fmedwards3
Topic Starter
Running Winxp, sp3.
Unable to update Microsoft Security Essentials, Malwarebyte's Anti-malware, Spybot Search and Destroy or Lavasoft Adaware.
Error messages indicate internet connection is not working, but I can browse using Firefox.
One of the programs above gave me an error message of cannot connect to 127.0.0.1, so maybe this is a hosts file problem?
___________________________
OTL logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – c:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
========== Driver Services (SafeList) ==========
DRV - (UIUSys) – C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (PTDCWWAN) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm) PANTECH PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCBus) PANTECH PC Card Composite Device Driver (UDP) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (DigimHID) – C:\WINDOWS\system32\drivers\DigimHID.SYS (ACE CAD Enterprise Co., Ltd.)
DRV - (AWGNA54) – C:\WINDOWS\system32\drivers\AWGNA54.sys (Ativa)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/done.html
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: [removed]:1.94.20100904
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 00:28:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 00:28:11 | 000,000,000 | —D | M]
[2009/12/27 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Extensions
[2010/09/12 10:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions
[2010/04/28 21:29:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/12 10:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/12 10:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2009/12/27 19:29:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/27 23:04:47 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
O1 HOSTS File: ([2010/08/22 17:22:36 | 000,000,024 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: $Temporary GISTS fuke
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] c:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ativa Wireless Utility.lnk = C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe File not found
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1256571913274 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-861567501-789336058-1343024091-1005 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/26 01:13:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell - "" = AutoRun
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 60 Days ==========
[2010/09/12 15:10:02 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/11 21:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu
[2010/09/06 22:35:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\taifypqtu
[2010/09/05 14:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\mfxgosviv
[2010/09/03 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/03 20:08:29 | 000,000,000 | —D | C] – C:\Program Files\BatteryBar
[2010/09/02 08:29:50 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2010/09/02 08:29:50 | 000,126,976 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2010/09/02 08:29:50 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2010/09/02 08:29:46 | 000,194,560 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2010/09/02 08:29:44 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/09/02 08:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Bullzip
[2010/09/02 08:24:46 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comdlg32.OCX
[2010/09/01 17:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/09/01 17:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Office Genuine Advantage
[2010/08/29 21:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/29 21:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/08/29 21:48:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/29 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/08/29 21:47:32 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple Computer
[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/26 12:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for xx Sep 2010
[2010/08/26 09:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for 24 Aug 2010
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Opera
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Opera
[2010/08/22 22:14:37 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Anti-Malware
[2010/08/22 15:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Malwarebytes
[2010/08/22 15:42:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/22 15:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/22 15:42:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/22 15:42:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/20 18:31:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\fme\My Documents\My Data Sources
[2010/08/16 06:48:49 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/16 06:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/08/16 06:48:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/15 23:00:48 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Google
[2010/08/14 21:56:41 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/18 20:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\Flash Drive Backup
[2010/07/17 13:03:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\DSL
[2010/07/17 12:28:02 | 000,000,000 | -H-D | C] – C:\Program Files\InstallJammer Registry
[2010/07/17 12:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Thinstation-2.2.2
[2010/07/14 22:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/12 15:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/12 14:34:28 | 000,099,840 | —- | M] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:52:15 | 000,001,893 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/12 09:52:05 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/12 09:52:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/12 09:51:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/12 09:51:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/12 09:50:55 | 008,126,464 | -H– | M] () – C:\Documents and Settings\fme\NTUSER.DAT
[2010/09/12 09:50:32 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\fme\ntuser.ini
[2010/09/12 09:50:21 | 005,890,164 | -H– | M] () – C:\Documents and Settings\fme\Local Settings\Application Data\IconCache.db
[2010/09/11 21:53:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/11 06:41:29 | 000,025,088 | —- | M] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:27:44 | 000,024,576 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:23:03 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/08 22:22:08 | 000,126,796 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:53:03 | 000,047,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:12 | 000,252,902 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:39:25 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 09:54:03 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/04 00:24:12 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 23:09:09 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:11:24 | 000,001,415 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:37:32 | 000,154,624 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 02:19:12 | 000,148,480 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:47:05 | 000,131,584 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/03 01:06:42 | 000,077,760 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 13:14:31 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 13:11:22 | 000,134,656 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:51:40 