Windows\SysWow64\lxebserv.dll
[2010/07/17 15:12:59 | 000,688,128 | —- | C] ( ) – C:\Windows\SysWow64\lxebhbn3.dll
[2010/07/17 15:12:59 | 000,602,792 | —- | C] ( ) – C:\Windows\SysWow64\lxebcoms.exe
[2010/07/17 15:12:59 | 000,581,632 | —- | C] ( ) – C:\Windows\SysWow64\lxeblmpm.dll
[2010/07/17 15:12:59 | 000,328,360 | —- | C] ( ) – C:\Windows\SysWow64\lxebih.exe
[2010/07/17 15:12:58 | 000,802,816 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomc.dll
[2010/07/17 15:12:58 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomm.dll
[2010/07/17 15:12:58 | 000,369,320 | —- | C] ( ) – C:\Windows\SysWow64\lxebcfg.exe
[2010/07/17 15:12:58 | 000,086,121 | —- | C] (Lexmark International) – C:\Windows\SysWow64\LXEBcfg.dll
[2010/07/17 15:12:45 | 001,335,808 | —- | C] ( ) – C:\Windows\SysNative\lxebusb1.dll
[2010/07/17 15:12:45 | 000,683,008 | —- | C] ( ) – C:\Windows\SysNative\LXEBhcp.dll
[2010/07/17 15:12:45 | 000,558,592 | —- | C] ( ) – C:\Windows\SysNative\lxebinpa.dll
[2010/07/17 15:12:45 | 000,515,072 | —- | C] ( ) – C:\Windows\SysNative\lxebiesc.dll
[2010/07/17 15:12:44 | 001,648,128 | —- | C] ( ) – C:\Windows\SysNative\lxebserv.dll
[2010/07/17 15:12:44 | 000,989,696 | —- | C] ( ) – C:\Windows\SysNative\lxebpmui.dll
[2010/07/17 15:12:44 | 000,899,072 | —- | C] ( ) – C:\Windows\SysNative\lxeblmpm.dll
[2010/07/17 15:12:43 | 001,107,456 | —- | C] ( ) – C:\Windows\SysNative\lxebhbn3.dll
[2010/07/17 15:12:43 | 000,527,016 | —- | C] ( ) – C:\Windows\SysNative\lxebih.exe
[2010/07/17 15:12:42 | 001,366,528 | —- | C] ( ) – C:\Windows\SysNative\lxebcomc.dll
[2010/07/17 15:12:42 | 001,054,888 | —- | C] ( ) – C:\Windows\SysNative\lxebcoms.exe
[2010/07/17 15:12:42 | 000,581,632 | —- | C] ( ) – C:\Windows\SysNative\lxebcomm.dll
[2010/07/17 15:12:41 | 000,616,104 | —- | C] ( ) – C:\Windows\SysNative\lxebcfg.exe
[2010/07/17 15:12:41 | 000,075,264 | —- | C] (Lexmark International) – C:\Windows\SysNative\LXEBcfg.dll
[2010/07/17 15:12:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lexmark Pro200-S500 Series
[2010/07/17 15:09:03 | 000,000,000 | —D | C] – C:\Program Files\Lexmark Pro200-S500 Series
[2009/07/24 09:24:50 | 001,526,576 | —- | C] (Adobe Systems Incorporated) – C:\ProgramData\flashax9f.exe

========== Files - Modified Within 30 Days ==========

[2010/08/16 08:44:01 | 003,670,016 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT
[2010/08/16 08:41:59 | 000,000,470 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job
[2010/08/16 08:23:30 | 000,767,248 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/16 08:23:30 | 000,649,438 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/16 08:23:30 | 000,121,660 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/16 08:16:50 | 000,000,056 | -HS- | M] () – C:\_PartitionInfo
[2010/08/16 08:16:40 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:16:39 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:16:39 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/16 08:16:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/16 08:16:23 | 4253,650,944 | -HS- | M] () – C:\hiberfil.sys
[2010/08/15 23:52:15 | 000,524,288 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/08/15 23:52:15 | 000,065,536 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/08/15 23:52:09 | 001,878,094 | -H– | M] () – C:\Users\James Angehr\AppData\Local\IconCache.db
[2010/08/15 23:07:00 | 000,000,282 | —- | M] () – C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/14 12:21:36 | 000,359,929 | —- | M] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 20:49:42 | 000,000,732 | —- | M] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 19:58:14 | 000,363,520 | —- | M] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/13 18:33:16 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/12 09:26:16 | 000,470,488 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/07/17 15:17:28 | 000,225,655 | —- | M] () – C:\Windows\SysNative\LexFiles.ulf
[2010/07/17 15:13:33 | 000,001,836 | —- | M] () – C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK

========== Files Created - No Company Name ==========

[2010/08/14 12:24:52 | 000,359,929 | —- | C] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 21:39:47 | 4253,650,944 | -HS- | C] () – C:\hiberfil.sys
[2010/08/13 20:19:33 | 000,000,732 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 20:03:50 | 000,363,520 | —- | C] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/13 18:33:16 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/18 07:52:41 | 000,000,252 | —- | C] () – C:\ProgramData\FastPics.log
[2010/07/17 15:33:13 | 000,014,050 | —- | C] () – C:\ProgramData\lxebJSW.log
[2010/07/17 15:14:54 | 000,109,056 | —- | C] () – C:\Windows\SysNative\lxebvs.dll
[2010/07/17 15:14:45 | 000,065,106 | —- | C] () – C:\Windows\SysNative\lxebprpr.chm
[2010/07/17 15:14:45 | 000,065,024 | —- | C] () – C:\Windows\SysNative\lxebgcfg.dll
[2010/07/17 15:14:44 | 000,399,360 | —- | C] () – C:\Windows\SysNative\lxebcui.dll
[2010/07/17 15:14:44 | 000,148,480 | —- | C] () – C:\Windows\SysNative\lxebcuir.dll
[2010/07/17 15:14:44 | 000,008,694 | —- | C] () – C:\Windows\SysNative\lxebcommuilogo_rtl.bmp
[2010/07/17 15:14:44 | 000,008,694 | —- | C] () – C:\Windows\SysNative\lxebcommuilogo.bmp
[2010/07/17 15:14:39 | 000,009,592 | —- | C] () – C:\ProgramData\lxebscan.log
[2010/07/17 15:13:33 | 000,001,836 | —- | C] () – C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK
[2010/07/17 15:13:03 | 000,000,044 | -H– | C] () – C:\Windows\SysNative\lxebrwrd.ini
[2010/07/17 15:13:01 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\LXEBinst.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] () – C:\Windows\SysWow64\lxebcomx.dll
[2010/07/17 15:13:00 | 000,323,584 | —- | C] () – C:\Windows\SysWow64\lxebins.dll
[2010/07/17 15:13:00 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\lxebinsb.dll
[2010/07/17 15:13:00 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\lxebcu.dll
[2010/07/17 15:13:00 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\lxebinsr.dll
[2010/07/17 15:13:00 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\lxebcub.dll
[2010/07/17 15:13:00 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\lxebjswr.dll
[2010/07/17 15:13:00 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\lxebcur.dll
[2010/07/17 15:12:58 | 000,002,057 | —- | C] () – C:\Windows\SysWow64\lxeb.loc
[2010/07/17 15:12:46 | 000,585,216 | —- | C] () – C:\Windows\SysNative\LXEBinst.dll
[2010/07/17 15:12:46 | 000,225,655 | —- | C] () – C:\Windows\SysNative\LexFiles.ulf
[2010/07/17 15:12:43 | 000,450,048 | —- | C] () – C:\Windows\SysNative\lxebins.dll
[2010/07/17 15:12:43 | 000,298,496 | —- | C] () – C:\Windows\SysNative\lxebgrd.dll
[2010/07/17 15:12:43 | 000,245,248 | —- | C] () – C:\Windows\SysNative\lxebinsb.dll
[2010/07/17 15:12:43 | 000,090,624 | —- | C] () – C:\Windows\SysNative\lxebinsr.dll
[2010/07/17 15:12:43 | 000,040,448 | —- | C] () – C:\Windows\SysNative\lxebjswr.dll
[2010/07/17 15:12:42 | 000,378,368 | —- | C] () – C:\Windows\SysNative\lxebcu.dll
[2010/07/17 15:12:42 | 000,073,216 | —- | C] () – C:\Windows\SysNative\lxebcub.dll
[2010/07/17 15:12:42 | 000,022,016 | —- | C] () – C:\Windows\SysNative\lxebcur.dll
[2010/07/17 15:12:41 | 000,002,057 | —- | C] () – C:\Windows\SysNative\lxeb.loc
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\LxWbGwLog.log
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\cmn_upld.log
[2010/07/17 15:11:11 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/07/17 15:09:03 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\LXEBsm.dll
[2010/07/17 15:09:03 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\LXEBsmr.dll
[2010/07/17 15:09:03 | 000,023,552 | —- | C] () – C:\Windows\SysNative\lxebsmr.dll
[2010/07/17 15:09:01 | 000,381,440 | —- | C] () – C:\Windows\SysNative\lxebsm.dll
[2010/06/15 19:34:39 | 000,000,680 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps.dat
[2010/05/03 09:48:09 | 000,026,624 | —- | C] () – C:\Users\James Angehr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 20:55:23 | 000,000,552 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d8caps.dat
[2009/12/17 21:41:45 | 000,428,116 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistMSI490A.txt
[2009/12/17 21:41:45 | 000,011,472 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistUI490A.txt
[2009/12/03 09:41:39 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/03 09:40:30 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/23 13:08:03 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2009/11/05 19:03:50 | 000,002,836 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/11/05 15:54:13 | 000,061,678 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JPR.{PB
[2009/11/05 15:54:13 | 000,012,358 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JCM.{PB
[2009/11/05 10:43:18 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/11/03 11:45:55 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2009/11/03 11:45:55 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2009/11/03 11:45:55 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2009/11/03 11:45:55 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2009/11/03 11:45:55 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2009/11/03 11:45:55 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2009/10/28 11:01:22 | 000,209,920 | —- | C] () – C:\Windows\SysWow64\nmNsp.dll
[2009/10/28 11:01:22 | 000,160,256 | —- | C] () – C:\Windows\SysWow64\CESpy.dll
[2009/09/29 23:28:28 | 002,101,248 | —- | C] () – C:\Windows\SysWow64\Apblend.dll
[2009/09/29 23:27:50 | 000,057,344 | —- | C] () – C:\Windows\AsfHelper.dll
[2009/09/29 23:27:45 | 000,241,664 | —- | C] () – C:\Windows\SysWow64\3DImageRenderer.dll
[2009/09/29 23:18:59 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\SBarHook.DLL
[2009/07/24 09:20:22 | 000,775,020 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/08/27 20:29:00 | 000,033,792 | —- | C] () – C:\Windows\SysWow64\OnekeyDM.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2010/03/19 10:15:26 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\BitTorrent
[2010/06/25 13:07:27 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Canon
[2010/08/16 08:35:09 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\CE
[2010/05/20 08:08:38 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\ID Vault
[2009/10/24 05:10:23 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Lenovo
[2009/11/11 12:16:10 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\WildTangent
[2010/08/15 23:07:00 | 000,000,282 | —- | M] () – C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2010/08/15 23:52:17 | 000,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/16 08:41:59 | 000,000,470 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/07/02 18:35:36 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2009/10/28 11:01:36 | 000,011,733 | —- | M] () – C:\ceInstall.log
[2010/08/16 08:41:41 | 001,243,000 | —- | M] () – C:\ceProcesses.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/08/16 08:16:51 | 001,867,531 | —- | M] () – C:\FaceProv.log
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/08/16 08:16:23 | 4253,650,944 | -HS- | M] () – C:\hiberfil.sys
[2010/08/12 09:25:47 | 000,000,520 | —- | M] () – C:\ICAutoUpdate.log.bak
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/12/02 01:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2010/08/16 08:16:20 | 272,285,695 | -HS- | M] () – C:\pagefile.sys
[2009/09/29 23:10:08 | 000,002,096 | —- | M] () – C:\RHDSetup.log
[2010/08/16 08:37:10 | 000,000,499 | —- | M] () – C:\rkill.log
[2010/08/16 08:35:12 | 017,457,851 | —- | M] () – C:\sysiclog.txt
[2010/06/25 18:42:19 | 027,679,426 | —- | M] () – C:\sysiclog.txt.bak
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/08/16 08:16:50 | 000,000,056 | -HS- | M] () – C:\_PartitionInfo

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/06/25 17:58:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\*. /mp /s >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 01:26:45 | 000,648,704 | —- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 – C:\Windows\SysWOW64\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/20 21:50:35 | 000,179,200 | —- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B – C:\Windows\SysWOW64\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2006/11/02 04:44:30 | 000,004,608 | —- | M] (Microsoft Corporation) MD5=17C0671BF57057108A6D949510EE42C8 – C:\Windows\SysWOW64\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 8/16/2010 8:40:22 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\James Angehr\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 187.74 Gb Total Space | 36.13 Gb Free Space | 19.25% Space Free | Partition Type: NTFS
Drive D: | 30.38 Gb Total Space | 28.53 Gb Free Space | 93.91% Space Free | Partition Type: NTFS
Drive E: | 7.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAMESANGEHR-PC
Current User Name: James Angehr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 7E D7 FC 0D C0 14 CB 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04C867BB-5980-434D-8141-DD94BE845468}" = rport=139 | protocol=6 | dir=out | app=system |
"{35049EEC-3934-47F4-9072-359EEDC3B720}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{43D36A0B-DABD-4A06-9FBE-96E0459FEAF8}" = lport=445 | protocol=6 | dir=in | app=system |
"{56795D00-1F3A-4ECF-B756-F301B705C3F4}" = lport=139 | protocol=6 | dir=in | app=system |
"{727FF404-C7C0-4C15-B4E1-D6304A4AEC0D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{813756C7-C5A4-419E-B5B0-DDA55C36565D}" = rport=138 | protocol=17 | dir=out | app=system |
"{8F6ADB7B-4FF3-4D09-9F26-B7E5B569602B}" = rport=137 | protocol=17 | dir=out | app=system |
"{9D0B3EFA-723C-419D-95EE-BB6359DF3735}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BF340282-0235-4146-939D-D7AD5A6E6587}" = lport=138 | protocol=17 | dir=in | app=system |
"{F1D90187-7C1E-4B04-80B9-F3CEFC48A9BB}" = rport=445 | protocol=6 | dir=out | app=system |
"{FDAEEAEB-DC27-4B1C-ABF5-E6FB7F51D9B2}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{196AFBEF-D90F-479C-A5B1-CF5E134C0D79}" = dir=in | app=c:\windows\system32\igrssvcs.exe |
"{253EEE0F-6FFE-4EB6-BB7E-273C9D00BA04}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25911AD7-288B-414C-8CB3-5969FDADDDFE}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{2CFA8B3F-AF00-4FEF-9136-2F5C75188492}" = dir=in | app=c:\program files (x86)\lenovo\readycomm\projectionist.exe |
"{2FC40AD0-B412-45C0-A167-159072B0C23C}" = dir=in | app=c:\windows\system32\lxebcoms.exe |
"{304E8715-7069-4A8D-9C46-8EC7ACC62967}" = dir=in | app=c:\program files (x86)\lenovo\readycomm\common\igrs.exe |
"{43891784-B32F-45CD-A354-3875C880EEBB}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{4BBD5375-2FD9-45E4-AA73-D168F54F287C}" = dir=out | app=c:\program files (x86)\lenovo\readycomm\projectionist.exe |
"{4DAEBD8D-F023-4537-9371-6D0E386F4198}" = dir=out | app=c:\program files (x86)\lenovo\readycomm\filereceiver.exe |
"{51F2C09A-4D7C-42E7-8997-FDD2837282C4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5F1ADBCA-5ACD-406B-84A2-BFAD36A9E541}" = dir=in | app=c:\program files (x86)\lenovo\readycomm\filereceiver.exe |
"{6C73D2A2-3084-49CC-B07E-295C441A80FA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{7A171A67-ACD4-45F7-AD9D-8677A364090C}" = dir=in | app=c:\windows\system32\lxebcoms.exe |
"{814CDA17-194E-4224-8032-72BA88E49716}" = dir=out | app=c:\windows\system32\igrssvcs.exe |
"{814D179E-8336-43C2-AB8E-B1456144E8D9}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9B151916-7A00-4E59-BF43-97FEF4750259}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{B015BBEE-020B-4AC6-B20C-18EAE2277C97}" = dir=in | app=c:\windows\system32\lxebcoms.exe |
"{C4B9ADAD-BE01-4E22-8190-E281F8E9FD9C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E76FE4CC-9716-46D7-AF85-CFC6B445D444}" = dir=in | app=c:\program files (x86)\lenovo\readycomm\readycomm.exe |
"{EFEC490E-3AB5-4286-8B66-7220D7CEDAAF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F39E6738-23F0-418E-BB2E-C04A9E1F72D9}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{F7C63F44-CFA4-4C1F-ADC2-24ED49E9DAF3}" = dir=out | app=c:\program files (x86)\lenovo\readycomm\common\igrs.exe |
"{FD56C7BF-B103-49A3-A512-6CD28907EBE2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{FE094A06-D10B-4B9F-8E5A-A3B588C8BA20}" = dir=out | app=c:\program files (x86)\lenovo\readycomm\readycomm.exe |
"TCP Query User{0ABF2A72-762C-480E-9EF9-1ADA571FCE20}C:\program files (x86)\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"TCP Query User{DEF42E63-31BE-456F-A9C1-79E90B8DB5D0}C:\windows\system32\ftp.exe" = protocol=6 | dir=in | app=c:\windows\system32\ftp.exe |
"UDP Query User{4451B56D-46CF-43B5-BAA5-9CF0D2F2B784}C:\program files (x86)\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"UDP Query User{B477C238-2BEE-4A0D-ADDB-EA6C8225295A}C:\windows\system32\ftp.exe" = protocol=17 | dir=in | app=c:\windows\system32\ftp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
"{5759E649-E281-46C2-BB4B-50413623DCDF}" = iTunes
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{86177DAE-38B1-49DD-912E-35CB703AB779}" = Microsoft SQL Server VSS Writer
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"7D4044978059DC8916896568EDDF0E875D1FA4EC" = Windows Driver Package - Lenovo (ACPIVPC) System (10/15/2008 3.1.0.1)
"87B8039CA0CD7A68D9536013C2495013C4B4B168" = Windows Driver Package - ENE (enecir) HIDClass (11/19/2008 2.7.0.2)
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"Lexmark Pro200-S500 Series" = Lexmark Pro200-S500 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{20BFD848-897A-48BB-97A7-CDB5A8D4719E}" = WordPerfect Office 12
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5AC5ED2E-2936-4B54-A429-703F9034938E}" = Covenant Eyes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6345DBAE-79E8-443A-9A21-926DA3998A70}" = Lenovo First Boot
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{717E0AD5-91EB-459F-AB8B-1B5219BAF7CE}" = Lenovo System Repair - Windows Update Monitor
"{720264BB-47DB-4728-9B00-AEA049576F48}" = Lenovo Idea Notes
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 4.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = MediaShow
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROHYBRIDR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9B304612-421E-4CC3-84A1-5BAAC1CBE409}" = Onekey Theater
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A8656CC0-6E08-11D4-9A83-00A0CC3530CA}" = BibleWorks 5
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}" = Energy Management
"{AEEAE03F-DEB4-461B-ACC2-FFA7BFAA7178}" = SlideBar Driver
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office ProductCode 1 Key
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}" = Windows Live Toolbar
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7FB1A71-D808-4CD2-997D-837B39EA7EB0}" = DIBS
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{FE7AD27A-62B1-44F6-B69C-25D1ECA94F5D}" = Lenovo EasyCamera
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast!" = avast! Antivirus
"BitTorrent" = BitTorrent
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"Canon RAW Codec" = Canon RAW Codec
"Carbonite Setup Lite" = Carbonite Online Backup Setup
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DPP" = Canon Utilities Digital Photo Professional 3.8
"EasyCapture3.5" = EasyCapture
"EOS Utility" = Canon Utilities EOS Utility
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"FLAC" = FLAC 1.2.1b (remove only)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ID Vault" = ID Vault
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = MediaShow
"InstallShield_{9B304612-421E-4CC3-84A1-5BAAC1CBE409}" = Onekey Theater
"InstallShield_{AEEAE03F-DEB4-461B-ACC2-FFA7BFAA7178}" = SlideBar Driver
"Lenovo Idea Central" = Lenovo Idea Central
"Lenovo SlideNav" = Lenovo SlideNav
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"PROHYBRIDR" = 2007 Microsoft Office system
"Reader Rabbit® I Can Read! With Phonics" = Reader Rabbit® I Can Read! With Phonics
"RealPlayer 12.0" = RealPlayer
"VeriFace" = VeriFace
"WildTangent wildgames Master Uninstall" = WildGames
"Windows Live Toolbar" = Windows Live Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 2/15/2010 12:42:54 PM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files (x86)\Lenovo\VeriFace\Apblend.dll failed, 00000005.

Error - 5/18/2010 9:28:59 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll failed, 00000005.

Error - 6/22/2010 8:45:28 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\SysWOW64\propsys.dll failed, 00000005.

Error - 7/23/2010 5:31:06 PM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\inf\xnacc.inf failed, 00000005.

Error - 8/16/2010 12:52:12 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\James Angehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 8/16/2010 9:17:33 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\James Angehr\AppData\Local\Temp\90fcpg51.out failed, 00000005.

Error - 8/16/2010 9:17:35 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\James Angehr\AppData\Local\Temp\w-vrfwvc.out failed, 00000005.

Error - 8/16/2010 9:17:36 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\James Angehr\AppData\Local\Temp\ngdbiev4.out failed, 00000005.

Error - 8/16/2010 9:18:10 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\James Angehr\AppData\Local\Temp\ncbe8h7o.out failed, 00000005.

Error - 8/16/2010 9:36:20 AM | Computer Name = JamesAngehr-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\SysWOW64\vssapi.dll failed, 00000005.

[ Application Events ]
Error - 7/28/2010 10:31:45 AM | Computer Name = JamesAngehr-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/29/2010 9:55:43 AM | Computer Name = JamesAngehr-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/29/2010 9:55:47 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
StartIDVault not started.

Error - 7/29/2010 9:56:47 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
InstallAddOns not started.

Error - 7/29/2010 9:56:48 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
StartIDVault not started.

Error - 7/30/2010 8:33:50 AM | Computer Name = JamesAngehr-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/30/2010 8:33:56 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
StartIDVault not started.

Error - 7/30/2010 8:34:53 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
InstallAddOns not started.

Error - 7/30/2010 8:34:54 AM | Computer Name = JamesAngehr-PC | Source = IDVaultSvc | ID = 0
Description = C:\Program Files (x86)\ID Vault\IDVault.exe failed signature verification.
StartIDVault not started.

Error - 7/30/2010 3:49:58 PM | Computer Name = JamesAngehr-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2/19/2010 1:48:42 AM | Computer Name = JamesAngehr-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 2/19/2010 9:34:01 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/20/2010 10:26:44 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/21/2010 9:57:17 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/22/2010 12:09:29 PM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/23/2010 9:36:03 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/24/2010 11:21:24 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/25/2010 9:41:54 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/25/2010 10:59:59 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =

Error - 2/26/2010 10:41:52 AM | Computer Name = JamesAngehr-PC | Source = HTTP | ID = 15016
Description =


< End of report >
Hi,

I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


You will need to right click and choose "Run as Administrator" to run the tools we will use.


Did you install Covenant Eyes into your pc?

–Next–

Please do the following:

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
    O4:64bit: - HKLM..\Run: [Unattend0000000001{2F0CCE2D-26B0-45A0-90A2-BEE09B5FC562}] C:\Windows\test.bat File not found
    O4 - HKCU..\Run: [aqormobi] C:\Users\James Angehr\AppData\Local\mnlpsrxej\punhcdmshdw.exe ()
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2001/07/13 18:11:22 | 000,000,073 | R— | M] () - E:\AUTORUN.INF – [ UDF ]
    O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.EXE id= ver=1.0.0.0 – File not found
    
    :Files
    C:\Users\James Angehr\AppData\Local\mnlpsrxej
    C:\Users\James Angehr\Desktop\rkill.com
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
To post in your next reply:
1. OTL logs.
2. Still getting redirects?
Yes, Covenant Eyes was installed and run intentionally. I just attempted to run the scan on the laptop and it first gave me some error messages saying there was no disk in drive E and to insert a disk - I clicked on continue a few times. Then the program froze (had "not responding" in the window heading) and eventually a screen came up from Windows saying that OTL was not responding and had to close. Then I tried to access the internet and wasn't able to (I'm typing from our desktop computer) - tried to go to the proxy settings page and there was no proxy set up. Just restarted it and there are no pop-ups, but also I cannot access the internet?
Hi,

You may need to refurnish your proxy settings if you're using it as the previous one is infected.

Also, please navigate to this folder: C:\_OTL\MovedFiles
and see post the contents of the logs found there, if any. Thanks.
No, I wasn't - but in order to access the internet previously right after the virus, I followed the bleeping computer.com instructions to rechange the re-direct in firefox so that there wasn't a proxy. Covenant eyes is going CRAZY on the laptop right now. :(
On restart, "windows sockets initialization failed" and "lenovo readyComm has stopped working." Also avast anti-virus is turned off and can't be turned on! Under C:_OTL Moved Files, I see a file folder. I open that, I get a bunch more folders and eventually an application entitled "punhcdmshdw.exe - do I open that??
Hi,

Don't open that one. We may need to reinstall Covenant Eyes, for now please do the following:

Open a new Notepad session
  • Click the Start button, click Run.
  • In the run box type notepad.
  • click OK.
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all of the text in the code box below into Notepad, Do not copy the word code.

    @Echo on
    pushd\windows\system32\drivers\etc
    attrib -h -s -r hosts
    echo 127.0.0.1 localhost>HOSTS
    attrib +r +h +s hosts
    popd
    ipconfig /release
    ipconfig /renew
    ipconfig /flushdns
    netsh winsock reset all
    netsh int ip reset all
    shutdown -r -t 1
    del %0
  • Click File, Save as…, and set the Save in to your Desktop
  • In the File name box, type fix.bat
  • In the Save as type: box, choose All Files
  • Choose a location to save. Preferably on your desktop.
  • Click Save
It should look like this: [external image: Posted Image]

Double click on fix.bat & allow it to run. A small black box should open and close - this is normal.

Try connecting to the internet after you're through.
I did what you asked (typed, not copy and pasted), but upon restart, still not able to connect to internet, adn still receiving messages that ReadyComm, Avast, and Covenant Eyes not working.
Hi,

Try reinstalling the following: ReadyComm, Avast, and Covenant Eyes as they may be the one's using the LSP.

Then run another OTL for me please:
  • Open OTL.exe.
  • Right click on the icon then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on your C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To your first question, there were no problems running the fix.bat, as far as I know. I also don't think there was any window saying anything?

I still can't connect to the internet, so I ran the OTL, then used a flash drive to get the logfile to my desktop computer. I do have a question about that - is there any risk of infecting my desktop if I'm transferring files from my husband's laptop with the same flash drive?

Here's the OTL logfile:

OTL logfile created on: 8/17/2010 5:55:28 PM - Run 2
OTL by OldTimer - Version 3.2.10.0 Folder = c:\Users\James Angehr\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 187.74 Gb Total Space | 43.74 Gb Free Space | 23.30% Space Free | Partition Type: NTFS
Drive D: | 30.38 Gb Total Space | 28.53 Gb Free Space | 93.91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1.95 Gb Total Space | 1.58 Gb Free Space | 80.77% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAMESANGEHR-PC
Current User Name: James Angehr
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - c:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\ID Vault\IDVault.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
PRC - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
PRC - C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarDriverAdapter_550vista.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
PRC - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
PRC - C:\Windows\SysWOW64\IgrsSvcs.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - c:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:64bit: - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:64bit: - (lxeb_device) – C:\Windows\SysNative\lxebcoms.exe ( )
SRV:64bit: - (System_Repair_UpdateMonitor) – C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IDVaultSvc) – C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
SRV - (DDNIService) – C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
SRV - (DDNIMSGService) – C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (lxeb_device) – C:\Windows\SysWow64\lxebcoms.exe ( )
SRV - (IGRS) – C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (FHPService) – C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
SRV - (GameConsoleService) – C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe (WildTangent, Inc.)
SRV - (IncSvc) – C:\Windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ACPIVPC) – C:\Windows\SysNative\DRIVERS\AcpiVpc.sys (Lenovo Corporation)
DRV:64bit: - (tvtumon) – C:\Windows\SysNative\DRIVERS\tvtumon.sys (Lenovo)
DRV:64bit: - (WSVD) – C:\Windows\SysNative\drivers\WSVD.sys (CyberLink)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (usbsmi) – C:\Windows\SysNative\DRIVERS\SMIksdrv.sys (SMI)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\DRIVERS\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (enecirhid) – C:\Windows\SysNative\DRIVERS\enecirhid.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (enecirhidma) – C:\Windows\SysNative\DRIVERS\enecirhidma.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\DRIVERS\wimfltr.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/24 19:35:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/24 19:35:19 | 000,000,000 | —D | M]

[2009/10/23 17:46:45 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Extensions
[2010/08/16 13:00:06 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions
[2010/04/26 22:20:08 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/23 19:32:52 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/20 08:10:10 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (GuardId.MSIEBrowser.BHO) - {5b0a01d2-b8a0-4e56-9e6b-cba0ef4b4eb5} - mscoree.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [lxebmon.exe] C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4 - HKLM..\Run: [IdeaNotesUser] C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Lenovo SlideNav] C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [OnekeyDM] C:\Program Files (x86)\Lenovo\OnekeyDM\OnekeyDM.exe ()
O4 - HKLM..\Run: [Readycomm] C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordPerfect Office 1215] C:\Program Files (x86)\WordPerfect Office 12\Programs\Registration.exe (Corel Corporation)
O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - Startup: C:\Users\James Angehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk = C:\Users\James Angehr\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/16 22:38:34 | 000,000,000 | —D | C] – C:\_OTL
[2010/08/13 18:33:23 | 000,000,000 | —D | C] – C:\Users\James Angehr\AppData\Roaming\Malwarebytes
[2010/08/13 18:33:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/13 18:33:10 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/11 09:37:35 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 09:37:35 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/08/11 09:36:57 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/08/11 09:36:55 | 004,697,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 09:36:41 | 002,335,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/11 09:36:39 | 000,706,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/08/11 09:36:39 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2010/08/11 09:36:38 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2010/08/11 09:36:36 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2010/08/11 09:36:36 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/08/11 09:36:36 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 09:36:36 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 09:36:36 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2010/08/11 09:36:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2010/08/11 09:36:36 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2010/08/11 09:36:36 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2010/08/11 09:36:36 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2010/08/11 09:36:36 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/11 09:36:35 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/08/11 09:36:35 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 09:36:35 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 09:36:35 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/08/11 09:36:35 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2010/08/11 09:36:35 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2010/08/11 09:36:35 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2010/08/11 09:36:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2010/08/11 09:36:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/07/17 15:13:01 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxebinpa.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] ( ) – C:\Windows\SysWow64\lxebiesc.dll
[2010/07/17 15:13:00 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxebusb1.dll
[2010/07/17 15:13:00 | 000,651,264 | —- | C] ( ) – C:\Windows\SysWow64\lxebpmui.dll
[2010/07/17 15:12:59 | 001,056,768 | —- | C] ( ) – C:\Windows\SysWow64\lxebserv.dll
[2010/07/17 15:12:59 | 000,688,128 | —- | C] ( ) – C:\Windows\SysWow64\lxebhbn3.dll
[2010/07/17 15:12:59 | 000,581,632 | —- | C] ( ) – C:\Windows\SysWow64\lxeblmpm.dll
[2010/07/17 15:12:58 | 000,802,816 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomc.dll
[2010/07/17 15:12:58 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomm.dll
[2009/07/24 09:24:50 | 001,526,576 | —- | C] (Adobe Systems Incorporated) – C:\ProgramData\flashax9f.exe

========== Files - Modified Within 30 Days ==========

[2010/08/17 17:55:22 | 003,670,016 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT
[2010/08/17 17:53:43 | 000,767,248 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/17 17:53:43 | 000,649,438 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/17 17:53:43 | 000,121,660 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/17 17:48:42 | 000,000,470 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job
[2010/08/17 17:07:00 | 000,000,282 | —- | M] () – C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/17 16:32:07 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/17 16:32:07 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/17 14:32:12 | 000,000,056 | -HS- | M] () – C:\_PartitionInfo
[2010/08/17 14:32:09 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/17 14:32:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/17 14:31:58 | 4253,650,944 | -HS- | M] () – C:\hiberfil.sys
[2010/08/17 14:31:04 | 000,524,288 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/08/17 14:31:04 | 000,065,536 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/08/17 14:30:58 | 003,226,404 | -H– | M] () – C:\Users\James Angehr\AppData\Local\IconCache.db
[2010/08/14 12:21:36 | 000,359,929 | —- | M] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 20:49:42 | 000,000,732 | —- | M] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 19:58:14 | 000,363,520 | —- | M] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/13 18:33:16 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/12 09:26:16 | 000,470,488 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2010/08/17 17:52:36 | 000,363,520 | —- | C] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/14 12:24:52 | 000,359,929 | —- | C] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 21:39:47 | 4253,650,944 | -HS- | C] () – C:\hiberfil.sys
[2010/08/13 20:19:33 | 000,000,732 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 18:33:16 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/18 07:52:41 | 000,000,252 | —- | C] () – C:\ProgramData\FastPics.log
[2010/07/17 15:33:13 | 000,014,050 | —- | C] () – C:\ProgramData\lxebJSW.log
[2010/07/17 15:14:39 | 000,010,472 | —- | C] () – C:\ProgramData\lxebscan.log
[2010/07/17 15:13:01 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\LXEBinst.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] () – C:\Windows\SysWow64\lxebcomx.dll
[2010/07/17 15:13:00 | 000,323,584 | —- | C] () – C:\Windows\SysWow64\lxebins.dll
[2010/07/17 15:13:00 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\lxebinsb.dll
[2010/07/17 15:13:00 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\lxebcu.dll
[2010/07/17 15:13:00 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\lxebinsr.dll
[2010/07/17 15:13:00 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\lxebcub.dll
[2010/07/17 15:13:00 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\lxebjswr.dll
[2010/07/17 15:13:00 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\lxebcur.dll
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\LxWbGwLog.log
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\cmn_upld.log
[2010/07/17 15:11:11 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/07/17 15:09:03 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\LXEBsm.dll
[2010/07/17 15:09:03 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\LXEBsmr.dll
[2010/06/15 19:34:39 | 000,000,680 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps.dat
[2010/05/03 09:48:09 | 000,026,624 | —- | C] () – C:\Users\James Angehr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 20:55:23 | 000,000,552 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d8caps.dat
[2009/12/17 21:41:45 | 000,428,116 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistMSI490A.txt
[2009/12/17 21:41:45 | 000,011,472 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistUI490A.txt
[2009/12/03 09:41:39 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/03 09:40:30 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/23 13:08:03 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2009/11/05 19:03:50 | 000,002,836 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/11/05 15:54:13 | 000,061,678 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JPR.{PB
[2009/11/05 15:54:13 | 000,012,358 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JCM.{PB
[2009/11/05 10:43:18 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/11/03 11:45:55 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2009/11/03 11:45:55 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2009/11/03 11:45:55 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2009/11/03 11:45:55 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2009/11/03 11:45:55 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2009/11/03 11:45:55 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2009/09/29 23:28:28 | 002,101,248 | —- | C] () – C:\Windows\SysWow64\Apblend.dll
[2009/09/29 23:27:50 | 000,057,344 | —- | C] () – C:\Windows\AsfHelper.dll
[2009/09/29 23:27:45 | 000,241,664 | —- | C] () – C:\Windows\SysWow64\3DImageRenderer.dll
[2009/09/29 23:18:59 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\SBarHook.DLL
[2009/07/24 09:20:22 | 000,775,020 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/08/27 20:29:00 | 000,033,792 | —- | C] () – C:\Windows\SysWow64\OnekeyDM.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2010/03/19 10:15:26 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\BitTorrent
[2010/06/25 13:07:27 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Canon
[2010/08/16 22:58:52 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\CE
[2010/05/20 08:08:38 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\ID Vault
[2009/10/24 05:10:23 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Lenovo
[2009/11/11 12:16:10 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\WildTangent
[2010/08/17 17:07:00 | 000,000,282 | —- | M] () – C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2010/08/17 14:31:06 | 000,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/17 17:48:42 | 000,000,470 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job

========== Purity Check ==========


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI