This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Old PC - freezes

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

1. I have an old PC that I've kept limping along. This week it started freezing up, requiring a re-boot.
Yesterday, it refused to boot up in anything but safe mode - and McAfee virus scanning is shut off and will NOT restart. So I can't scan - would like to get this going again. I have a clean backup from about two months ago and most files have been saved to an external drive, which is good.

2. OTL,txt

OTL logfile created on: 9/12/2010 12:54:20 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Sara Byron\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 78.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 864 1728 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 5.26 Gb Free Space | 4.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 99.21 Gb Free Space | 33.28% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FAMILYDELL
Current User Name: Sara Byron
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sara Byron\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Sara Byron\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Pml Driver HPZ12) – C:\WINDOWS\System32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (spupdsvc) – C:\WINDOWS\SYSTEM32\spupdsvc.exe (Microsoft Corporation)
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\SYSTEM32\UAService7.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (IAANTMon) – C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe (Intel)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (SQLAgent$MICROSOFTBCM) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (iAimTV2) – C:\WINDOWS\System32\DRIVERS\wATV03nt.sys File not found
DRV - (gameenum) – C:\WINDOWS\System32\DRIVERS\gameenum.sys File not found
DRV - (CamAv) – C:\WINDOWS\System32\Drivers\CamAv.sys File not found
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys ()
DRV - (PCLEPCI) – C:\WINDOWS\SYSTEM32\DRIVERS\Pclepci.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\SYSTEM32\DRIVERS\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\SYSTEM32\DRIVERS\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\SYSTEM32\DRIVERS\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (szkg5) – C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (MPE) – C:\WINDOWS\SYSTEM32\DRIVERS\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (PalmUSBD) – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys (PalmSource, Inc.)
DRV - (emAudio) – C:\WINDOWS\SYSTEM32\DRIVERS\emAudio.sys (Pinnacle Systems GmbH)
DRV - (MDFSYSNT) – C:\WINDOWS\System32\drivers\MDFSYSNT.SYS (Mediafour Corporation)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (DCamUSBEMPIA) – C:\WINDOWS\SYSTEM32\DRIVERS\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINDOWS\SYSTEM32\DRIVERS\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINDOWS\SYSTEM32\DRIVERS\emScan.sys (eMPIA Technology, Inc.)
DRV - (MDPMGRNT) – C:\WINDOWS\System32\drivers\MDPMGRNT.SYS (Mediafour Corporation)
DRV - (MarvinBus) – C:\WINDOWS\SYSTEM32\DRIVERS\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (DVDAccss) – C:\WINDOWS\SYSTEM32\DRIVERS\DVDAccss.sys (Apple Computer, Inc.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (ctdvda2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\SYSTEM32\DRIVERS\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys (Creative Technology Ltd.)
DRV - (emupia) – C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys (Creative Technology Ltd)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\PFC.SYS (Padus, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://member.square-enix.com/na/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.ravelry.com/account/login|http://www.att.net|http://www.voy.com/33031/|http://central.hinsdale86.org/Daily%20Announcements/Forms/AllItems.aspx|http://mail.google.com/mail/?source=navclient-ff&zx;=1w0tkde3j7rys&shva;=1#inbox|http://www.facebook.com/login.php?v=1.0&api;_key=e004be66908863e93f45ec5853daecba&next;=%3Faction%3Dseal%26id%3D856664843%26skip%3D856664843&canvas;|http://www.atlasquest.com/people/profile.html|http://www.hcbands.org/|http://www.fiberfarm.com/blog"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=IEFM1&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{1650a312-02bc-40ee-977e-83f158701739}: C:\Program Files\SiteAdvisor\4144\FF\ [2006/10/20 13:11:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 22:11:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 22:11:51 | 000,000,000 | —D | M]

