DrEd
Topic Starter
Running XP SP3. I’ve started receiving voice ads through my speakers for about a week, ads for mustard, Lysol, dishwashing detergent, a random instrumental piece that sounds like a movie trailer, "Congratulations! You've Won!" etc. They may vary between 3-5 minutes apart to 20-30 minutes apart, totally random times. The same four ads or trailer have been playing over and over in no apparent sequence. Sometimes two or three of the same or different ads even play simultaneously superimposed on each other. I ran numerous antivirus and anti-malware programs multiple times but they found nothing (Kaspersky, Avira, Malwarebytes, Ad-aware, Spybot, Spysweeper, The Cleaner7.) I have observed task manager applications during the sound periods for any jump in usage; nothing. I’ve search all visible and hidden files for unusual mp3, wav, rar, and their variations files; nothing. I searched for all visible and hidden files created, modified or accessed the day the sounds began, and at the exact times the sounds occurred; nothing. The ads sometimes even begin immediately after start-up before icons load on the desktop or task bar. The ads occur even if browsers (IE and Firefox) have not been opened. Firefox has ad-blockers installed and I deselected ‘play sounds in web pages’ in IE; no change. I attempted to sys restore to a day before the ads began. I have several restore dates available but after each restore restart I get the message that computer was unable to sys restore, even when I restore from Safe Mode and attempted 8 different available restore points. Ran RegClean; no change. I attempted to do Windows installation repair thinking it might override a rogue file but Windows won’t let me repair because SP3 is a higher version than my retail disk. I hope you can help. Here’s the Hijack This, OTL, DDS logs:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:33:58 AM, on 8/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] "C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [tcactive] "C:\Program Files\The Cleaner7\tcap.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.0.0.0.0
O15 - Trusted Zone: http://support.microsoft.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: The Cleaner 2011 Helper Service (moohelp) - MooSoft Development LLC - C:\Program Files\The Cleaner7\mhelper.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
–
End of file - 8551 bytes
OLT Logs:
OTL Extras logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"C:\Program Files\MEDITECH\Print\VMagicPPII.exe" = C:\Program Files\MEDITECH\Print\VMagicPPII.exe:*:Enabled:Document Spooling Service – (Medical Information Technology, Inc.)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Ed's stuff\config\mirc\mirc.exe" = C:\Ed's stuff\config\mirc\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\WINDOWS\LMI59.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI59.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – (LogMeIn, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\LMID.tmp\lmi_rescue.exe" = C:\WINDOWS\LMID.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" = C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy – (Juniper Networks)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\WINDOWS\LMI5.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI5.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\WINDOWS\LMI3.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Spy Sweeper
"{23C3F5C0-566B-478B-AAB6-197ADAD0C945}" = Uniblue SpeedUpMyPC 2009
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3819891A-030B-4a4e-98ED-B28A649E48AB}" = HP Deskjet 3900 series
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{42F6BED9-41DD-40F1-85A8-8E0350493626}" = HPDeskjet3900Series
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"{4732D4A0-5A47-44D8-9B84-B3BD4906D30D}" = TaxCut Premium 2007
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{49B43E4D-32DD-46CD-8EE0-214A947BAFA9}" = DJ_SF_03_D4300_Software_Min
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{79207BEE-6CD3-483C-824C-944663BACAC4}" = TaxCut Premium + Efile 2008
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{8080E151-1FBF-400e-9497-29FDF9410AC6}" = HP Deskjet D4300 Printer Driver 11.0 Rel .3
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{911A0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Outlook 2002
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{92A0792A-E771-4C4A-9A4A-C2917AA19EEA}" = H&R; Block Basic + Efile 2009
"{99011A6E-5200-11DE-BDB8-7ACD56D89593}" = Rosetta Stone Version 3
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E69D6784-CAE4-4770-BBF8-A4E45304E749}" = TaxCut Missouri 2007
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1BD306D-EC22-4739-AD87-0ECB5A907BAC}" = Eudora
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BCWipe" = BCWipe 3.0
"CalcTime" = CalcTime
"CCleaner" = CCleaner (remove only)
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"GoZone iSync" = GoZone iSync
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"InstallShield_{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"InterCover_1.20" = InterCover 1.24
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"Legacy 5.0" = Legacy 5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft.Net.Client.3.5" = Microsoft .NET Framework Client Profile - PREVIEW
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (3.0.3)" = Mozilla Firefox (3.0.3)
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"New Folder Here" = New Folder Here
"NoAds" = NoAds
"Office8.0" = Microsoft Office 97, Professional Edition
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"The Cleaner_is1" = The Cleaner 2011
"The QI Macros for Excel" = The QI Macros for Excel
"Uniblue SpeedUpMyPC 2009" = Uniblue SpeedUpMyPC 2009
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Encoder 7" = Windows Media Encoder 7.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:41:00 AM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 12.0.6541.5000, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/31/2010 12:00:48 PM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.11.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
< End of report >
OTL logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\WebrootSecurity\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WRConsumerService) – C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (moohelp) – C:\Program Files\The Cleaner7\mhelper.exe (MooSoft Development LLC)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (KodakCCS) – C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe (Eastman Kodak Company)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (vsdatant) – C:\WINDOWS\System32\vsdatant.sys File not found
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NEOFLTR_650_15507) Juniper Networks TDI Filter Driver (NEOFLTR_650_15507) – C:\WINDOWS\SYSTEM32\DRIVERS\NEOFLTR_650_15507.SYS (Juniper Networks)
DRV - (avgntflt) – C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (ssidrv) – C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) – C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssmdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.sys (Microsoft Corporation)
DRV - (CVirtA) – C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (RTL8023) – C:\WINDOWS\SYSTEM32\DRIVERS\GA311ND5.SYS (Realtek Semiconductor Corporation )
DRV - (DcCam) – C:\WINDOWS\SYSTEM32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (Exportit) – C:\WINDOWS\SYSTEM32\DRIVERS\ExportIt.sys (Eastman Kodak Company)
DRV - (DcPTP) – C:\WINDOWS\SYSTEM32\DRIVERS\DcPtp.sys (Eastman Kodak Company)
DRV - (DcLps) – C:\WINDOWS\SYSTEM32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DCFS2K) – C:\WINDOWS\SYSTEM32\DRIVERS\DCFS2k.sys (Eastman Kodak Company)
DRV - (DcFpoint) – C:\WINDOWS\SYSTEM32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (BCSWAP) – C:\WINDOWS\System32\drivers\BCSwap.sys (Jetico, Inc.)