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 11:25:36 | 000,134,144 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 10:43:59 | 000,132,608 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | M] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:31:46 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:53:04 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/09/01 22:14:03 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/09/01 17:39:31 | 001,007,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/29 21:49:08 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/26 02:01:50 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 01:39:00 | 000,155,319 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:04 | 000,450,560 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/26 00:58:45 | 000,447,488 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 23:30:10 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:40:40 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/24 21:49:58 | 000,394,997 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:16:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/22 22:14:42 | 000,000,610 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 17:22:36 | 000,000,024 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/22 15:42:54 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 06:48:14 | 000,000,885 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/15 12:21:37 | 000,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/15 11:55:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/15 11:52:32 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/15 11:49:28 | 000,540,530 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/15 11:49:28 | 000,472,704 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/15 11:49:28 | 000,077,870 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/14 00:30:01 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/12 16:16:07 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/08/12 16:13:00 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 16:01:28 | 000,027,136 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/27 01:28:54 | 008,463,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/12 10:44:41 | 000,099,840 | —- | C] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/11 06:36:18 | 000,025,088 | —- | C] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:15:27 | 000,024,576 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:22:07 | 000,126,796 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:45:07 | 000,047,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:11 | 000,252,902 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:34:52 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 00:24:21 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/03 23:09:31 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 20:24:34 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:08:30 | 000,001,415 | —- | C] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:39:28 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/03 02:34:28 | 000,154,624 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 01:47:41 | 000,148,480 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:06:41 | 000,077,760 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 23:41:52 | 000,131,584 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/02 13:14:31 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 11:55:17 | 000,134,656 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:27:23 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 10:45:31 | 000,134,144 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | C] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:33:19 | 000,132,608 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/01 22:56:21 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:22:46 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/08/29 21:49:08 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/29 21:47:59 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/29 19:11:16 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/26 02:02:05 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/08/26 01:38:59 | 000,155,319 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:14 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 00:58:56 | 000,450,560 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/25 23:30:24 | 000,447,488 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 22:44:33 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:20:39 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/25 13:52:25 | 000,394,997 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:11:03 | 000,006,296 | —- | C] () – C:\Documents and Settings\fme\reset.log
[2010/08/22 22:14:42 | 000,000,610 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 15:42:54 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 08:45:31 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/16 06:49:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/16 06:48:14 | 000,000,885 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 11:08:52 | 001,007,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/14 00:35:53 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/12 15:44:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/12 15:18:20 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 14:31:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/05/31 18:26:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/29 12:08:25 | 000,000,126 | —- | C] () – C:\Documents and Settings\fme\Local Settings\Application Data\fusioncache.dat
[2009/12/28 11:38:15 | 000,073,414 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/12/27 23:24:51 | 000,076,407 | —- | C] () – C:\Documents and Settings\fme\Application Data\Smiley.ico
[2009/10/26 02:01:52 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2009/10/26 01:51:33 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/26 01:46:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/10/26 01:09:30 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2009/10/26 01:09:30 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2009/10/26 01:09:30 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/12/29 11:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2009/12/29 12:34:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Embarcadero
[2009/12/29 12:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27}
[2010/08/16 06:48:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2010/09/11 17:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/02 08:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Bullzip
[2009/12/29 12:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\CodeGear
[2009/12/27 23:05:07 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit
[2010/05/06 11:23:24 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit Software
[2010/04/02 23:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\kompozer.net
[2010/08/22 22:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Opera
[2010/03/30 19:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Smith Micro
[2010/05/16 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Thinstall
[2010/09/12 15:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/09/12 09:51:33 | 000,005,162 | —- | M] () – C:\aaw7boot.log
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/10/26 01:06:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/12 09:51:33 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/08/22 18:45:46 | 000,000,383 | —- | M] () – C:\rkill.log