[2008/08/30 14:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Extensions
[2010/09/09 22:22:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\extensions
[2010/05/04 08:14:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/22 13:56:54 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/05/04 08:14:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2008/11/12 09:32:23 | 000,001,739 | —- | M] () – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\searchplugins\aim-search.xml
[2009/03/09 00:16:26 | 000,001,632 | —- | M] () – C:\Documents and Settings\Sara Byron\Application Data\Mozilla\Firefox\Profiles\sayrjs30.default\searchplugins\live-search.xml
[2010/09/09 22:22:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/27 17:16:24 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2007/05/11 17:41:00 | 000,200,704 | —- | M] (Ancestry.com) – C:\Program Files\Mozilla Firefox\plugins\npImgCtl.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/03/11 10:11:34 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100523150009.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google; Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google; Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk = C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe File not found
O4 - Startup: C:\Documents and Settings\Sara Byron\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…84/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1212589685328 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1124298262359 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,21/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\siteadvisor {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll (McAfee, Inc.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Sara Byron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sara Byron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/11 17:07:39 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/08/03 01:09:30 | 000,000,062 | —- | M] () - G:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: AppSecDll - (C:\Documents and Settings\Robert Jeffers\Local Settings\Application Data\Windows Server\opljlc.dll) - C:\Documents and Settings\Robert Jeffers\Local Settings\Application Data\Windows Server\opljlc.dll File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - vct3216.acm File not found
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.DRAW - DVIDEO.DLL File not found
Drivers32: VIDC.FPS1 - frapsvid.dll File not found
Drivers32: VIDC.I420 - i420vfw.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.MSUD - msulvc05.dll File not found
Drivers32: VIDC.PIM1 - pclepim1.dll File not found
Drivers32: VIDC.VP40 - vp4vfw.dll File not found
Drivers32: vidc.VP60 - vp6vfw.dll File not found
Drivers32: vidc.VP61 - vp6vfw.dll File not found
Drivers32: vidc.VP62 - vp6vfw.dll File not found
Drivers32: vidc.VP70 - vp7vfw.dll File not found
Drivers32: VIDC.WMV3 - wmv9vcm.dll File not found
Drivers32: vidc.X264 - x264vfw.dll File not found
Drivers32: VIDC.YV12 - yv12vfw.dll File not found

CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.