DRV - (USBFVNETR) – C:\WINDOWS\SYSTEM32\DRIVERS\ma101rnd.sys (ATMEL)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {57068FBE-1506-42ee-AB02-BD183E7999E4}:2.3.2
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0521
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.2.3
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Components: C:\Program Files\mozilla\components [2010/07/04 14:39:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Plugins: C:\Program Files\mozilla\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Firefox2009\components [2010/08/24 13:45:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Firefox2009\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]
[2008/10/22 09:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/30 09:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions
[2009/08/10 18:20:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/27 18:52:39 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/09/27 18:37:04 | 000,000,000 | —D | M] (Compact Menu 2) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{57068FBE-1506-42ee-AB02-BD183E7999E4}
[2010/08/26 15:17:23 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/23 12:56:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/08/27 18:54:09 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/25 12:11:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/07/06 11:29:23 | 000,000,815 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1ad.doubleclick.net
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [tcactive] C:\Program Files\The Cleaner7\tcap.exe (MooSoft Development Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: 0.0.0.0 ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: christushealth.org ([my] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] https in Trusted sites)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (OWS\S) - File not found
O30 - LSA: Security Packages - (SECURID SOFTWARE TOKEN) - File not found
O30 - LSA: Security Packages - (ecurity) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () - C:\AUTOEXEC.BAK – [ NTFS ]
O32 - AutoRun File - [2007/10/07 21:36:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.MFD – [ NTFS ]
O32 - AutoRun File - [1998/05/02 13:12:24 | 000,000,497 | -HS- | M] () - D:\AUTOEXEC.DOS – [ FAT32 ]
O32 - AutoRun File - [2003/06/14 19:51:48 | 000,000,212 | -H– | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/31 10:54:53 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2010/08/26 15:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Sunbelt Software
[2010/08/26 15:20:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\1101 Leah Drive #415, San Marcos, TX 78666
[2010/08/26 15:20:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\HPAppData
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/24 21:06:26 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/24 16:33:03 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/08/24 08:41:45 | 000,000,000 | —D | C] – C:\Program Files\safeboot tools
[2010/08/23 09:26:22 | 000,000,000 | —D | C] – C:\Program Files\undelete safeboot fix
[2010/08/19 15:52:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\HPAppData
[2010/08/19 08:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/08/18 08:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/02/13 13:49:23 | 013,951,112 | —- | C] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/31 11:03:14 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:11 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/31 08:46:42 | 211,976,192 | —- | M] () – C:\WINDOWS\outlook.pst
[2010/08/31 08:42:14 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/31 08:40:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/31 08:40:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 21:00:16 | 008,388,608 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/30 21:00:16 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/30 20:30:49 | 000,262,144 | —- | M] () – C:\WINDOWS\outlook.bak
[2010/08/30 18:40:34 | 000,017,635 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:52 | 000,426,770 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job
[2010/08/29 09:10:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/27 21:33:59 | 000,011,753 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/27 21:32:08 | 000,001,550 | —- | M] () – C:\WINDOWS\winzip32.ini
[2010/08/27 21:32:08 | 000,000,938 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/25 17:37:24 | 000,000,977 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 21:06:26 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:18 | 000,000,895 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/19 22:00:27 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/16 21:06:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/13 08:47:19 | 000,172,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 07:15:20 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/12 07:15:20 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/11 22:12:19 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/11 22:06:29 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/11 22:06:29 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/11 22:06:29 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/10 23:08:10 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/08/02 09:51:31 | 000,233,984 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/31 11:03:14 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:40:11 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/30 09:29:12 | 000,017,635 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:48 | 000,426,770 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/27 21:33:56 | 000,011,753 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/25 17:37:24 | 000,000,977 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 16:58:18 | 000,000,895 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:37:49 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/16 12:47:50 | 008,388,608 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/03/02 19:00:00 | 004,555,278 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/03/02 19:00:00 | 001,449,935 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/03/02 19:00:00 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/02 19:00:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/03/02 19:00:00 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/03/02 19:00:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/03/02 19:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/03/02 19:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/03/02 19:00:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/03/02 19:00:00 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/03/02 19:00:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/03/02 19:00:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/03/02 19:00:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/03/02 19:00:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/03/02 19:00:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/03/02 19:00:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/03/02 19:00:00 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/11/14 13:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 13:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 13:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 13:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 13:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 13:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 13:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 13:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 13:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 13:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/20 15:53:05 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/06/07 11:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/31 16:55:37 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/11/06 11:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/10/31 03:02:23 | 000,001,550 | —- | C] () – C:\WINDOWS\winzip32.ini
[2008/10/24 15:15:57 | 000,002,528 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2008/02/02 17:30:32 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/02 17:30:31 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/01/04 16:57:22 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/01/04 16:56:24 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/11/21 22:37:14 | 000,000,000 | —- | C] () – C:\WINDOWS\PanelExe.INI
[2007/11/21 22:29:19 | 000,000,000 | —- | C] () – C:\WINDOWS\FileMgrExe.INI
[2007/11/16 16:55:40 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/10/03 22:09:29 | 000,029,696 | —- | C] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2007/09/17 21:45:20 | 000,001,394 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/01 17:34:05 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/08/27 00:23:13 | 000,000,880 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\AdobeDLM.log
[2007/08/27 00:23:13 | 000,000,006 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\dm.ini
[2007/08/26 21:19:49 | 000,000,065 | —- | C] () – C:\WINDOWS\goldwave.ini
[2007/08/26 19:42:52 | 000,073,204 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2007/08/26 19:42:52 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/08/25 19:56:56 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/08/25 19:32:36 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2007/08/25 11:49:28 | 000,004,995 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/08/25 02:32:43 | 000,233,984 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/08 14:19:31 | 000,002,238 | -H– | C] () – C:\Program Files\Ikona1021944043.ico
[2003/12/27 08:00:34 | 000,023,357 | -H– | C] () – C:\Program Files\folder.htt
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/17 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2009/07/20 15:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2008/09/06 08:41:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2010/01/17 12:11:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2009/07/12 14:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2009/01/31 16:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\pdf995
[2010/01/24 21:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TaxCut
[2010/06/14 18:02:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\thecleaner
[2009/04/12 15:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\uniblue
[2007/10/13 11:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/06/27 22:24:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
[2009/10/08 08:17:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2009/08/17 17:15:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/07/21 15:28:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2009/10/04 13:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
[2010/01/23 22:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/08/26 16:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/02 20:24:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/12 15:33:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8AE45C14-3559-45A6-AF34-03CE304FA276}
[2010/08/26 15:21:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\Tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2003/03/31 07:00:00 | 000,245,920 | R— | M] () – C:\$LDR$
[2010/08/31 08:39:57 | 000,173,310 | —- | M] () – C:\aaw7boot.log
[2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () – C:\AUTOEXEC.BAK
[2007/10/07 21:36:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/02 22:35:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.MFD
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/04/16 17:03:32 | 000,084,210 | -HS- | M] () – C:\BOOTLOG.PRV
[2006/04/16 17:43:36 | 000,077,688 | -HS- | M] () – C:\BOOTLOG.TXT
[2007/08/24 16:35:00 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/10/24 08:18:40 | 000,001,173 | —- | M] () – C:\caavsetup.log
[2003/12/27 07:54:16 | 000,245,792 | RH– | M] () – C:\CLASSES.1ST
[1998/06/18 11:34:08 | 000,009,729 | —- | M] () – C:\CLOUDS.jpg
[2000/06/08 12:00:00 | 000,093,040 | -HS- | M] () – C:\COMMAND.COM
[2007/02/11 15:55:14 | 000,002,197 | —- | M] () – C:\COMPATID.TXT
[2007/02/02 22:35:40 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/02/02 22:35:40 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2005/02/28 05:00:30 | 000,017,031 | —- | M] () – C:\DEL
[2007/01/21 10:41:08 | 000,050,405 | -HS- | M] () – C:\DETLOG.OLD
[2007/01/21 12:26:56 | 000,050,405 | -HS- | M] () – C:\DETLOG.TXT
[2009/08/11 08:53:05 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2009/07/20 08:57:38 | 003,594,989 | —- | M] () – C:\EasyShare.dmp
[2007/09/02 20:20:06 | 000,004,915 | -H– | M] () – C:\ffastun.ffa
[2007/09/02 20:20:03 | 001,474,560 | -H– | M] () – C:\ffastun.ffl
[2007/09/02 20:20:06 | 000,819,200 | -H– | M] () – C:\ffastun.ffo
[2007/09/02 20:20:03 | 013,987,840 | -H– | M] () – C:\ffastun0.ffx
[2008/02/13 17:48:02 | 000,019,456 | —- | M] () – C:\FORGETFUL.doc
[2008/03/26 17:18:15 | 000,022,528 | —- | M] () – C:\heim_tax_worksheet_2007.xls
[2007/08/24 10:46:58 | 000,499,132 | —- | M] () – C:\hpfr3900.log
[2000/06/08 12:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2005/09/22 15:30:14 | 000,000,207 | -H– | M] () – C:\IPH.PH
[2003/12/27 07:59:18 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2003/12/27 08:01:42 | 000,008,076 | -HS- | M] () – C:\NETLOG.TXT
[2007/08/25 16:39:30 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2008/08/18 20:56:31 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/02/20 13:04:56 | 000,022,016 | —- | M] () – C:\Optical.exe
[2010/08/31 08:39:57 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2010/04/21 10:40:07 | 000,000,028 | —- | M] () – C:\pending.un
[2010/08/18 10:41:04 | 000,000,441 | —- | M] () – C:\rkill.log
[2010/08/23 09:39:53 | 000,014,268 | —- | M] () – C:\SAFEBOOT_REPAIR.TXT
[2007/08/24 17:10:46 | 000,000,634 | -H– | M] () – C:\SCANDISK.LOG
[2007/03/24 14:30:30 | 000,226,091 | -HS- | M] () – C:\SETUPLOG.TXT
[2003/12/27 15:17:08 | 000,000,202 | —- | M] () – C:\SETUPXLG.TXT
[2003/12/27 07:54:16 | 000,005,166 | -HS- | M] () – C:\SUHDLOG.DAT
[2003/12/27 07:54:16 | 000,499,744 | -HS- | M] () – C:\SYSTEM.1ST
[2004/03/19 12:47:18 | 000,000,000 | —- | M] () – C:\temp.html
[2003/03/31 07:00:00 | 000,454,830 | R— | M] () – C:\txtsetup.sif
[2010/01/12 17:11:37 | 000,000,838 | —- | M] () – C:\updatedatfix.log
[2003/12/27 13:51:44 | 000,000,010 | RH– | M] () – C:\VIDC.ZFR
[2003/12/27 07:58:52 | 000,045,568 | -HS- | M] () – C:\VIDEOROM.BIN
[2004/03/05 16:33:46 | 000,000,063 | —- | M] () – C:\WINDOWSWinHlp32.BMK
[2007/08/24 11:31:54 | 000,005,464 | —- | M] () – C:\winzip.log
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007/08/25 00:50:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\FONTS\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/04/08 21:43:36 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[1996/11/17 00:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\ArtGalry.cag
[2008/10/18 00:46:43 | 000,001,682 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/10/03 22:06:53 | 000,029,696 | —- | M] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2004/03/08 14:19:30 | 000,000,354 | -HS- | M] () – C:\Program Files\desktop.ini
[2003/12/27 08:00:36 | 000,023,357 | -H– | M] () – C:\Program Files\folder.htt
[2004/03/08 14:19:32 | 000,002,238 | -H– | M] () – C:\Program Files\Ikona1021944043.ico
[2005/02/11 21:00:58 | 013,951,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/08/24 17:27:10 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\config\default.sav
[2007/08/24 17:27:10 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\config\software.sav
[2007/08/24 17:27:10 | 000,405,504 | —- | M] () – C:\WINDOWS\SYSTEM32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/18 21:08:42 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/18 21:32:01 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/08/25 00:56:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 03:12:19
========== Alternate Data Streams ==========
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:22:10.85 on Tue 08/31/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1354 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
svchost.exe 4
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
svchost.exe 4
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.cnn.com/
uDefault_Page_URL = hxxp://www.msn.com
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [tcactive] "c:\program files\the cleaner7\tcap.exe"
uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [PMBVolumeWatcher] "c:\program files\sony\pmb\PMBVolumeWatcher.exe"
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: 0.0.0.0
Trusted Zone: christushealth.org\my
Trusted Zone: microsoft.com\oas.support
Trusted Zone: microsoft.com \support
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\eudora\EuShlExt.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\frolfaoz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
FF - plugin: c:\documents and settings\administrator\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\firefox2009\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\firefox2009\plugins\npMozCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox2009\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\firefox2009\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\firefox2009\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\firefox2009\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\firefox2009\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\firefox2009\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\firefox2009\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\firefox2009\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\firefox2009\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\firefox2009\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\firefox2009\greprefs\all.js - pref("geo.enabled", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-11 64288]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-4-21 29808]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-7 11608]
R1 NEOFLTR_650_15507;Juniper Networks TDI Filter Driver (NEOFLTR_650_15507);c:\windows\system32\drivers\NEOFLTR_650_15507.SYS [2010-4-21 85360]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-7 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-7 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-7 56816]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2009-10-24 360224]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-13 24652]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2009-7-20 1201640]
S2 moohelp;The Cleaner 2011 Helper Service;c:\program files\the cleaner7\mhelper.exe [2010-6-14 813056]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [2007-8-25 80000]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?]
S4 BCSWAP;BCSWAP;c:\windows\system32\drivers\BCSwap.sys [2002-8-16 83456]
=============== Created Last 30 ================
2010-08-26 17:48 –d—– c:\windows\system32\wbem\New Folder
2010-08-25 17:37 –d—– c:\program files\Spybot - Search & Destroy
2010-08-25 17:37 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-24 21:06 95,024 a——- c:\windows\system32\drivers\SBREDrv.sys
2010-08-24 16:58 -cd-h— c:\docume~1\alluse~1\applic~1\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-24 08:41 –d—– c:\program files\safeboot tools
2010-08-23 09:26 –d—– c:\program files\undelete safeboot fix
2010-08-19 22:37 664 a——- c:\windows\system32\d3d9caps.dat
2010-08-18 09:18 –d—– c:\windows\system32\wbem\Repository
==================== Find3M ====================
2010-08-12 07:15 15,880 ac—— c:\windows\system32\lsdelete.exe
2010-08-12 07:15 64,288 a——- c:\windows\system32\drivers\Lbd.sys
2010-06-30 07:31 149,504 a——- c:\windows\system32\schannel.dll
2010-06-24 07:10 667,136 a——- c:\windows\system32\wininet.dll
2010-06-24 07:10 81,920 a——- c:\windows\system32\ieencode.dll
2010-06-23 08:44 1,851,904 a——- c:\windows\system32\win32k.sys
2010-06-17 09:03 80,384 a——- c:\windows\system32\iccvid.dll
2010-06-14 09:31 744,448 a——- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 02:41 1,172,480 a——- c:\windows\system32\msxml3.dll
2007-10-03 22:06 29,696 ac—— c:\program files\4E90396851764FA59BAE4EFBBC94F08D.db
2005-02-11 21:00 13,951,112 ac—— c:\program files\Win MEdia Player 9-Setup.exe
2004-03-08 14:19 2,238 ac–h— c:\program files\Ikona1021944043.ico
2004-03-08 14:19 354 ac-sh— c:\program files\desktop.ini
2003-12-27 08:00 23,357 ac–h— c:\program files\folder.htt
2009-08-09 01:44 245,760 ac-sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat
============= FINISH: 11:22:54.93 ===============
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:33:58 AM, on 8/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] "C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [tcactive] "C:\Program Files\The Cleaner7\tcap.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.0.0.0.0
O15 - Trusted Zone: http://support.microsoft.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: The Cleaner 2011 Helper Service (moohelp) - MooSoft Development LLC - C:\Program Files\The Cleaner7\mhelper.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
–
End of file - 8551 bytes
OLT Logs:
OTL Extras logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"C:\Program Files\MEDITECH\Print\VMagicPPII.exe" = C:\Program Files\MEDITECH\Print\VMagicPPII.exe:*:Enabled:Document Spooling Service – (Medical Information Technology, Inc.)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Ed's stuff\config\mirc\mirc.exe" = C:\Ed's stuff\config\mirc\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\WINDOWS\LMI59.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI59.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – (LogMeIn, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\LMID.tmp\lmi_rescue.exe" = C:\WINDOWS\LMID.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" = C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy – (Juniper Networks)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\WINDOWS\LMI5.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI5.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\WINDOWS\LMI3.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Spy Sweeper
"{23C3F5C0-566B-478B-AAB6-197ADAD0C945}" = Uniblue SpeedUpMyPC 2009
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3819891A-030B-4a4e-98ED-B28A649E48AB}" = HP Deskjet 3900 series
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{42F6BED9-41DD-40F1-85A8-8E0350493626}" = HPDeskjet3900Series
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"{4732D4A0-5A47-44D8-9B84-B3BD4906D30D}" = TaxCut Premium 2007
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{49B43E4D-32DD-46CD-8EE0-214A947BAFA9}" = DJ_SF_03_D4300_Software_Min
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{79207BEE-6CD3-483C-824C-944663BACAC4}" = TaxCut Premium + Efile 2008
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{8080E151-1FBF-400e-9497-29FDF9410AC6}" = HP Deskjet D4300 Printer Driver 11.0 Rel .3
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{911A0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Outlook 2002
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{92A0792A-E771-4C4A-9A4A-C2917AA19EEA}" = H&R; Block Basic + Efile 2009
"{99011A6E-5200-11DE-BDB8-7ACD56D89593}" = Rosetta Stone Version 3
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E69D6784-CAE4-4770-BBF8-A4E45304E749}" = TaxCut Missouri 2007
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1BD306D-EC22-4739-AD87-0ECB5A907BAC}" = Eudora
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BCWipe" = BCWipe 3.0
"CalcTime" = CalcTime
"CCleaner" = CCleaner (remove only)
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"GoZone iSync" = GoZone iSync
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"InstallShield_{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"InterCover_1.20" = InterCover 1.24
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"Legacy 5.0" = Legacy 5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft.Net.Client.3.5" = Microsoft .NET Framework Client Profile - PREVIEW
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (3.0.3)" = Mozilla Firefox (3.0.3)
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"New Folder Here" = New Folder Here
"NoAds" = NoAds
"Office8.0" = Microsoft Office 97, Professional Edition
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"The Cleaner_is1" = The Cleaner 2011
"The QI Macros for Excel" = The QI Macros for Excel
"Uniblue SpeedUpMyPC 2009" = Uniblue SpeedUpMyPC 2009
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Encoder 7" = Windows Media Encoder 7.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 8/31/2010 11:41:00 AM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 12.0.6541.5000, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/31/2010 12:00:48 PM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.11.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit
< End of report >
OTL logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\WebrootSecurity\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WRConsumerService) – C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (moohelp) – C:\Program Files\The Cleaner7\mhelper.exe (MooSoft Development LLC)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (KodakCCS) – C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe (Eastman Kodak Company)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (vsdatant) – C:\WINDOWS\System32\vsdatant.sys File not found
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NEOFLTR_650_15507) Juniper Networks TDI Filter Driver (NEOFLTR_650_15507) – C:\WINDOWS\SYSTEM32\DRIVERS\NEOFLTR_650_15507.SYS (Juniper Networks)
DRV - (avgntflt) – C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (ssidrv) – C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) – C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssmdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.sys (Microsoft Corporation)
DRV - (CVirtA) – C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (RTL8023) – C:\WINDOWS\SYSTEM32\DRIVERS\GA311ND5.SYS (Realtek Semiconductor Corporation )
DRV - (DcCam) – C:\WINDOWS\SYSTEM32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (Exportit) – C:\WINDOWS\SYSTEM32\DRIVERS\ExportIt.sys (Eastman Kodak Company)
DRV - (DcPTP) – C:\WINDOWS\SYSTEM32\DRIVERS\DcPtp.sys (Eastman Kodak Company)
DRV - (DcLps) – C:\WINDOWS\SYSTEM32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DCFS2K) – C:\WINDOWS\SYSTEM32\DRIVERS\DCFS2k.sys (Eastman Kodak Company)
DRV - (DcFpoint) – C:\WINDOWS\SYSTEM32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (BCSWAP) – C:\WINDOWS\System32\drivers\BCSwap.sys (Jetico, Inc.)
DRV - (USBFVNETR) – C:\WINDOWS\SYSTEM32\DRIVERS\ma101rnd.sys (ATMEL)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {57068FBE-1506-42ee-AB02-BD183E7999E4}:2.3.2
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0521
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.2.3
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Components: C:\Program Files\mozilla\components [2010/07/04 14:39:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Plugins: C:\Program Files\mozilla\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Firefox2009\components [2010/08/24 13:45:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Firefox2009\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]
[2008/10/22 09:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/30 09:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions
[2009/08/10 18:20:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/27 18:52:39 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/09/27 18:37:04 | 000,000,000 | —D | M] (Compact Menu 2) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{57068FBE-1506-42ee-AB02-BD183E7999E4}
[2010/08/26 15:17:23 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/23 12:56:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/08/27 18:54:09 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/25 12:11:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/07/06 11:29:23 | 000,000,815 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1ad.doubleclick.net
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [tcactive] C:\Program Files\The Cleaner7\tcap.exe (MooSoft Development Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: 0.0.0.0 ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: christushealth.org ([my] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] https in Trusted sites)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (OWS\S) - File not found
O30 - LSA: Security Packages - (SECURID SOFTWARE TOKEN) - File not found
O30 - LSA: Security Packages - (ecurity) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () - C:\AUTOEXEC.BAK – [ NTFS ]
O32 - AutoRun File - [2007/10/07 21:36:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.MFD – [ NTFS ]
O32 - AutoRun File - [1998/05/02 13:12:24 | 000,000,497 | -HS- | M] () - D:\AUTOEXEC.DOS – [ FAT32 ]
O32 - AutoRun File - [2003/06/14 19:51:48 | 000,000,212 | -H– | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/31 10:54:53 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2010/08/26 15:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Sunbelt Software
[2010/08/26 15:20:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\1101 Leah Drive #415, San Marcos, TX 78666
[2010/08/26 15:20:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\HPAppData
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/24 21:06:26 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/24 16:33:03 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/08/24 08:41:45 | 000,000,000 | —D | C] – C:\Program Files\safeboot tools
[2010/08/23 09:26:22 | 000,000,000 | —D | C] – C:\Program Files\undelete safeboot fix
[2010/08/19 15:52:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\HPAppData
[2010/08/19 08:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/08/18 08:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/02/13 13:49:23 | 013,951,112 | —- | C] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/31 11:03:14 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:11 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/31 08:46:42 | 211,976,192 | —- | M] () – C:\WINDOWS\outlook.pst
[2010/08/31 08:42:14 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/31 08:40:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/31 08:40:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 21:00:16 | 008,388,608 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/30 21:00:16 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/30 20:30:49 | 000,262,144 | —- | M] () – C:\WINDOWS\outlook.bak
[2010/08/30 18:40:34 | 000,017,635 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:52 | 000,426,770 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job
[2010/08/29 09:10:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/27 21:33:59 | 000,011,753 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/27 21:32:08 | 000,001,550 | —- | M] () – C:\WINDOWS\winzip32.ini
[2010/08/27 21:32:08 | 000,000,938 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/25 17:37:24 | 000,000,977 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 21:06:26 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:18 | 000,000,895 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/19 22:00:27 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/16 21:06:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/13 08:47:19 | 000,172,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 07:15:20 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/12 07:15:20 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/11 22:12:19 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/11 22:06:29 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/11 22:06:29 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/11 22:06:29 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/10 23:08:10 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/08/02 09:51:31 | 000,233,984 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/31 11:03:14 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:40:11 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/30 09:29:12 | 000,017,635 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:48 | 000,426,770 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/27 21:33:56 | 000,011,753 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/25 17:37:24 | 000,000,977 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 16:58:18 | 000,000,895 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:37:49 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/16 12:47:50 | 008,388,608 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/03/02 19:00:00 | 004,555,278 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/03/02 19:00:00 | 001,449,935 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/03/02 19:00:00 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/02 19:00:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/03/02 19:00:00 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/03/02 19:00:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/03/02 19:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/03/02 19:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/03/02 19:00:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/03/02 19:00:00 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/03/02 19:00:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/03/02 19:00:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/03/02 19:00:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/03/02 19:00:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/03/02 19:00:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/03/02 19:00:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/03/02 19:00:00 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/11/14 13:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 13:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 13:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 13:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 13:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 13:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 13:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 13:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 13:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 13:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/20 15:53:05 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/06/07 11:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/31 16:55:37 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/11/06 11:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/10/31 03:02:23 | 000,001,550 | —- | C] () – C:\WINDOWS\winzip32.ini
[2008/10/24 15:15:57 | 000,002,528 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2008/02/02 17:30:32 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/02 17:30:31 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/01/04 16:57:22 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/01/04 16:56:24 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/11/21 22:37:14 | 000,000,000 | —- | C] () – C:\WINDOWS\PanelExe.INI
[2007/11/21 22:29:19 | 000,000,000 | —- | C] () – C:\WINDOWS\FileMgrExe.INI
[2007/11/16 16:55:40 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/10/03 22:09:29 | 000,029,696 | —- | C] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2007/09/17 21:45:20 | 000,001,394 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/01 17:34:05 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/08/27 00:23:13 | 000,000,880 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\AdobeDLM.log
[2007/08/27 00:23:13 | 000,000,006 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\dm.ini
[2007/08/26 21:19:49 | 000,000,065 | —- | C] () – C:\WINDOWS\goldwave.ini
[2007/08/26 19:42:52 | 000,073,204 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2007/08/26 19:42:52 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/08/25 19:56:56 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/08/25 19:32:36 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2007/08/25 11:49:28 | 000,004,995 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/08/25 02:32:43 | 000,233,984 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/08 14:19:31 | 000,002,238 | -H– | C] () – C:\Program Files\Ikona1021944043.ico
[2003/12/27 08:00:34 | 000,023,357 | -H– | C] () – C:\Program Files\folder.htt
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/17 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2009/07/20 15:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2008/09/06 08:41:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2010/01/17 12:11:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2009/07/12 14:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2009/01/31 16:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\pdf995
[2010/01/24 21:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TaxCut
[2010/06/14 18:02:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\thecleaner
[2009/04/12 15:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\uniblue
[2007/10/13 11:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/06/27 22:24:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
[2009/10/08 08:17:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2009/08/17 17:15:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/07/21 15:28:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2009/10/04 13:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
[2010/01/23 22:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/08/26 16:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/02 20:24:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/12 15:33:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8AE45C14-3559-45A6-AF34-03CE304FA276}
[2010/08/26 15:21:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\Tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2003/03/31 07:00:00 | 000,245,920 | R— | M] () – C:\$LDR$
[2010/08/31 08:39:57 | 000,173,310 | —- | M] () – C:\aaw7boot.log
[2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () – C:\AUTOEXEC.BAK
[2007/10/07 21:36:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/02 22:35:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.MFD
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/04/16 17:03:32 | 000,084,210 | -HS- | M] () – C:\BOOTLOG.PRV
[2006/04/16 17:43:36 | 000,077,688 | -HS- | M] () – C:\BOOTLOG.TXT
[2007/08/24 16:35:00 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/10/24 08:18:40 | 000,001,173 | —- | M] () – C:\caavsetup.log
[2003/12/27 07:54:16 | 000,245,792 | RH– | M] () – C:\CLASSES.1ST
[1998/06/18 11:34:08 | 000,009,729 | —- | M] () – C:\CLOUDS.jpg
[2000/06/08 12:00:00 | 000,093,040 | -HS- | M] () – C:\COMMAND.COM
[2007/02/11 15:55:14 | 000,002,197 | —- | M] () – C:\COMPATID.TXT
[2007/02/02 22:35:40 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/02/02 22:35:40 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2005/02/28 05:00:30 | 000,017,031 | —- | M] () – C:\DEL
[2007/01/21 10:41:08 | 000,050,405 | -HS- | M] () – C:\DETLOG.OLD
[2007/01/21 12:26:56 | 000,050,405 | -HS- | M] () – C:\DETLOG.TXT
[2009/08/11 08:53:05 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2009/07/20 08:57:38 | 003,594,989 | —- | M] () – C:\EasyShare.dmp
[2007/09/02 20:20:06 | 000,004,915 | -H– | M] () – C:\ffastun.ffa
[2007/09/02 20:20:03 | 001,474,560 | -H– | M] () – C:\ffastun.ffl
[2007/09/02 20:20:06 | 000,819,200 | -H– | M] () – C:\ffastun.ffo
[2007/09/02 20:20:03 | 013,987,840 | -H– | M] () – C:\ffastun0.ffx
[2008/02/13 17:48:02 | 000,019,456 | —- | M] () – C:\FORGETFUL.doc
[2008/03/26 17:18:15 | 000,022,528 | —- | M] () – C:\heim_tax_worksheet_2007.xls
[2007/08/24 10:46:58 | 000,499,132 | —- | M] () – C:\hpfr3900.log
[2000/06/08 12:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2005/09/22 15:30:14 | 000,000,207 | -H– | M] () – C:\IPH.PH
[2003/12/27 07:59:18 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2003/12/27 08:01:42 | 000,008,076 | -HS- | M] () – C:\NETLOG.TXT
[2007/08/25 16:39:30 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2008/08/18 20:56:31 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/02/20 13:04:56 | 000,022,016 | —- | M] () – C:\Optical.exe
[2010/08/31 08:39:57 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2010/04/21 10:40:07 | 000,000,028 | —- | M] () – C:\pending.un
[2010/08/18 10:41:04 | 000,000,441 | —- | M] () – C:\rkill.log
[2010/08/23 09:39:53 | 000,014,268 | —- | M] () – C:\SAFEBOOT_REPAIR.TXT
[2007/08/24 17:10:46 | 000,000,634 | -H– | M] () – C:\SCANDISK.LOG
[2007/03/24 14:30:30 | 000,226,091 | -HS- | M] () – C:\SETUPLOG.TXT
[2003/12/27 15:17:08 | 000,000,202 | —- | M] () – C:\SETUPXLG.TXT
[2003/12/27 07:54:16 | 000,005,166 | -HS- | M] () – C:\SUHDLOG.DAT
[2003/12/27 07:54:16 | 000,499,744 | -HS- | M] () – C:\SYSTEM.1ST
[2004/03/19 12:47:18 | 000,000,000 | —- | M] () – C:\temp.html
[2003/03/31 07:00:00 | 000,454,830 | R— | M] () – C:\txtsetup.sif
[2010/01/12 17:11:37 | 000,000,838 | —- | M] () – C:\updatedatfix.log
[2003/12/27 13:51:44 | 000,000,010 | RH– | M] () – C:\VIDC.ZFR
[2003/12/27 07:58:52 | 000,045,568 | -HS- | M] () – C:\VIDEOROM.BIN
[2004/03/05 16:33:46 | 000,000,063 | —- | M] () – C:\WINDOWSWinHlp32.BMK
[2007/08/24 11:31:54 | 000,005,464 | —- | M] () – C:\winzip.log
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007/08/25 00:50:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\FONTS\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/04/08 21:43:36 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[1996/11/17 00:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\ArtGalry.cag
[2008/10/18 00:46:43 | 000,001,682 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/10/03 22:06:53 | 000,029,696 | —- | M] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2004/03/08 14:19:30 | 000,000,354 | -HS- | M] () – C:\Program Files\desktop.ini
[2003/12/27 08:00:36 | 000,023,357 | -H– | M] () – C:\Program Files\folder.htt
[2004/03/08 14:19:32 | 000,002,238 | -H– | M] () – C:\Program Files\Ikona1021944043.ico
[2005/02/11 21:00:58 | 013,951,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/08/24 17:27:10 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\config\default.sav
[2007/08/24 17:27:10 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\config\software.sav
[2007/08/24 17:27:10 | 000,405,504 | —- | M] () – C:\WINDOWS\SYSTEM32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/18 21:08:42 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/18 21:32:01 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/08/25 00:56:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 03:12:19
========== Alternate Data Streams ==========
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:22:10.85 on Tue 08/31/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1354 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
svchost.exe 4
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
svchost.exe 4
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.cnn.com/
uDefault_Page_URL = hxxp://www.msn.com
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [tcactive] "c:\program files\the cleaner7\tcap.exe"
uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [PMBVolumeWatcher] "c:\program files\sony\pmb\PMBVolumeWatcher.exe"
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: 0.0.0.0
Trusted Zone: christushealth.org\my
Trusted Zone: microsoft.com\oas.support
Trusted Zone: microsoft.com \support
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\eudora\EuShlExt.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\frolfaoz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
FF - plugin: c:\documents and settings\administrator\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\firefox2009\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\firefox2009\plugins\npMozCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox2009\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\firefox2009\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\firefox2009\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\firefox2009\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\firefox2009\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\firefox2009\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\firefox2009\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\firefox2009\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\firefox2009\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\firefox2009\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\firefox2009\greprefs\all.js - pref("geo.enabled", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-11 64288]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-4-21 29808]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-7 11608]
R1 NEOFLTR_650_15507;Juniper Networks TDI Filter Driver (NEOFLTR_650_15507);c:\windows\system32\drivers\NEOFLTR_650_15507.SYS [2010-4-21 85360]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-7 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-7 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-7 56816]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2009-10-24 360224]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-13 24652]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2009-7-20 1201640]
S2 moohelp;The Cleaner 2011 Helper Service;c:\program files\the cleaner7\mhelper.exe [2010-6-14 813056]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [2007-8-25 80000]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?]
S4 BCSWAP;BCSWAP;c:\windows\system32\drivers\BCSwap.sys [2002-8-16 83456]
=============== Created Last 30 ================
2010-08-26 17:48 –d—– c:\windows\system32\wbem\New Folder
2010-08-25 17:37 –d—– c:\program files\Spybot - Search & Destroy
2010-08-25 17:37 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-24 21:06 95,024 a——- c:\windows\system32\drivers\SBREDrv.sys
2010-08-24 16:58 -cd-h— c:\docume~1\alluse~1\applic~1\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-24 08:41 –d—– c:\program files\safeboot tools
2010-08-23 09:26 –d—– c:\program files\undelete safeboot fix
2010-08-19 22:37 664 a——- c:\windows\system32\d3d9caps.dat
2010-08-18 09:18 –d—– c:\windows\system32\wbem\Repository
==================== Find3M ====================
2010-08-12 07:15 15,880 ac—— c:\windows\system32\lsdelete.exe
2010-08-12 07:15 64,288 a——- c:\windows\system32\drivers\Lbd.sys
2010-06-30 07:31 149,504 a——- c:\windows\system32\schannel.dll
2010-06-24 07:10 667,136 a——- c:\windows\system32\wininet.dll
2010-06-24 07:10 81,920 a——- c:\windows\system32\ieencode.dll
2010-06-23 08:44 1,851,904 a——- c:\windows\system32\win32k.sys
2010-06-17 09:03 80,384 a——- c:\windows\system32\iccvid.dll
2010-06-14 09:31 744,448 a——- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 02:41 1,172,480 a——- c:\windows\system32\msxml3.dll
2007-10-03 22:06 29,696 ac—— c:\program files\4E90396851764FA59BAE4EFBBC94F08D.db
2005-02-11 21:00 13,951,112 ac—— c:\program files\Win MEdia Player 9-Setup.exe
2004-03-08 14:19 2,238 ac–h— c:\program files\Ikona1021944043.ico
2004-03-08 14:19 354 ac-sh— c:\program files\desktop.ini
2003-12-27 08:00 23,357 ac–h— c:\program files\folder.htt
2009-08-09 01:44 245,760 ac-sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat
============= FINISH: 11:22:54.93 ===============