[2010/08/22 19:14:31 | 000,034,250 | —- | M] () – C:\TDSSKiller.2.4.1.2_22.08.2010_19.14.06_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/10/26 01:13:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/10/24 19:29:16 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/24 19:29:15 | 001,073,152 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/24 19:29:15 | 000,823,296 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/26 01:13:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 12:13:08
< End of report >
________________________
OTL Extras logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_USERS\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1" = KompoZer 0.8b3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{50EF6812-7B51-4459-A52D-B4776DAAA415}" = ACECAD DigiMemo Manager
"{57EC5BFE-7CB7-3057-8385-C9D72918511C}" = Microsoft .NET Framework 4 Client Profile Beta 2
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E405B40-3879-3C9B-9286-8D5E71258C35}" = Microsoft .NET Framework 4 Extended Beta 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo Delphi
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AA74ED37-681C-4AE8-8D1D-5485EBB3ED3D}" = SQL Server System CLR Types
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE65493C-EA18-3458-AA58-EEDB9D671528}" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"{D95AA4F4-9FCF-4BD8-AC07-AB1912A202E2}_is1" = Home Plan Pro version 5.2.18.17
"{DB6F07FF-A436-453a-B685-F6C1F4F09D22}" = PANTECH PC Card Software
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E69974C9-ECDC-4B02-97EB-FB1CE638CECB}" = Web Deployment Tool
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1
"{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F07737AC-C218-4272-A678-26CA5F6CD8DF}" = Opera 10.61
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ABC Amber Photoshop Converter" = ABC Amber Photoshop Converter
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Foxit Toolbar
"BatteryBar" = BatteryBar (remove only)
"Belarc Advisor" = Belarc Advisor 8.1
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"DynoPlex eOffice" = DynoPlex eOffice
"Foxit Reader" = Foxit Reader
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"ie8" = Windows Internet Explorer 8
"InstallShield_{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile Beta 2" = Microsoft .NET Framework 4 Client Profile Beta 2
"Microsoft .NET Framework 4 Extended Beta 2" = Microsoft .NET Framework 4 Extended Beta 2
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Home Design - Platinum" = Punch! Home Design - Platinum
"RealVNC_is1" = VNC Free Edition 4.1.3
"uTorrent" = µTorrent
"Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"VZAccess Manager" = VZAccess Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/12/2010 10:45:59 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 10:51:48 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 10:52:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 11:47:51 fme | Computer Name = LATITUDE505 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3888, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 9/12/2010 12:39:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 12:44:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 2:25:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 2:29:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 4:06:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 4:23:02 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
[ System Events ]
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 12:16:07 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established
Error - 9/12/2010 2:52:52 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 4:27:22 fme | Computer Name = LATITUDE505 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
< End of report >
Unable to update Microsoft Security Essentials, Malwarebyte's Anti-malware, Spybot Search and Destroy or Lavasoft Adaware.
Error messages indicate internet connection is not working, but I can browse using Firefox.
One of the programs above gave me an error message of cannot connect to 127.0.0.1, so maybe this is a hosts file problem?
___________________________
OTL logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – c:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
========== Driver Services (SafeList) ==========
DRV - (UIUSys) – C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (PTDCWWAN) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm) PANTECH PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCBus) PANTECH PC Card Composite Device Driver (UDP) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (DigimHID) – C:\WINDOWS\system32\drivers\DigimHID.SYS (ACE CAD Enterprise Co., Ltd.)
DRV - (AWGNA54) – C:\WINDOWS\system32\drivers\AWGNA54.sys (Ativa)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/done.html
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: [removed]:1.94.20100904
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 00:28:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 00:28:11 | 000,000,000 | —D | M]
[2009/12/27 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Extensions
[2010/09/12 10:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions
[2010/04/28 21:29:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/12 10:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/12 10:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2009/12/27 19:29:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/27 23:04:47 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
O1 HOSTS File: ([2010/08/22 17:22:36 | 000,000,024 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: $Temporary GISTS fuke
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] c:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ativa Wireless Utility.lnk = C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe File not found
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1256571913274 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-861567501-789336058-1343024091-1005 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/26 01:13:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell - "" = AutoRun
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 60 Days ==========
[2010/09/12 15:10:02 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/11 21:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu
[2010/09/06 22:35:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\taifypqtu
[2010/09/05 14:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\mfxgosviv
[2010/09/03 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/03 20:08:29 | 000,000,000 | —D | C] – C:\Program Files\BatteryBar
[2010/09/02 08:29:50 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2010/09/02 08:29:50 | 000,126,976 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2010/09/02 08:29:50 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2010/09/02 08:29:46 | 000,194,560 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2010/09/02 08:29:44 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/09/02 08:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Bullzip
[2010/09/02 08:24:46 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comdlg32.OCX
[2010/09/01 17:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/09/01 17:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Office Genuine Advantage
[2010/08/29 21:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/29 21:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/08/29 21:48:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/29 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/08/29 21:47:32 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple Computer
[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/26 12:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for xx Sep 2010
[2010/08/26 09:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for 24 Aug 2010
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Opera
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Opera
[2010/08/22 22:14:37 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Anti-Malware
[2010/08/22 15:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Malwarebytes
[2010/08/22 15:42:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/22 15:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/22 15:42:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/22 15:42:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/20 18:31:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\fme\My Documents\My Data Sources
[2010/08/16 06:48:49 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/16 06:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/08/16 06:48:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/15 23:00:48 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Google
[2010/08/14 21:56:41 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/18 20:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\Flash Drive Backup
[2010/07/17 13:03:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\DSL
[2010/07/17 12:28:02 | 000,000,000 | -H-D | C] – C:\Program Files\InstallJammer Registry
[2010/07/17 12:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Thinstation-2.2.2
[2010/07/14 22:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/12 15:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/12 14:34:28 | 000,099,840 | —- | M] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:52:15 | 000,001,893 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/12 09:52:05 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/12 09:52:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/12 09:51:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/12 09:51:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/12 09:50:55 | 008,126,464 | -H– | M] () – C:\Documents and Settings\fme\NTUSER.DAT
[2010/09/12 09:50:32 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\fme\ntuser.ini
[2010/09/12 09:50:21 | 005,890,164 | -H– | M] () – C:\Documents and Settings\fme\Local Settings\Application Data\IconCache.db
[2010/09/11 21:53:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/11 06:41:29 | 000,025,088 | —- | M] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:27:44 | 000,024,576 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:23:03 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/08 22:22:08 | 000,126,796 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:53:03 | 000,047,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:12 | 000,252,902 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:39:25 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 09:54:03 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/04 00:24:12 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 23:09:09 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:11:24 | 000,001,415 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:37:32 | 000,154,624 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 02:19:12 | 000,148,480 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:47:05 | 000,131,584 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/03 01:06:42 | 000,077,760 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 13:14:31 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 13:11:22 | 000,134,656 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:51:40 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 11:25:36 | 000,134,144 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 10:43:59 | 000,132,608 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | M] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:31:46 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:53:04 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/09/01 22:14:03 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/09/01 17:39:31 | 001,007,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/29 21:49:08 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/26 02:01:50 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 01:39:00 | 000,155,319 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:04 | 000,450,560 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/26 00:58:45 | 000,447,488 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 23:30:10 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:40:40 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/24 21:49:58 | 000,394,997 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:16:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/22 22:14:42 | 000,000,610 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 17:22:36 | 000,000,024 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/22 15:42:54 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 06:48:14 | 000,000,885 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/15 12:21:37 | 000,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/15 11:55:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/15 11:52:32 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/15 11:49:28 | 000,540,530 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/15 11:49:28 | 000,472,704 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/15 11:49:28 | 000,077,870 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/14 00:30:01 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/12 16:16:07 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/08/12 16:13:00 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 16:01:28 | 000,027,136 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/27 01:28:54 | 008,463,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/12 10:44:41 | 000,099,840 | —- | C] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/11 06:36:18 | 000,025,088 | —- | C] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:15:27 | 000,024,576 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:22:07 | 000,126,796 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:45:07 | 000,047,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:11 | 000,252,902 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:34:52 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 00:24:21 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/03 23:09:31 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 20:24:34 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:08:30 | 000,001,415 | —- | C] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:39:28 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/03 02:34:28 | 000,154,624 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 01:47:41 | 000,148,480 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:06:41 | 000,077,760 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 23:41:52 | 000,131,584 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/02 13:14:31 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 11:55:17 | 000,134,656 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:27:23 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 10:45:31 | 000,134,144 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | C] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:33:19 | 000,132,608 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/01 22:56:21 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:22:46 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/08/29 21:49:08 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/29 21:47:59 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/29 19:11:16 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/26 02:02:05 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/08/26 01:38:59 | 000,155,319 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:14 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 00:58:56 | 000,450,560 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/25 23:30:24 | 000,447,488 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 22:44:33 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:20:39 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/25 13:52:25 | 000,394,997 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:11:03 | 000,006,296 | —- | C] () – C:\Documents and Settings\fme\reset.log
[2010/08/22 22:14:42 | 000,000,610 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 15:42:54 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 08:45:31 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/16 06:49:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/16 06:48:14 | 000,000,885 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 11:08:52 | 001,007,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/14 00:35:53 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/12 15:44:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/12 15:18:20 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 14:31:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/05/31 18:26:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/29 12:08:25 | 000,000,126 | —- | C] () – C:\Documents and Settings\fme\Local Settings\Application Data\fusioncache.dat
[2009/12/28 11:38:15 | 000,073,414 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/12/27 23:24:51 | 000,076,407 | —- | C] () – C:\Documents and Settings\fme\Application Data\Smiley.ico
[2009/10/26 02:01:52 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2009/10/26 01:51:33 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/26 01:46:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/10/26 01:09:30 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2009/10/26 01:09:30 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2009/10/26 01:09:30 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/12/29 11:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2009/12/29 12:34:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Embarcadero
[2009/12/29 12:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27}
[2010/08/16 06:48:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2010/09/11 17:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/02 08:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Bullzip
[2009/12/29 12:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\CodeGear
[2009/12/27 23:05:07 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit
[2010/05/06 11:23:24 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit Software
[2010/04/02 23:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\kompozer.net
[2010/08/22 22:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Opera
[2010/03/30 19:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Smith Micro
[2010/05/16 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Thinstall
[2010/09/12 15:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/09/12 09:51:33 | 000,005,162 | —- | M] () – C:\aaw7boot.log
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/10/26 01:06:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/12 09:51:33 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/08/22 18:45:46 | 000,000,383 | —- | M] () – C:\rkill.log
[2010/08/22 19:14:31 | 000,034,250 | —- | M] () – C:\TDSSKiller.2.4.1.2_22.08.2010_19.14.06_log.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/10/26 01:13:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/10/24 19:29:16 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/24 19:29:15 | 001,073,152 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/24 19:29:15 | 000,823,296 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/26 01:13:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 12:13:08
< End of report >
________________________
OTL Extras logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_USERS\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1" = KompoZer 0.8b3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{50EF6812-7B51-4459-A52D-B4776DAAA415}" = ACECAD DigiMemo Manager
"{57EC5BFE-7CB7-3057-8385-C9D72918511C}" = Microsoft .NET Framework 4 Client Profile Beta 2
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E405B40-3879-3C9B-9286-8D5E71258C35}" = Microsoft .NET Framework 4 Extended Beta 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo Delphi
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AA74ED37-681C-4AE8-8D1D-5485EBB3ED3D}" = SQL Server System CLR Types
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE65493C-EA18-3458-AA58-EEDB9D671528}" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"{D95AA4F4-9FCF-4BD8-AC07-AB1912A202E2}_is1" = Home Plan Pro version 5.2.18.17
"{DB6F07FF-A436-453a-B685-F6C1F4F09D22}" = PANTECH PC Card Software
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E69974C9-ECDC-4B02-97EB-FB1CE638CECB}" = Web Deployment Tool
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1
"{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F07737AC-C218-4272-A678-26CA5F6CD8DF}" = Opera 10.61
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ABC Amber Photoshop Converter" = ABC Amber Photoshop Converter
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Foxit Toolbar
"BatteryBar" = BatteryBar (remove only)
"Belarc Advisor" = Belarc Advisor 8.1
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"DynoPlex eOffice" = DynoPlex eOffice
"Foxit Reader" = Foxit Reader
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"ie8" = Windows Internet Explorer 8
"InstallShield_{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile Beta 2" = Microsoft .NET Framework 4 Client Profile Beta 2
"Microsoft .NET Framework 4 Extended Beta 2" = Microsoft .NET Framework 4 Extended Beta 2
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Home Design - Platinum" = Punch! Home Design - Platinum
"RealVNC_is1" = VNC Free Edition 4.1.3
"uTorrent" = µTorrent
"Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"VZAccess Manager" = VZAccess Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/12/2010 10:45:59 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 10:51:48 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 10:52:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 11:47:51 fme | Computer Name = LATITUDE505 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3888, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 9/12/2010 12:39:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 12:44:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 2:25:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 2:29:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 4:06:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 9/12/2010 4:23:02 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
[ System Events ]
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 12:16:07 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established
Error - 9/12/2010 2:52:52 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE
Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established
Error - 9/12/2010 4:27:22 fme | Computer Name = LATITUDE505 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
< End of report >