========== Files/Folders - Created Within 30 Days ==========

[2010/09/12 12:52:42 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sara Byron\Desktop\OTL.exe
[2010/09/12 12:52:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Sara Byron\My Documents\Downloads
[2004/12/23 23:53:48 | 000,036,963 | R— | C] (Cypress Semiconductor) – C:\Program Files\Common Files\SM1updtr.dll
[2004/03/29 17:00:30 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[6 C:\Documents and Settings\Sara Byron\My Documents\*.tmp files -> C:\Documents and Settings\Sara Byron\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/12 12:52:42 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sara Byron\Desktop\OTL.exe
[2010/09/12 12:34:52 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/09/12 12:25:11 | 000,002,048 | —- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/12 12:15:08 | 000,000,402 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C1000964-AA95-4E84-990A-2DFD6562E161}.job
[2010/09/12 12:11:41 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/11 21:58:28 | 009,437,184 | -H– | M] () – C:\Documents and Settings\Sara Byron\NTUSER.DAT
[2010/09/11 21:58:28 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Sara Byron\ntuser.ini
[2010/09/10 18:01:48 | 000,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/09/10 18:01:48 | 000,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/09/10 18:01:48 | 000,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/09/10 18:01:48 | 000,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/09/10 18:01:48 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/09/10 18:01:48 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/09/10 18:01:48 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/09/10 18:01:48 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/09/09 22:11:12 | 000,065,826 | —- | M] () – C:\Documents and Settings\Sara Byron\My Documents\CK flower.tif
[2010/09/09 22:03:52 | 000,406,840 | —- | M] () – C:\Documents and Settings\Sara Byron\My Documents\carole sig.tif
[2010/09/09 22:01:28 | 000,083,352 | —- | M] () – C:\Documents and Settings\Sara Byron\My Documents\devil horn trace.tif
[2010/09/06 23:09:13 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/08/29 22:12:13 | 000,083,456 | —- | M] () – C:\Documents and Settings\Sara Byron\My Documents\LTC label.doc
[2010/08/25 18:19:02 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/24 15:59:40 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/08/23 20:32:34 | 000,041,984 | —- | M] () – C:\Documents and Settings\Sara Byron\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\Documents and Settings\Sara Byron\My Documents\*.tmp files -> C:\Documents and Settings\Sara Byron\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/09 22:11:12 | 000,065,826 | —- | C] () – C:\Documents and Settings\Sara Byron\My Documents\CK flower.tif
[2010/09/09 22:03:52 | 000,406,840 | —- | C] () – C:\Documents and Settings\Sara Byron\My Documents\carole sig.tif
[2010/09/09 22:01:28 | 000,083,352 | —- | C] () – C:\Documents and Settings\Sara Byron\My Documents\devil horn trace.tif
[2010/07/21 11:15:11 | 000,000,876 | —- | C] () – C:\WINDOWS\ILload.INI
[2010/06/10 14:13:30 | 000,000,410 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/14 09:20:02 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2009/04/19 09:41:27 | 000,002,528 | —- | C] () – C:\Documents and Settings\Sara Byron\Application Data\$_hpcst$.hpc
[2009/03/01 12:25:06 | 000,000,094 | —- | C] () – C:\WINDOWS\family.ini
[2009/02/22 09:50:03 | 001,380,403 | —- | C] () – C:\WINDOWS\System32\avgsdk.dll
[2009/02/22 09:20:44 | 000,000,264 | —- | C] () – C:\WINDOWS\reimage.ini
[2008/05/02 13:55:37 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\HPPLVS.dll
[2008/04/21 08:25:39 | 000,000,014 | —- | C] () – C:\WINDOWS\hpmssnpjt.ini
[2008/03/31 20:28:10 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/03/20 09:24:43 | 000,484,352 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2008/03/20 09:24:43 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\DVResampleru.dll
[2008/03/19 16:19:21 | 000,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2008/03/19 16:17:10 | 000,014,165 | —- | C] () – C:\WINDOWS\System32\drivers\Pclepci.sys
[2008/02/12 22:13:17 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2008/02/12 22:13:17 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2008/02/12 22:13:16 | 000,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2008/02/12 22:13:16 | 000,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2008/02/12 22:13:16 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2008/01/01 19:41:39 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/01/01 19:39:04 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Sci-Fi
[2008/01/01 19:39:04 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2007/06/11 14:24:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\hppatusg01.dll
[2007/03/27 02:55:48 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/01/26 18:07:09 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/12 11:24:42 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/10/25 11:22:26 | 000,000,000 | —- | C] () – C:\WINDOWS\HPMProp.INI
[2006/10/25 11:21:58 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2006/10/22 09:00:15 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/07/14 12:01:07 | 000,003,344 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/08 11:11:57 | 000,057,344 | —- | C] () – C:\WINDOWS\HAJEInstall.dll
[2006/02/06 14:25:47 | 000,002,890 | —- | C] () – C:\WINDOWS\fecfile.ini
[2006/02/06 13:25:47 | 000,001,186 | —- | C] () – C:\WINDOWS\FECLoad.ini
[2006/02/06 13:25:47 | 000,000,102 | —- | C] () – C:\WINDOWS\FECHECK5.INI
[2006/01/13 21:51:54 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2006/01/13 21:51:54 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\lfkodak.dll
[2006/01/13 21:51:53 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\cdTextCtl.dll
[2005/12/19 15:42:57 | 000,000,766 | —- | C] () – C:\WINDOWS\CoD.INI
[2005/11/01 16:34:13 | 000,000,074 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2005/10/29 21:28:47 | 000,000,037 | —- | C] () – C:\WINDOWS\Viewer.ini
[2005/10/28 21:41:07 | 000,000,031 | —- | C] () – C:\WINDOWS\SimPark.ini
[2005/09/23 06:20:07 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\rfwdres.dll
[2005/09/23 06:20:07 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\rfshext.dll
[2005/09/23 06:20:07 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\rfhres.dll
[2005/09/23 06:20:07 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\rfshres.dll
[2005/09/23 06:20:07 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\rfstrres.dll
[2005/09/22 08:13:43 | 000,041,984 | —- | C] () – C:\Documents and Settings\Sara Byron\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/07/31 12:35:25 | 000,001,751 | —- | C] () – C:\WINDOWS\IDIS.INI
[2005/07/29 13:38:24 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2005/06/20 21:32:15 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2005/03/05 22:55:22 | 000,000,119 | —- | C] () – C:\WINDOWS\NNS.INI
[2005/01/25 18:00:27 | 000,000,316 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/12/25 19:56:13 | 000,000,248 | —- | C] () – C:\WINDOWS\RomeTW.ini
[2004/12/21 11:49:55 | 000,000,133 | —- | C] () – C:\Documents and Settings\Sara Byron\Local Settings\Application Data\fusioncache.dat
[2004/11/23 21:29:25 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/11/20 16:43:34 | 000,000,043 | —- | C] () – C:\WINDOWS\KA.INI
[2004/11/13 18:50:28 | 000,000,449 | —- | C] () – C:\WINDOWS\JUNO.INI
[2004/10/29 21:25:35 | 000,000,675 | —- | C] () – C:\WINDOWS\Spidey.ini
[2004/10/23 21:20:18 | 000,000,041 | —- | C] () – C:\Documents and Settings\Sara Byron\Application Data\tvmcwrd.dll
[2004/10/03 11:59:06 | 000,000,029 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\tvmcwrd.dll
[2004/09/28 23:25:17 | 000,000,356 | —- | C] () – C:\WINDOWS\System32\CNCASv51.ini
[2004/09/28 23:25:16 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVSyf.DLL
[2004/09/28 23:25:10 | 000,000,599 | —- | C] () – C:\WINDOWS\System32\CNCMP51.INI
[2004/08/31 13:02:57 | 000,015,099 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/08/11 19:03:08 | 000,000,456 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/08/01 15:29:59 | 000,000,021 | —- | C] () – C:\WINDOWS\DVDSentry.ini
[2004/07/23 20:53:44 | 000,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2004/07/09 22:08:57 | 000,001,351 | —- | C] () – C:\WINDOWS\disney.ini
[2004/07/02 12:25:33 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2004/03/29 17:18:50 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/03/29 17:09:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/03/29 17:00:49 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/03/29 17:00:33 | 000,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2004/03/29 17:00:33 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/03/29 17:00:32 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2004/03/29 17:00:32 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2004/03/29 17:00:08 | 000,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/03/29 16:59:07 | 000,000,197 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/29 16:56:11 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/03/29 16:44:49 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/29 16:44:41 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/03/29 16:30:34 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/11/20 14:18:40 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/07/03 01:00:00 | 000,274,816 | —- | C] () – C:\WINDOWS\System32\drivers\iaStor.sys
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2000/01/28 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1980/01/01 01:00:00 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\e1000msg.dll

========== LOP Check ==========

[2008/01/01 19:41:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/07/02 22:56:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/03/03 14:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/02/25 11:29:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2007/03/04 20:27:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mediafour
[2004/09/28 22:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2005/02/27 19:43:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/01/01 19:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2008/03/19 16:25:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/03/19 16:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2008/10/13 14:25:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/05/11 20:10:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/03/11 00:00:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2008/10/13 16:11:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/10/12 19:05:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/10/01 16:18:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/01/01 19:41:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008/11/12 09:31:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/19 08:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/05/03 08:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/20 14:39:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/21 08:43:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/01/27 15:03:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\acccore
[2010/02/18 19:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Aim
[2009/12/03 13:01:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Amazon
[2010/02/12 16:52:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Canon
[2009/05/06 08:51:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\DNA
[2007/03/21 18:36:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Expedia
[2004/09/03 23:12:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\FileOpen
[2005/11/01 16:34:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\FTW
[2009/03/03 14:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\HotSync
[2010/03/22 13:17:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\KeePass
[2004/07/31 22:42:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Leadertech
[2007/09/20 22:04:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\NCH Swift Sound
[2008/05/29 08:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Netscape
[2009/03/08 22:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Nikon
[2008/11/24 21:30:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\OpenOffice.org
[2005/09/27 23:33:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\OurPictures
[2008/11/06 10:37:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\OverDrive
[2008/05/29 08:52:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Photodex
[2008/01/12 11:55:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\SmartDraw
[2006/05/21 13:02:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Snapfish
[2009/07/21 17:32:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\SPORE
[2008/09/13 17:14:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\SPORE Creature Creator
[2007/03/13 13:34:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\TrinityEnrollment
[2007/10/14 12:36:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Ulead Systems
[2007/06/07 21:34:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\Viewpoint
[2004/10/08 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\WeatherBug
[2007/09/16 23:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara Byron\Application Data\WinPatrol
[2010/02/16 09:57:05 | 000,000,270 | —- | M] () – C:\WINDOWS\Tasks\Backup.job
[2010/09/12 12:15:08 | 000,000,402 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1000964-AA95-4E84-990A-2DFD6562E161}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/12/09 08:37:15 | 000,019,932 | —- | M] () – C:\aaw7boot.log
[2010/06/01 08:53:26 | 000,002,092 | —- | M] () – C:\additdiag.txt
[2009/05/11 17:07:39 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/06 00:51:23 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/03/11 09:50:13 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2002/09/03 14:13:28 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2002/09/03 14:36:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/08/22 15:01:31 | 000,000,558 | —- | M] () – C:\debugInstaller.txt
[2004/03/29 16:36:46 | 000,006,062 | RH– | M] () – C:\DELL.SDR
[2007/07/02 14:40:15 | 000,009,075 | —- | M] () – C:\dnsbak.reg
[2007/07/27 15:02:20 | 000,001,339 | —- | M] () – C:\EasyShareInstall.log
[2006/09/09 13:07:17 | 000,000,000 | —- | M] () – C:\except.log
[2006/07/19 17:35:48 | 000,000,017 | —- | M] () – C:\gputest.txt
[2005/02/24 19:40:10 | 000,000,737 | —- | M] () – C:\inferno.log
[2005/07/13 00:07:46 | 000,002,886 | R— | M] () – C:\install.inf
[2002/09/03 14:36:02 | 000,000,000 | —- | M] () – C:\IO.SYS
[2008/11/12 09:32:07 | 000,003,703 | -H– | M] () – C:\IPH.PH
[2004/12/03 17:53:41 | 000,000,047 | —- | M] () – C:\kingdom_dbg.txt
[2009/01/30 12:14:04 | 000,006,329 | —- | M] () – C:\KnitAbleConDebug.log
[2006/09/09 13:24:37 | 000,001,016 | —- | M] () – C:\log.log
[2005/07/12 23:34:50 | 001,527,808 | R— | M] () – C:\mcs_cor2.dll
[2005/05/18 03:01:00 | 000,520,192 | R— | M] () – C:\mcs_core.dll
[2005/07/12 23:36:48 | 000,872,448 | R— | M] () – C:\mcs_dec.ax
[2005/06/30 18:16:20 | 000,131,072 | R— | M] () – C:\mcs_enc.ax
[2002/09/03 14:36:02 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2003/10/09 01:00:00 | 000,499,712 | R— | M] (Microsoft Corporation) – C:\msvcp71.dll
[2003/10/09 01:00:00 | 000,348,160 | R— | M] (Microsoft Corporation) – C:\msvcr71.dll
[2004/10/27 19:01:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/02 10:20:04 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/09/12 12:25:02 | 905,969,664 | -HS- | M] () – C:\pagefile.sys
[2009/01/26 22:09:49 | 000,007,168 | —- | M] () – C:\palm.grf
[2008/06/03 13:02:52 | 000,001,399 | —- | M] () – C:\photodex-presenter-install.log
[2004/11/20 16:41:39 | 000,000,056 | R— | M] () – C:\RAYMAN.BAT
[2009/02/22 09:51:54 | 000,000,649 | —- | M] () – C:\reimage.log
[2004/07/06 22:36:14 | 000,000,000 | —- | M] () – C:\report.txt
[2009/06/01 21:25:09 | 000,140,408 | —- | M] () – C:\Sonic-3D-Blast-(F)-[!].gs0
[2009/05/17 15:15:51 | 000,140,408 | —- | M] () – C:\Sonic-and-Knuckles-&-Sonic-3-(JUE)-[!].gs0
[2009/05/11 22:15:14 | 000,140,408 | —- | M] () – C:\Sonic-and-Knuckles-&-Sonic-3-(JUE)-[!].gs9
[2009/07/27 23:30:42 | 000,000,980 | —- | M] () – C:\Sonic-and-Knuckles-&-Sonic-3-(JUE)-[!].srm
[2009/06/16 15:08:45 | 000,140,408 | —- | M] () – C:\Sonic-and-Knuckles-(JUE)-[!].gs0
[2009/07/16 18:52:08 | 000,000,272 | —- | M] () – C:\Sonic-and-Knuckles-(JUE)-[!].srm
[2009/06/21 12:30:14 | 000,140,408 | —- | M] () – C:\Sonic-the-Hedgehog-(JUE)-[!].gs0
[2010/03/02 16:46:41 | 000,016,464 | —- | M] () – C:\TDSSKiller.2.2.7.1_02.03.2010_15.46.36_log.txt
[2006/09/09 13:24:30 | 000,001,290 | —- | M] () – C:\timer.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/03 14:35:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/09/05 05:00:00 | 000,016,384 | —- | M] (CANON INC.) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPDyf.DLL
[2003/09/05 05:00:00 | 000,048,128 | —- | M] (CANON INC.) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPPyf.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2007/08/06 13:41:08 | 000,229,888 | —- | M] (Hewlett-Packard ) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\HP1006S.DLL
[2006/06/29 18:34:20 | 000,066,048 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\hpzpp3xr.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/02/06 19:03:18 | 000,307,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/09/03 14:22:52 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 14:22:52 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 14:22:52 | 000,397,312 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/02 10:25:52 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/10/28 19:06:51 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Sara Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/07/01 23:10:15 | 000,000,079 | —- | M] () – C:\Documents and Settings\Sara Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/05/06 09:13:18 | 026,739,584 | —- | M] ( ) – C:\Documents and Settings\Sara Byron\Desktop\AdbeRdr910_en_US.exe
[2010/02/25 17:19:43 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Sara Byron\Desktop\erunt_setup.exe
[2010/07/06 08:51:56 | 008,589,088 | —- | M] (Mozilla) – C:\Documents and Settings\Sara Byron\Desktop\Firefox Setup 3.6.6.exe
[2010/03/22 13:13:43 | 001,934,507 | —- | M] (Dominik Reichl ) – C:\Documents and Settings\Sara Byron\Desktop\KeePass-2.10-Setup.exe
[2001/07/07 13:57:48 | 001,081,344 | —- | M] () – C:\Documents and Settings\Sara Byron\Desktop\Knitcomp 1024.exe
[2010/09/12 12:52:42 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sara Byron\Desktop\OTL.exe
[2010/02/25 17:18:33 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Sara Byron\Desktop\SysRestorePoint.exe
[2010/03/22 13:50:06 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sara Byron\Desktop\TFC.exe
[2009/11/22 15:51:52 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Documents and Settings\Sara Byron\Desktop\ZIPReader.exe

< %PROGRAMFILES%\Common Files\*.* >
[2003/08/27 15:19:18 | 000,036,963 | R— | M] (Cypress Semiconductor) – C:\Program Files\Common Files\SM1updtr.dll

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-11 19:12:31

========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:27AAAD97
< End of report >


EXTRAS content

OTL Extras logfile created on: 9/12/2010 12:54:20 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Sara Byron\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 78.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 864 1728 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 5.26 Gb Free Space | 4.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 99.21 Gb Free Space | 33.28% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FAMILYDELL
Current User Name: Sara Byron
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sony\Station\Launchpad\LaunchPad.exe" = C:\Program Files\Sony\Station\Launchpad\LaunchPad.exe:*:Enabled:LaunchPad – ()
"C:\Program Files\VentSrv\ventrilo_srv.exe" = C:\Program Files\VentSrv\ventrilo_srv.exe:*:Disabled:ventrilo_srv – ()
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HP1006MC.EXE" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE – (Software 2000 Limited)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – File not found
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{37EBB600-EAA2-012B-AD89-000000000000}" = TurboTax 2009 wiliper
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{606BC780-101C-41DB-808D-4539BFA0774A}" = MobileMe Control Panel
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{DB0BB9FA-1B60-4036-8E29-3D56D8085256}" = WOT for Internet Explorer
"{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}" = Safari
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"{FF1482CF-D19B-44DD-B887-9698CB51DFD5}" = Studio 10.8 Patch
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.5
"AU10_is1" = Advanced Uninstaller PRO - Version 10
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CleanUp!" = CleanUp!
"Click'N Design 3D" = Click'N Design 3D
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"ERUNT_is1" = ERUNT 1.1j
"FECfile" = FECfile
"FECfile5.3.1.0" = FECfile
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.8.0
"HandAble.com KnitAble for PalmOS" = HandAble.com KnitAble for PalmOS
"HP LaserJet P1000 series" = HP LaserJet P1000 series
"IDIS" = IDIS
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War™
"InterActual Player" = InterActual Player
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.10
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"MS Access 97 SP2" = MS Access 97 SP2
"MSC" = McAfee AntiVirus Plus
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"pdfFactory" = pdfFactory
"Photodex Presenter" = Photodex Presenter
"PictureProject In Touch Downloader" = PictureProject In Touch Downloader 1.0
"proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
"PROSet" = Intel® PRO Network Adapters and Drivers
"ProShow Gold" = ProShow Gold
"Raining Poogles" = Raining Poogles Screen Saver
"SM1FX_AT" = USB Storage Adapter FX (SM1)
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareGuard_is1" = SpywareGuard v2.2
"Switch" = Switch
"TeamSpeak 2 Server_is1" = TeamSpeak 2 Server RC2
"TurboTax 2009" = TurboTax 2009
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"W2 Mate (2006)_is1" = W2 Mate (2006) 2.0
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Mobile Device Handbook" = Windows Mobile® Device Handbook
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/10/2010 11:53:41 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/11/2010 3:09:25 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/11/2010 3:12:10 PM | Computer Name = FAMILYDELL | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft .NET Framework 1.1 – Error 1706.No valid source
could be found for product Microsoft .NET Framework 1.1. The Windows installer
cannot continue.

Error - 9/11/2010 3:12:16 PM | Computer Name = FAMILYDELL | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{2A3320D6-C805-4280-B423-B665BDE33D8F}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\TEMP\NDP1.1sp1-KB979906-X86\NDP1.1sp1-KB979906-X86-msi.0.log.

Error - 9/11/2010 3:12:18 PM | Computer Name = FAMILYDELL | Source = NativeWrapper | ID = 5000
Description =

Error - 9/11/2010 6:40:10 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/11/2010 8:09:11 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/11/2010 9:18:01 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/11/2010 9:28:44 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

Error - 9/12/2010 1:12:21 PM | Computer Name = FAMILYDELL | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 3

[ System Events ]
Error - 9/12/2010 1:27:40 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:40 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:27:41 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 9/12/2010 1:35:08 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/12/2010 1:48:50 PM | Computer Name = FAMILYDELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}


< End of report >

Thanks in advance for your help - you guys are always the most help!

Sara
Hi Patrick's Mom,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Drive C: | 111.72 Gb Total Space | 5.26 Gb Free Space | 4.71% Space Free

This will need to be addressed once this machine is clean.



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O36 - AppCertDlls: AppSecDll - (C:\Documents and Settings\Robert Jeffers\Local Settings\Application Data\Windows Server\opljlc.dll) - C:\Documents and Settings\Robert Jeffers\Local Settings\Application Data\Windows Server\opljlc.dll File not found

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • When OTL reboots the machine, boot back to safe mode.
  • Please save the resulting log to be posted in your next reply.
Please post the OTL log.



Please read through these instructions to familarize yourself with what to expect when this tool runs

Your security programs will not be running while in safe mode. You will not be able to disable them. Should Combofix reboot the computer, boot back to safe mode and let combofix finish, save the log and try to boot to normal windows.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTL fix log
  • Combofix log
Are you in normal windows?

Thanks
Hello - thanks for the help. THis may be bigger than you and I. My first concern was your observation that there is very little space on this machine. THere should be plenty of space on there - as we've been saving stuff to an external drive. Unles my daughter has been saving stuff that I don't know about. I booted into safe mode and ran the script that you sent with OTL. When the PC rebooted, it booted to a blank screen. I get a quick screen that says hit F1 for settings or F12 for … whatever, I forget. I have a boot CD - Hiren's boot CD and a system recovery CD. Made them last Feb when this PC was badly infected. I;ve tried to get t his thing to boot a few times - I superstitiously let it rest for an hour or two - still no response. If it helps, you can read my last session with CatByte. This may be a case of going to MicroCenter for a new PC. What do you now suggest? Sara
Hi Patrick's Mom, Did you try booting to normal windows? I believe the F12 message is an option to choose what to boot from. Try booting again, if you receive the message again hit F12. You should be presented a list of items to boot from. Choose your hard drive. Let us know if you successfully booted the computer. If successful Do not run combofix at this time. Thanks
Hey again. I had already tried many boot options. But I tried them all again - with no luck. When the PC powers up, it boots to a blank screen. While the PC is booting up, I can hit F12 and choose the boot options. It does not boot when I chose normal - still a blank screen. It does not boot to C: drive. - Same result, blank screen. It does not boot to CD, with the Hirens boot CD in the drive. I did try kicking it - with no different results. There is nothing critical on the hard drive - but there are some photos that my daughter would like to recover. She wasn't suppose to be saving photos there anyway - but I'd like to get them for her if I can. Anything else I can do, or should I take it to MicroCenter and get them to try to boot to an external drive to access whatever might be left on the hard drive? Sara
Hi Patrick's Mom, Not be able to boot to a cd indicates the possibility of bigger problems. When you tried was your bios configured to boot from a CD? Each computer is different as for what key to start tapping when the computer first starts. Usually during the initial stages of a bootup a screen will display the name of the key to enter the bios. On yours it may be the F1 key.. Once you have entered the bios look for a menu similar to boot order. Follow the instructions on that screen to set CD/DVD first. save the setting and exit. Turn off the computer. Try using your windows CD and see if you can enter the Recovery Console. Let me know how you make out. If you can get into the Recovery console we may be able to do a windows repair or some other small tasks to see if we can get the computer to boot. I see in your previous thread you had a similar problem with the boot.ini file. Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer. 1. Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted. 2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console. 3. You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?" Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1. 4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER. You should now have a C:\windows> prompt For now just see if you can get that far As a side note MicroCente may be able to slave your HD to a computer and recover the pictures.
Thanks for the reply. I will admit that I am sometimes an idiot. I was trying to boot to the DVD player and not the CD. I ran diagnostics on the PC and everything checked out OK. Then I booted to the System recover console. When I chose R for Windows XP recovery, it told me that there is not a hard drive in the PC. I stuff it down and opened everything up and wiggled connections - dusted a bit, although it wasn't too dusty - disconnected the hard drive and reconnected it. Put it back together and re-booted to the System Conole and got the same thing. I then shut it down and rebooted to the Hiren's boot CD successfully also - At one point it asked for a Windows recover DISKETTE - and I don;t have one - I looked through all my stuff and I don't have anything on diskettes. I did find a very old 5 1/4 floppy that amused me. Guess I should clean my desk more often. While running the diagnostics, I would swear that the diagnostics was scanning the hard drive - but the recover CD says it is not there. Anything else I can do? Sara
Hi Patrick's Mom,

Please do not try too many things on your own, we may loose track of what was tried and wasn't.

We can check a couple of things. Please refer to the instructions for booting to the recovery console
  • at exaclty which point did you receive the no Hard drive message?
  • were you given the option to install additional drivers at any time?

Reboot your computer and enter the bios. Find the section for Hard Drives. Does bios report any hard drives? If so please post the make and model of the hard drive.

Please post the make and model of your computer.

Thanks
I believe that I have been following your instructions. If you think that I am not, then I must not be communicating what I am doing in your technical language – so I will respond step-by-step from now on.
Each computer is different as for what key to start tapping when the computer first starts. Usually during the initial stages of a bootup a screen will display the name of the key to enter the bios. On yours it may be the F1 key.. Once you have entered the bios look for a menu similar to boot order. Follow the instructions on that screen to set CD/DVD first. save the setting and exit. Turn off the computer.
My computer says press F2 to enter Setup. That includes a menu to set the boor order. It is, and has been set to boot to the CD first.

Try using your windows CD and see if you can enter the Recovery Console. Let me know how you make out. If you can get into the Recovery console we may be able to do a windows repair or some other small tasks to see if we can get the computer to boot. I see in your previous thread you had a similar problem with the boot.ini file.
I have a recovery console CD that I made last February while working with CatByte. I can boot to this Recovery Console CD.

Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer. I do not have an XP startup disk. I have OS disks that say to only use them if I am re-installing.

1. Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted. I already did that when I went into the setup by hitting F2. I did it again, and it is still set to boot to CD first.
2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console. Did that. Through the Recovery Console CD.
3. You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?" When I chose R, I get the response that the Recovery Console does not detect a hard drive. It says that it cannot proceed, and to hit F3 to quit.
Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1. I cannot get this far.
4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER. . I cannot get this far. But there isn’t a password anyway.


You should now have a C:\windows> prompt . No, because I cannot get this far.

Your last message: We can check a couple of things. Please refer to the instructions for booting to the recovery console What instructions? I only have a System Recover Disk that I made with CatBYte last February. I did not make an instruction guide for it.
• at exaclty which point did you receive the no Hard drive message? After the System Recovery process asked me to chose R to repair the XP installation.
• were you given the option to install additional drivers at any time? NO.


Reboot your computer and enter the bios. Find the section for Hard Drives. Does bios report any hard drives? If so please post the make and model of the hard drive. I cannot find an area that tells me about my hard drives. There is a prompt that says that SATA RAID is ON. DO you want me to open the PC and record the hard drive info?

Please post the make and model of your computer. It is a Dell Dimension XPS – from 2004. Kinda old.

Hope this helps. I do have the Hirens disk that I made with CatByte last February.
Hi Patrick's Mom

I believe that I have been following your instructions. If you think that I am not, then I must not be communicating what I am doing in your technical language – so I will respond step-by-step from now on.

You're doing fine. You tried to boot to Hirem's and I wanted to make sure you didn't attempt any changes to your machine.

I do not have an XP startup disk. I have OS disks that say to only use them if I am re-installing.

I was refering to the XP installation disk you used to try to rebuild the boot cfg. You seemed to be able to enter the Recovery Console with it.
http://forums.whatthetech.com/index.php?sh…st&p=638245

That includes a menu to set the boor order. It is, and has been set to boot to the CD first.

But I didn't know that. When you posted you couldn't boot to the CD, not having it set correctly in the bios is the usuall suspect.

What instructions?

The ones I gave you a couple of posts back. You did follow them and pinpointed the spot you recieved the message.

at exaclty which point did you receive the no Hard drive message? After the System Recovery process asked me to chose R to repair the XP installation.
• were you given the option to install additional drivers at any time? NO.

Good. At least we know how far you can get.

I cannot find an area that tells me about my hard drives. There is a prompt that says that SATA RAID is ON. DO you want me to open the PC and record the hard drive info?

Now that we know what computer you have we may be able to find out more about the bios and the various sections. Let me check into it a bit more. It may be the RAID that is the problem. Knowing which HD you have may be benificial as we might be able to get a diagnostics tool from the manufacturer. So if you don't mind….

Hope this helps

Yes it does. :thumbup:
Glad we're back on track. I won't go too far without you, but sometimes, it is obvious what to do next. Here is theinfo on the hard drive: Maxtor Diamond Max Plus 9 120 GB SATA/150 HDD 3.5 Series
Sorry that it took so long to respond. I had to go to Michigan for an Irish Dance competition with my daughter and there was NO WIFI at the cottage that we rented! It was TERRIBLE! But fun anyway. SO I had to borrow a PC with a CD burner - but got it done today. The Quick test showed no errors on the HD. The regular test also showed no errors on the hard drive. Is there anything else that I should do? The tutorial goes on to tell me how to try to fix errors, but I didn't get any errors. Next?
Hi

Glad you had fun. :thumbup:

Well at least we know the HD is there. Let's make sure it hasn't been disabled in the bios. We'll also set it to boot first.

Enter the bios as you did before (F2 key) and locate this setting Boot Sequence

  • Use the arrow keys to highlight the Boot Sequence menu option and press to access
  • NOTE: Write down your current boot sequence in case you want to restore it.
  • Press the up- and down-arrow keys to move through the list of devices.
  • Make sure the hard Drive is not set to Disabled (enabled devices have a checkmark)
  • Press the spacebar to enable or disable a device if the hard drive is found to be disabled .
  • Move the Hard Drive to the top of the list.
  • Press plus (+) or minus (–) to move a selected device up or down the list.
If you needed to make any changes there should be an option to" Save changes and exit" or "save changes and exit". Do not change anything else.

Let me know what you find.
OK I did that. I'm not sure what you expected to happen, but what happened is what I expected. ANd that was nothing. I saved the change and it booted to a blank screen. Then I did a hard reboot and it booted to the same blank screen - if I turn off all the lights, the screen flickers a bit, but nothing ever happens. Is there anything that this Hiren's Boot CD could do for us?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI