OTL logfile created on: 10/22/2010 12:18:23 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\patricia\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.81 Gb Total Space | 112.69 Gb Free Space | 51.74% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.91 Gb Free Space | 99.41% Space Free | Partition Type: NTFS
Computer Name: PATRICIA-PC | User Name: patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\patricia\AppData\Roaming\Microsoft\svchost.exe ()
PRC - C:\Users\patricia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\patricia\AppData\Local\temp\dwm.exe ()
PRC - C:\Users\patricia\AppData\Roaming\Microsoft\Windows\shell.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe ()
PRC - C:\Program Files\Vidalia Bundle\Tor\tor.exe ()
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Vidalia Bundle\Polipo\polipo.exe ()
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell DataSafe Local Backup\SftService.exe (SoftThinks)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\AOL 9.1\shellmon.exe (AOL, LLC.)
PRC - C:\Program Files\AOL 9.1\waol.exe (AOL, LLC.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Common Files\aol\1247175231\ee\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
========== Modules (SafeList) ==========
MOD - C:\Users\patricia\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (TabQuery Service) – C:\ProgramData\TabQuery\tabquery119.exe File not found
SRV - (MyWebSearchService) – C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe File not found
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SftService) – C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (Netaapl) – C:\Windows\System32\drivers\netaapl.sys (Apple Inc.)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (CtClsFlt) – C:\Windows\System32\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (PCD5SRVC{3F6A8B78-EC003E00-05040104}) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (k57nd60x) Broadcom NetLink ™ – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKLM\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.2.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: openinregedit@firefox:0.1.2.4
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/20 14:02:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/20 14:02:05 | 000,000,000 | —D | M]
[2010/03/21 21:03:44 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Extensions
[2009/09/13 18:32:03 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/03/21 21:03:44 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\extensions
[2010/03/21 21:03:44 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\extensions\[removed]
[2010/10/21 23:49:15 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\Profiles\88udgmg2.default\extensions
[2010/05/24 17:59:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\Profiles\88udgmg2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/24 17:59:24 | 000,000,000 | —D | M] (No name found) – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\Profiles\88udgmg2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}-trash
[2010/09/23 15:33:06 | 000,000,000 | —D | M] (Torbutton) – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\Profiles\88udgmg2.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010/09/02 20:54:38 | 000,000,000 | —D | M] – C:\Users\patricia\AppData\Roaming\Mozilla\Firefox\Profiles\88udgmg2.default\extensions\openinregedit@firefox
[2010/10/19 22:20:29 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/08 19:36:17 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/24 14:57:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
O1 HOSTS File: ([2009/09/10 15:22:19 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Freecause Toolbar BHO) - {399C60D2-38B1-4E25-B9E7-6498C1BC2DCD} - C:\Program Files\Dogpile Toolbar\Toolbar.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100916034804.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Dogpile Toolbar) - {C53FE659-316A-4F56-A194-A5BE491BE866} - C:\Program Files\Dogpile Toolbar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Dogpile Toolbar) - {C53FE659-316A-4F56-A194-A5BE491BE866} - C:\Program Files\Dogpile Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1247175231\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL 9.1\AOL.EXE (AOL, LLC.)
O4 - HKCU..\Run: [svchost] C:\Users\patricia\AppData\Roaming\Microsoft\svchost.exe ()
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Vidalia] C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe ()
O4 - Startup: C:\Users\patricia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
F3 - HKCU WinNT: Load - (C:\Users\patricia\AppData\Local\Temp\dwm.exe) - C:\Users\patricia\AppData\Local\temp\dwm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr =
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Go PlaySushi! - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\patricia\AppData\Roaming\Microsoft\Windows\shell.exe) - C:\Users\patricia\AppData\Roaming\Microsoft\Windows\shell.exe ()
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\patricia\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\patricia\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~2\SPYWAR~1\sp_rsdel.exe \??\C:\PROGRA~2\SPYWAR~1\sp_rsdel.dat) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\scg726.acm (SHARP Corporation)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
MsConfig - StartUpFolder: C:^Users^patricia^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk - C:\PROGRA~1\MICROS~3\Office12\ONENOTEM.EXE - File not found
MsConfig - StartUpReg:
Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
PDVDDXSrv - hkey= - key= - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
MsConfig - StartUpReg:
StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig - StartUpReg:
SunJavaUpdateSched - hkey= - key= - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg:
WMPNSCFG - hkey= - key= - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - C:\Windows\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootMin: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - C:\Windows\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: McMPFSvc - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet: mcmscsvc - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet: MCODS - C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootNet: Messenger - File not found
SafeBootNet: mfefire - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SafeBootNet: mfefirek - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet: mfefirek.sys - C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet: mfehidk - C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfehidk.sys - C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet: mfevtp - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/10/22 11:04:02 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\patricia\Desktop\OTL.exe
[2010/10/21 19:36:19 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Elephant Games
[2010/10/21 19:36:19 | 000,000,000 | —D | C] – C:\ProgramData\Elephant Games
[2010/10/21 19:35:01 | 000,000,000 | —D | C] – C:\Program Files\Mystery Trackers - The Void Collector's Edition
[2010/10/21 12:09:16 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\patricia\Desktop\HijackThis.exe
[2010/10/21 12:00:16 | 000,000,000 | —D | C] – C:\Windows\en
[2010/10/21 11:59:35 | 000,039,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fssfltr.sys
[2010/10/21 11:54:41 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/10/21 11:54:22 | 000,000,000 | —D | C] – C:\Program Files\Bing Bar Installer
[2010/10/21 11:54:17 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2010/10/21 11:54:17 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2010/10/21 11:54:17 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/10/21 11:35:56 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Local\Windows Live
[2010/10/21 11:34:54 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/10/19 11:00:51 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2010/10/19 10:58:17 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2010/10/19 10:58:03 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2010/10/19 10:58:03 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2010/10/19 10:58:03 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2010/10/19 10:58:00 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2010/10/19 10:58:00 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2010/10/19 10:57:59 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2010/10/19 10:57:59 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2010/10/19 10:57:59 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2010/10/19 10:57:59 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2010/10/19 10:57:58 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2010/10/19 10:57:53 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2010/10/19 10:57:53 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2010/10/19 10:57:53 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2010/10/19 10:57:53 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2010/10/19 10:57:53 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2010/10/18 22:01:29 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\Dirty Dancing 1987 20th Anniversary Edition DvDrip[Eng]-greenbud1969
[2010/10/14 17:10:53 | 000,000,000 | —D | C] – C:\Program Files\Paltalk Messenger
[2010/10/14 16:52:11 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/14 16:51:20 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/14 16:50:36 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/14 16:50:29 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/14 16:50:29 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/14 16:50:29 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/14 16:50:28 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/14 16:50:28 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/14 16:50:28 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/14 16:50:28 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/14 16:50:27 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/14 16:50:27 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/14 16:50:27 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/14 16:50:27 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/14 16:50:27 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/14 16:50:27 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/14 16:50:27 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/14 16:50:27 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/14 16:50:27 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/14 16:50:27 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/14 16:50:22 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/14 16:50:22 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/14 16:50:19 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/14 16:50:16 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/14 16:50:14 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/10 19:04:25 | 000,000,000 | —D | C] – C:\Program Files\Redemption Cemetery - Curse of the Raven
[2010/10/10 13:53:00 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\Jersey Shore - Season 01
[2010/10/08 13:01:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/10/05 03:11:05 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Paltalk
[2010/10/03 17:33:11 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\Sons of Anarchy Season 1 & 2
[2010/10/03 17:14:25 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\Linkin_Park-A_Thousand_Suns-2010-pLAN9
[2010/09/30 16:29:06 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\images
[2010/09/28 19:04:04 | 000,000,000 | —D | C] – C:\Users\patricia\Desktop\Human Weapon
[2010/09/28 18:23:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/28 16:20:00 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Notepad++
[2010/09/28 16:20:00 | 000,000,000 | —D | C] – C:\Program Files\Notepad++
[2010/09/24 18:31:15 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Ghost Ship Studios
[2010/09/24 16:43:46 | 000,000,000 | —D | C] – C:\Program Files\Nightmare Adventures - The Witch's Prison
[2010/09/23 15:32:52 | 000,000,000 | —D | C] – C:\Program Files\Vidalia Bundle
[2010/09/23 15:32:52 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Vidalia
[2010/09/23 15:28:56 | 000,000,000 | —D | C] – C:\Users\patricia\AppData\Roaming\Tor
[2010/09/23 00:47:28 | 000,049,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[2010/09/23 00:32:56 | 000,301,936 | —- | C] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2010/09/02 20:22:56 | 000,047,360 | —- | C] (VSO Software) – C:\Users\patricia\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2010/10/22 12:21:04 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/22 12:14:14 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/22 12:14:14 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/22 12:14:08 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/22 12:14:07 | 000,000,246 | —- | M] () – C:\Windows\tasks\PersonalSec.job
[2010/10/22 12:13:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/22 12:13:50 | 3213,815,808 | -HS- | M] () – C:\hiberfil.sys
[2010/10/22 11:05:16 | 000,294,912 | —- | M] () – C:\Users\patricia\Desktop\lerkblms.exe
[2010/10/22 11:04:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\patricia\Desktop\OTL.exe
[2010/10/22 10:11:39 | 000,381,248 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/21 22:10:15 | 000,050,176 | —- | M] () – C:\Users\patricia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/21 22:07:43 | 000,000,000 | -H– | M] () – C:\Users\patricia\Documents\Default.rdp
[2010/10/21 21:52:11 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{3665EB40-7FE9-4CC9-A94B-EAE9FD7003FC}.job
[2010/10/21 19:35:48 | 000,002,007 | —- | M] () – C:\Users\Public\Desktop\Play Mystery Trackers - The Void Collector's Edition.lnk
[2010/10/21 19:35:48 | 000,001,260 | —- | M] () – C:\Users\Public\Desktop\More Great Games.lnk
[2010/10/21 12:09:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\patricia\Desktop\HijackThis.exe
[2010/10/19 15:50:52 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/10/17 19:08:52 | 006,600,795 | —- | M] () – C:\Users\patricia\Documents\Monkey_with_a_deathwish.wmv
[2010/10/10 19:06:17 | 000,001,952 | —- | M] () – C:\Users\Public\Desktop\Play Redemption Cemetery - Curse of the Raven.lnk
[2010/10/03 18:35:24 | 000,134,733 | —- | M] () – C:\Users\patricia\Documents\IMG00377-20100925-1846.jpg
[2010/09/24 16:44:48 | 000,001,947 | —- | M] () – C:\Users\Public\Desktop\Play Nightmare Adventures - The Witch's Prison.lnk
[2010/09/24 16:40:21 | 000,001,686 | —- | M] () – C:\Users\patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2010/09/24 16:40:21 | 000,001,662 | —- | M] () – C:\Users\Public\Desktop\Game Manager.lnk
[2010/09/23 00:47:28 | 000,049,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2010/09/23 00:21:24 | 000,039,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\fssfltr.sys
[2010/09/22 20:49:12 | 000,242,684 | —- | M] () – C:\Users\patricia\Documents\Momma_Mia.jpg
[2010/09/22 20:47:20 | 002,236,416 | —- | M] () – C:\Users\patricia\Documents\BrazilGrannies1.pps
========== Files Created - No Company Name ==========
[2010/10/22 11:05:15 | 000,294,912 | —- | C] () – C:\Users\patricia\Desktop\lerkblms.exe
[2010/10/21 22:07:43 | 000,000,000 | -H– | C] () – C:\Users\patricia\Documents\Default.rdp
[2010/10/21 19:35:48 | 000,002,007 | —- | C] () – C:\Users\Public\Desktop\Play Mystery Trackers - The Void Collector's Edition.lnk
[2010/10/21 19:35:48 | 000,001,260 | —- | C] () – C:\Users\Public\Desktop\More Great Games.lnk
[2010/10/19 10:57:54 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2010/10/19 10:57:54 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2010/10/19 10:57:54 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2010/10/17 19:08:41 | 006,600,795 | —- | C] () – C:\Users\patricia\Documents\Monkey_with_a_deathwish.wmv
[2010/10/10 19:06:17 | 000,001,952 | —- | C] () – C:\Users\Public\Desktop\Play Redemption Cemetery - Curse of the Raven.lnk
[2010/10/03 18:35:23 | 000,134,733 | —- | C] () – C:\Users\patricia\Documents\IMG00377-20100925-1846.jpg
[2010/09/24 16:44:48 | 000,001,947 | —- | C] () – C:\Users\Public\Desktop\Play Nightmare Adventures - The Witch's Prison.lnk
[2010/09/22 20:49:11 | 000,242,684 | —- | C] () – C:\Users\patricia\Documents\Momma_Mia.jpg
[2010/09/22 20:47:16 | 002,236,416 | —- | C] () – C:\Users\patricia\Documents\BrazilGrannies1.pps
[2010/09/02 20:22:56 | 000,087,608 | —- | C] () – C:\Users\patricia\AppData\Roaming\inst.exe
[2010/09/02 20:22:56 | 000,007,887 | —- | C] () – C:\Users\patricia\AppData\Roaming\pcouffin.cat
[2010/09/02 20:22:56 | 000,001,144 | —- | C] () – C:\Users\patricia\AppData\Roaming\pcouffin.inf
[2010/09/02 20:22:56 | 000,000,055 | —- | C] () – C:\Users\patricia\AppData\Roaming\pcouffin.log
[2010/08/31 22:00:15 | 000,000,146 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/08 19:39:39 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/01 11:22:12 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/16 19:17:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/14 09:39:45 | 000,050,176 | —- | C] () – C:\Users\patricia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/26 18:38:24 | 000,007,728 | —- | C] () – C:\Users\patricia\AppData\Local\d3d9caps.dat
[2009/06/30 14:21:40 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2009/06/30 11:48:49 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2009/06/30 11:48:48 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/10/28 03:55:19 | 000,000,095 | —- | M] () – C:\9.Pr0_Collect.dat
[2009/08/11 17:32:27 | 000,000,461 | —- | M] () – C:\aaw7boot.log
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/09/07 21:51:53 | 000,000,000 | —- | M] () – C:\backup.reg
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/09/07 21:51:48 | 000,000,574 | —- | M] () – C:\cleanup.bat
[2009/09/10 18:01:48 | 000,024,328 | —- | M] () – C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/06/30 14:21:51 | 000,005,234 | RH– | M] () – C:\dell.sdr
[2010/10/22 12:13:50 | 3213,815,808 | -HS- | M] () – C:\hiberfil.sys
[2010/04/22 16:33:01 | 000,000,000 | —- | M] () – C:\install.rdf
[2009/09/06 22:00:42 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/09/06 22:00:42 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/10/22 12:13:49 | 3529,682,944 | -HS- | M] () – C:\pagefile.sys
[2009/09/10 20:21:22 | 000,001,838 | —- | M] () – C:\RootRepeal.txt
[2009/09/07 21:51:48 | 000,135,168 | —- | M] () – C:\zip.exe
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/11 17:52:24 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 22:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/11/28 10:40:05 | 000,003,656 | -HS- | M] () – C:\Windows\System32\spool\prtprocs\w32x86\OneNote Table Of Contents.onetoc2
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/10/22 00:23:34 | 000,019,967 | —- | M] () – C:\Users\patricia\AppData\Roaming\Microsoft\stor.cfg
[2010/10/22 12:14:26 | 000,096,256 | —- | M] () – C:\Users\patricia\AppData\Roaming\Microsoft\svchost.exe
< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2009/11/03 17:36:34 | 000,003,656 | -HS- | M] () – C:\Windows\System32\config\systemprofile\OneNote Table Of Contents.onetoc2
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/09/07 15:46:37 | 000,000,286 | -HS- | M] () – C:\Users\patricia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/10/21 12:09:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\patricia\Desktop\HijackThis.exe
[2010/10/22 11:05:16 | 000,294,912 | —- | M] () – C:\Users\patricia\Desktop\lerkblms.exe
[2010/10/22 11:04:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\patricia\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2010/03/29 09:44:39 | 000,061,224 | —- | M] () – C:\Users\patricia\GoToAssistDownloadHelper.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/07/08 16:40:49 | 000,000,402 | -HS- | M] () – C:\Users\patricia\Favorites\desktop.ini
[2010/10/13 18:50:02 | 000,001,158 | —- | M] () – C:\Users\patricia\Favorites\WildTangent Games.lnk
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/10/19 15:50:52 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.exe >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< %USERPROFILE%\Templates\*.tmp >
< %SYSTEMDRIVE%\explorexxx.exe\*.* >
< %Windir%\Installer\*.tmp >
< %systemroot%\System32\*.xco >
< %ProgramFiles%\system32\*.* >
< %systemroot%\System32\windos\*.* >
< %SystemRoot%\system32\sandbox\*.* >
< %SystemRoot%\system32\*.amo >
< %SystemRoot%\system32\Windows Live\*.* >
< %ProgramFiles%\logs\*.* >
< %ProgramFiles%\Bifrost\*.* >
< %SystemRoot%\system32\*.goo >
< %systemroot%\system32\IME\*.* >
[2009/11/03 17:36:24 | 000,003,656 | -HS- | M] () – C:\Windows\System32\IME\OneNote Table Of Contents.onetoc2
< %systemroot%\BackUp\*.* >
< %systemroot%\system32\*.ico >
[2006/09/18 17:31:55 | 000,107,620 | —- | M] () – C:\Windows\System32\acwizard.ico
< %systemroot%\system\*.dat >
< %systemroot%\system\*.exe >
< %AppData%\Macromedia\Common\*.* >
< %SYSTEMDRIVE%\dir\*.* /s >
< %systemroot%\system32\ras\*.exe >
< %SYSTEMDRIVE%\MFILES\*.* >
< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >
< %systemroot%\system32\services\*.* >
< %systemroot%\Spooler\*.* >
< %ProgramFiles%\system32\*.* >
< %systemroot%\system32\Setup\*.dll /x >
[2009/11/03 17:36:14 | 000,003,656 | -HS- | M] () – C:\Windows\System32\setup\OneNote Table Of Contents.onetoc2
< %systemroot%\system32\*.mine >
< %SYSTEMDRIVE%\cleansweep.exe\*.* >
< %systemroot%\system32\ras\*.dll >
< %systemroot%\system32\ras\*.drv >
< %systemroot%\*.iq >
< %systemroot%\system32\XP\*.* >
< %SYSTEMDRIVE%\Extracted\*.* >
< %systemroot%\system32\windows\*.* >
< %systemroot%\logs\*.* >
[2010/10/21 11:54:18 | 000,337,806 | —- | M] () – C:\Windows\Logs\DirectX.log
< %SYSTEMDRIVE%\Win.Msi\*.* >
< %systemroot%\regedit\*.* >
< %systemroot%\system32\skype\*.* >
< %AppData%\Adobe\dlluplwin25\*.* >
< %UserProfile%\*.dat >
[2010/08/01 19:01:39 | 000,000,046 | —- | M] () – C:\Users\patricia\jagex_runescape_preferences.dat
[2010/08/01 19:02:24 | 000,000,099 | —- | M] () – C:\Users\patricia\jagex_runescape_preferences2.dat
[2010/08/01 18:50:57 | 000,000,000 | —- | M] () – C:\Users\patricia\jagex__preferences3.dat
[2010/10/22 12:28:50 | 003,407,872 | -HS- | M] () – C:\Users\patricia\NTUSER.DAT
< %UserProfile%\*.dll >
< %systemroot%\system32\*.sxo >
< %SYSTEMDRIVE%\Gazma\*.* /s >
< %systemroot%\system32\spynet\*.* >
< %systemroot%\system32\System\*.* >
< %appdata%\Microsoft\Windows\*.* >
[2010/10/19 11:27:05 | 000,122,368 | —- | M] () – C:\Users\patricia\AppData\Roaming\Microsoft\Windows\shell.exe
< %systemroot%\system32\WinDir\*.* >
< %systemroot%\_\*.* >
< %systemroot%\system32\windows32\*.* >
< %ProgramFiles%\win\*.* >
< %AppData%\Microsoft\CD Burning\*.* >
< %systemroot%\*.cab >
< %systemroot%\K.Backup\*.* >
< %ProgramFiles%\Massenger\*.* >
< %systemroot%\System32\*.doc >
< %systemroot%\Office12\*.* >
< %systemroot%\System32\Rundl32.exe\*.* >
< %ProgramFiles%\yahoo.net\*.* >
< %systemroot%\system32\*.igo >
< %systemroot%\*.rew >
< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
< %USERPROFILE%\.COMMgr\*.* >
< %USERPROFILE%\Desktop\*.bat >
< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
< %PROGRAMFILES%\Internet Explorer\*.Jmp >
< %PROGRAMFILES%\Windows NT\system\*.dll >
< %systemroot%\system32\*.ext >
< %systemroot%\system32\Com\*.cfg >
< %systemroot%\system32\btz\*.* >
< %systemroot%\system32\EMP\*.* >
< %systemroot%\system32\expo\*.* >
< %systemroot%\system32\inet2\*.* >
< %systemroot%\system32\xrem\*.* >
< %ProgramFiles%\Microsoft\*.* >
< %systemroot%\usgwmt\*.* >
< %ProgramFiles%\B\*.* >
< %SYSTEMDRIVE%\lspp\*.* >
< %systemroot%\Kral\*.* >
< %SYSTEMDRIVE%\windowsdvd.exe\*.* >
< %systemroot%\system32\*.ipo >
< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >
< %systemroot%\system32\*.mof >
< %systemroot%\*.atm >
< %systemroot%\system32\svhost\*.* >
< %ProgramFiles%\system32\*.* >
< %ProgramFiles%\Docmentt\*.* >
< %systemroot%\Help\*.vbs >
< %ProgramFiles%\Windows WinSxs\*.* /s >
< %ProgramFiles%\Outlook Express\IDT\*.* /s >
< %ProgramFiles%\Microsoft Office\365\*.* /s >
< %ProgramFiles%\Windows Live\*.* >
< %systemroot%\system32\win32\*.* >
< %SYSTEMDRIVE%\RECYCLER\*.* >
< %systemroot%\Fresh1\*.* >
< %ProgramFiles%\Kekj\*.* /s >
< %systemroot%\GDU\*.* >
< %systemroot%\KA\*.* >
< %systemroot%\R\*.* >
< %systemroot%\system32\*.fyo >
< %USERPROFILE%\System\*.* >
< %systemroot%\Source\*.* >
< %systemroot%\system32\ac\*.* >
< %ProgramFiles%\MSDN\*.* >
< %AppData%\AdobeUM\winvcldll54\*.* /s >
< %ProgramFiles%\Internet Explorer\*.ico >
< %systemroot%\system32\*.ojo >
< %systemroot%\system32\d323s\*.* >
< %systemroot%\system32\re\*.* >
< %UserProfile%\Microsoft\*.dll >
< %UserProfile%\Microsoft\*.log >
< %systemroot%\Bios\*.* >
< %ProgramFiles%\Spool\*.* >
< %ProgramFiles%\promp3\*.* >
< %SYSTEMDRIVE%\Driver\*.* /s >
< %SYSTEMDRIVE%\inetserver.exe\*.* >
< %systemroot%\java\trustlib\*.* >
< %ProgramFiles%\Common Files\designer\*.exe >
< %ProgramFiles%\*. >
[2010/10/08 13:01:14 | 000,000,000 | —D | M] – C:\Program Files\Adobe
[2009/07/09 17:35:56 | 000,000,000 | —D | M] – C:\Program Files\AOL
[2009/10/16 21:31:10 | 000,000,000 | —D | M] – C:\Program Files\AOL 9.1
[2010/04/02 20:15:28 | 000,000,000 | —D | M] – C:\Program Files\Apple Software Update
[2009/06/30 11:48:25 | 000,000,000 | —D | M] – C:\Program Files\ATI Technologies
[2010/05/16 11:32:32 | 000,000,000 | —D | M] – C:\Program Files\AV Vcs 6.0 DIAMOND
[2010/02/22 21:33:35 | 000,000,000 | —D | M] – C:\Program Files\Awakening - The Dreamless Castle
[2010/09/24 16:40:21 | 000,000,000 | —D | M] – C:\Program Files\bfgclient
[2010/10/21 11:55:00 | 000,000,000 | —D | M] – C:\Program Files\Bing Bar Installer
[2010/10/11 15:42:03 | 000,000,000 | —D | M] – C:\Program Files\BitTorrent
[2010/05/04 18:47:07 | 000,000,000 | —D | M] – C:\Program Files\Bonjour
[2010/10/17 23:02:35 | 000,000,000 | —D | M] – C:\Program Files\CCleaner
[2009/06/30 11:50:29 | 000,000,000 | —D | M] – C:\Program Files\Cisco
[2009/06/30 11:58:48 | 000,000,000 | —D | M] – C:\Program Files\Citrix
[2009/07/16 19:20:09 | 000,000,000 | —D | M] – C:\Program Files\CleanUp!
[2009/09/13 22:49:44 | 000,000,000 | —D | M] – C:\Program Files\CoD RconTool
[2010/10/08 13:01:14 | 000,000,000 | —D | M] – C:\Program Files\Common Files
[2009/12/13 21:39:08 | 000,000,000 | —D | M] – C:\Program Files\Conduit
[2009/06/30 12:23:59 | 000,000,000 | —D | M] – C:\Program Files\Creative
[2009/06/30 12:22:35 | 000,000,000 | —D | M] – C:\Program Files\Creative Live! Cam
[2009/08/30 15:52:56 | 000,000,000 | —D | M] – C:\Program Files\CyberLink
[2010/01/18 21:00:14 | 000,000,000 | —D | M] – C:\Program Files\Dell
[2009/07/29 15:13:50 | 000,000,000 | —D | M] – C:\Program Files\Dell DataSafe Local Backup
[2009/12/02 14:42:59 | 000,000,000 | —D | M] – C:\Program Files\Dell DataSafe Online
[2009/06/30 11:45:49 | 000,000,000 | —D | M] – C:\Program Files\Dell Inc
[2009/08/11 22:58:15 | 000,000,000 | —D | M] – C:\Program Files\Dell Remote Access
[2009/06/30 12:13:06 | 000,000,000 | —D | M] – C:\Program Files\Dell Support Center
[2009/06/30 11:56:11 | 000,000,000 | —D | M] – C:\Program Files\Dell Video Chat
[2009/06/30 12:23:48 | 000,000,000 | —D | M] – C:\Program Files\Dell Webcam
[2009/06/30 14:21:30 | 000,000,000 | —D | M] – C:\Program Files\DellTPad
[2010/08/31 21:46:03 | 000,000,000 | —D | M] – C:\Program Files\DivX
[2010/03/21 21:03:52 | 000,000,000 | —D | M] – C:\Program Files\Dogpile Toolbar
[2010/09/02 20:31:04 | 000,000,000 | —D | M] – C:\Program Files\DVDFab 8
[2010/05/08 14:59:03 | 000,000,000 | —D | M] – C:\Program Files\Escape the Lost Kingdom
[2009/09/10 19:05:14 | 000,000,000 | —D | M] – C:\Program Files\ESET
[2010/07/31 09:04:29 | 000,000,000 | —D | M] – C:\Program Files\Google
[2009/06/30 06:28:14 | 000,000,000 | —D | M] – C:\Program Files\IDT
[2009/07/14 16:11:49 | 000,000,000 | -H-D | M] – C:\Program Files\InstallShield Installation Information
[2010/10/15 03:13:03 | 000,000,000 | —D | M] – C:\Program Files\Internet Explorer
[2010/05/04 18:50:27 | 000,000,000 | —D | M] – C:\Program Files\iPod
[2010/05/04 18:51:05 | 000,000,000 | —D | M] – C:\Program Files\iTunes
[2010/09/12 21:26:10 | 000,000,000 | —D | M] – C:\Program Files\iWonEI
[2010/01/18 20:38:20 | 000,000,000 | —D | M] – C:\Program Files\Java
[2009/09/13 18:29:15 | 000,000,000 | —D | M] – C:\Program Files\LimeWire
[2009/07/14 16:11:41 | 000,000,000 | —D | M] – C:\Program Files\Logitech
[2010/01/18 20:22:04 | 000,000,000 | —D | M] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/02 09:12:23 | 000,000,000 | —D | M] – C:\Program Files\McAfee
[2010/05/06 13:53:22 | 000,000,000 | —D | M] – C:\Program Files\McAfee Security Scan
[2010/08/13 03:29:11 | 000,000,000 | —D | M] – C:\Program Files\McAfee.com
[2009/06/30 12:15:16 | 000,000,000 | —D | M] – C:\Program Files\Microsoft
[2006/11/02 08:37:34 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Games
[2010/01/18 21:54:04 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Office
[2010/10/02 19:39:13 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Silverlight
[2009/06/30 12:16:28 | 000,000,000 | —D | M] – C:\Program Files\Microsoft SQL Server Compact Edition
[2010/01/18 21:53:59 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Visual Studio
[2010/08/13 03:10:30 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Works
[2010/06/25 13:45:23 | 000,000,000 | —D | M] – C:\Program Files\Microsoft.NET
[2010/08/10 12:23:57 | 000,000,000 | —D | M] – C:\Program Files\mIRC
[2010/08/13 03:26:38 | 000,000,000 | —D | M] – C:\Program Files\Movie Maker
[2010/10/20 14:02:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox
[2006/11/02 08:37:34 | 000,000,000 | —D | M] – C:\Program Files\MSBuild
[2009/09/09 14:47:23 | 000,000,000 | —D | M] – C:\Program Files\MSECACHE
[2010/10/21 11:54:41 | 000,000,000 | —D | M] – C:\Program Files\MSN Toolbar
[2010/06/25 03:01:27 | 000,000,000 | —D | M] – C:\Program Files\MSXML 4.0
[2010/10/21 19:35:48 | 000,000,000 | —D | M] – C:\Program Files\Mystery Trackers - The Void Collector's Edition
[2010/08/14 18:28:15 | 000,000,000 | —D | M] – C:\Program Files\Mystic Diary - Haunted Island
[2010/09/02 20:50:28 | 000,000,000 | —D | M] – C:\Program Files\Nero
[2010/08/04 18:53:50 | 000,000,000 | —D | M] – C:\Program Files\Nightfall Mysteries - Asylum Conspiracy
[2010/09/24 16:44:48 | 000,000,000 | —D | M] – C:\Program Files\Nightmare Adventures - The Witch's Prison
[2010/09/28 16:20:03 | 000,000,000 | —D | M] – C:\Program Files\Notepad++
[2010/10/14 17:11:04 | 000,000,000 | —D | M] – C:\Program Files\Paltalk Messenger
[2010/04/22 22:19:34 | 000,000,000 | —D | M] – C:\Program Files\Panda Security
[2010/01/23 20:43:10 | 000,000,000 | —D | M] – C:\Program Files\PlayPond
[2010/03/21 21:03:44 | 000,000,000 | —D | M] – C:\Program Files\PlaySushi
[2010/04/02 20:16:53 | 000,000,000 | —D | M] – C:\Program Files\QuickTime
[2010/08/04 18:47:38 | 000,000,000 | —D | M] – C:\Program Files\RealArcade
[2010/10/10 19:06:18 | 000,000,000 | —D | M] – C:\Program Files\Redemption Cemetery - Curse of the Raven
[2010/08/11 20:04:01 | 000,000,000 | —D | M] – C:\Program Files\Redrum - Time Lies
[2006/11/02 08:37:34 | 000,000,000 | —D | M] – C:\Program Files\Reference Assemblies
[2009/08/12 14:58:43 | 000,000,000 | —D | M] – C:\Program Files\RegCleaner
[2010/06/08 19:36:16 | 000,000,000 | R–D | M] – C:\Program Files\Skype
[2009/12/21 20:56:12 | 000,000,000 | —D | M] – C:\Program Files\Snood 4
[2010/05/28 21:42:21 | 000,000,000 | —D | M] – C:\Program Files\Special Enquiry Detail - The Hand that Feeds
[2009/08/30 15:55:52 | 000,000,000 | —D | M] – C:\Program Files\SpellRead
[2009/08/10 19:14:24 | 000,000,000 | —D | M] – C:\Program Files\Strange Cases - The Tarot Card Mystery
[2010/10/19 00:07:58 | 000,000,000 | —D | M] – C:\Program Files\TabQuery
[2009/12/13 21:39:08 | 000,000,000 | —D | M] – C:\Program Files\ToggleEN
[2009/08/11 17:39:05 | 000,000,000 | —D | M] – C:\Program Files\Trend Micro
[2006/11/02 09:01:55 | 000,000,000 | -H-D | M] – C:\Program Files\Uninstall Information
[2010/09/23 15:32:53 | 000,000,000 | —D | M] – C:\Program Files\Vidalia Bundle
[2009/07/09 17:35:53 | 000,000,000 | —D | M] – C:\Program Files\Viewpoint
[2010/05/12 16:32:28 | 000,000,000 | —D | M] – C:\Program Files\WildGames
[2009/06/30 12:03:27 | 000,000,000 | —D | M] – C:\Program Files\WildTangent
[2009/10/12 09:25:59 | 000,000,000 | —D | M] – C:\Program Files\Windows Calendar
[2009/10/12 09:25:56 | 000,000,000 | —D | M] – C:\Program Files\Windows Collaboration
[2009/10/12 09:25:50 | 000,000,000 | —D | M] – C:\Program Files\Windows Defender
[2009/09/09 14:47:47 | 000,000,000 | —D | M] – C:\Program Files\Windows Installer Clean Up
[2009/10/12 09:25:56 | 000,000,000 | —D | M] – C:\Program Files\Windows Journal
[2010/10/21 12:00:24 | 000,000,000 | —D | M] – C:\Program Files\Windows Live
[2010/09/16 03:23:03 | 000,000,000 | —D | M] – C:\Program Files\Windows Mail
[2010/10/15 03:13:06 | 000,000,000 | —D | M] – C:\Program Files\Windows Media Player
[2006/11/02 08:37:34 | 000,000,000 | —D | M] – C:\Program Files\Windows NT
[2009/10/12 09:25:54 | 000,000,000 | —D | M] – C:\Program Files\Windows Photo Gallery
[2009/11/01 03:08:54 | 000,000,000 | —D | M] – C:\Program Files\Windows Portable Devices
[2009/10/12 09:25:57 | 000,000,000 | —D | M] – C:\Program Files\Windows Sidebar
[2010/05/23 09:50:44 | 000,000,000 | —D | M] – C:\Program Files\WinRAR
[2009/08/11 16:03:32 | 000,000,000 | —D | M] – C:\Program Files\WinZip
[2010/04/02 19:53:32 | 000,000,000 | —D | M] – C:\Program Files\Xilisoft
[2009/08/06 18:15:41 | 000,000,000 | —D | M] – C:\Program Files\Zylom Games
< %systemroot%\system32\*.tso >
< %ALLUSERSPROFILE%\Documents\Server\*.* >
< %systemroot%\*.pif >
[2006/09/18 17:43:58 | 000,000,707 | —- | M] () – C:\Windows\_default.pif
< %systemroot%\system32\n7533\*.* >
< %systemroot%\Us18336\*.* >
< %systemroot%\system32\*.zip >
< %systemroot%\system32\*.wgo >
< %systemroot%\system32\dllcache\*.com >
< %systemroot%\system32\dllchache\*.* >
< %systemroot%\system32\038840\*.* >
< %systemroot%\system32\13E92A\*.* >
< %systemroot%\system32\1CB5AD\*.* >
< %systemroot%\system32\52682A\*.* >
< %USERPROFILE%\My Documents\*.htm >
< %SYSTEMDRIVE%\Mr_CF\*.* >
< %USERPROFILE%\My Documents\*.dll >
< %USERPROFILE%\My Documents\*.ccc >
< %systemroot%\system32\Sis\*.* >
< %systemroot%\Microsft\*.* >
< %SYSTEMDRIVE%\driverwinx.exe\*.* >
< %systemroot%\BifroXx\*.* >
< %SYSTEMDRIVE%\TSTP\*.* >
< %systemroot%\winsn\*.* >
< %ProgramFiles%\windata\*.* >
< %SYSTEMDRIVE%\msixxxxxxx.exe\*.* >
< %systemroot%\system32\*.sao >
< %systemroot%\system32\*.iem >
< %systemroot%\system32\*.mdd >
< %systemroot%\system32\*.wlo >
< %systemroot%\system32\*.skn >
< %SYSTEMDRIVE%\Winup\*.* >
< %SYSTEMDRIVE%\test\*.* >
< %systemroot%\system32\med\*.* >
< %systemroot%\Bifrost\*.* >
< %systemroot%\system32\explorer.exe\*.* >
< %UserProfile%\UserData\*.dat /x >
< %SYSTEMDRIVE%\Arquivo de programas\*.* >
< %ProgramFiles%\tcpview\*.* >
< %systemroot%\system32\*.lyo >
< %ProgramFiles%\huanbang2\*.* >
< %systemroot%\winhuanbang\*.* >
< %systemroot%\minrsv.ini\*.* >
< %systemroot%\assembly\GAC\*.* >
< %AppData%\Adobe\crtmswin91\*.* >
< %ProgramFiles%\Windows NT\Accessories\*.exe >
[2010/06/28 10:54:38 | 000,339,968 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows NT\Accessories\wordpad.exe
< %systemroot%\system32\*.pdo >
< %SYSTEMDRIVE%\APPDATASH\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-21 16:08:30
========== Alternate Data Streams ==========
@Alternate Data Stream - 957 bytes -> C:\Users\patricia\Documents\Fw_Fwd_Fwd_Fw_FW_howtocallthepolicewhenyou'reold.eml:OECustomProperty
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:BD13A410
@Alternate Data Stream - 2421 bytes -> C:\Users\patricia\Documents\32709-Mizfour;[eDED]download;30018960.eml:OECustomProperty
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:3D6B89CE
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:B54E4B5A
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:3086B95F
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:D3A89E47
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:68B61847
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:FAB64002
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:5EF1AD34
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 198 bytes -> C:\ProgramData\TEMP:D31BE97C
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:5197985B
@Alternate Data Stream - 192 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:517DBC32
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:B4F0E275
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:9E9A3410
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:526B3022
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:627153F1
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:1AC933DC
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:C7F08EA3
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:895A78C5
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C5CE2DF6
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:89C28CF6
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:ED51D3ED
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E6C6EB3B
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:C9CDDE5E
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:71004506
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:98982C88
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ED2998F5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:A58B27C9
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:EC855C73
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:60EA2068
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:7B2BB690
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A4ACFB14
< End of report >
OTL Extras logfile created on: 10/22/2010 12:18:23 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\patricia\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.81 Gb Total Space | 112.69 Gb Free Space | 51.74% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.91 Gb Free Space | 99.41% Space Free | Partition Type: NTFS
Computer Name: PATRICIA-PC | User Name: patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" =
"FirewallDisableNotify" =
"AntiVirusOverride" =
"FirewallOverride" =
"FirstRunDisabled" =
"UpdatesDisableNotify" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0114ECFE-88ED-4749-8751-7F7C5CDEFEAC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{082E7019-7219-423F-9654-9898FEC8C43B}" = rport=139 | protocol=6 | dir=out | app=system |
"{1268C4D7-EE30-451B-80DA-443CF385C6A5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{15F1B6EE-3BF5-4768-A85B-3D4FFBB881C4}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{17E0682B-D14C-4E4B-B6C8-8FBDE56B548A}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{23E9995B-3BEA-497E-BA29-83461BEA6152}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2DBB556A-0BAA-4E1F-9F56-F9799D5F53E2}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{30C09B6E-D310-4B4F-B6D7-DEB6F8754E96}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3FD92E82-1344-4BFC-B83F-11941A391256}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{4545FE12-CD2C-4E71-8A39-D81AEFF82872}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{588598A4-853F-4BA7-BBCA-A3F861EC3C6A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5A6A2E32-23DD-488F-923E-8528B2C3A725}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5AF58B14-F6B6-4377-B627-3F031CFFEB30}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5C36C575-A3E6-437C-ABB7-DA9E88EC5B2A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{67FCF424-D574-4154-B349-D48113A13F77}" = rport=2869 | protocol=6 | dir=out | app=system |
"{7037C5BD-259F-4C5A-97B8-E124E8DA29A9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{74202CD4-594F-421C-AA70-0E9A5B436F50}" = rport=445 | protocol=6 | dir=out | app=system |
"{7518C16D-203D-4AB7-A7A0-6B540A1E3A3E}" = lport=138 | protocol=17 | dir=in | app=system |
"{75F6B489-42DC-44F4-8D7C-81126B9C78B4}" = rport=137 | protocol=17 | dir=out | app=system |
"{789341FE-1535-4CAF-96EA-0EE3F13AD1CD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{78ED03D3-D5D7-4CAB-8808-D8D27C8008C6}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{82C0608C-EBA8-4010-9073-0936FB07F3FE}" = lport=137 | protocol=17 | dir=in | app=system |
"{8300CF1E-5092-4C14-8B69-3762955FA2EB}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{8E8AF9CF-506F-47F4-A29B-31A62DD3490E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93BF271F-B19C-4D13-9F26-128357907E12}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{98219C7E-179F-43D4-A3C5-1D5ABC17D6A2}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{A041D472-C2C8-4685-B956-6AB146437D20}" = rport=138 | protocol=17 | dir=out | app=system |
"{A4867394-CF72-4411-B1A8-B18BA3AD64A6}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A99237C8-B9E2-458D-8F9B-8C66FF139F59}" = lport=445 | protocol=6 | dir=in | app=system |
"{CB1024E4-727F-43E3-980E-6C6F742070B7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CECDC46D-2D0A-4255-AD9D-7A4EC7A25375}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D1399DB2-68B4-4236-B64A-E203CDC703ED}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D3A2C7AD-83B0-459D-90B6-7B1B1494C587}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D9AA408C-B8F8-441E-9047-200ADDE069EB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DDDF7895-BA5A-4D9B-BF8C-FE704350E63C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E3B3116B-B164-463F-8121-060D291DF4FF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E8EA3EFD-CE84-41B6-AD56-9AF5A0E76E2C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F39DC77B-A509-4310-9503-36723154AF6F}" = lport=139 | protocol=6 | dir=in | app=system |
"{FBA5E69A-5DF6-4C1A-8188-CC495A4849E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FE3DC614-CFE0-4978-A6C9-2F10502BC71C}" = lport=10243 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0000D566-A5C2-411F-8F1E-8F7BE7663561}" = protocol=17 | dir=in | app=c:\program files\aol 9.1\waol.exe |
"{0580A9E7-8750-4C75-AC7D-73D47B2AB2C1}" = protocol=6 | dir=in | app=c:\program files\dogpile toolbar\troubleshooter.exe |
"{0C4FC8F9-2563-41F4-9B30-DD918226B60B}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
"{166981A2-DCF9-4643-855E-5AA02B6658A8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{18C9FA2A-E333-436D-B158-4C7B79948C31}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{18F8572A-D7DC-4260-AB52-1B90455C2389}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{1AD84E2A-F2CD-4D78-88C5-A950F6A489F6}" = protocol=17 | dir=in | app=c:\program files\common files\aol\1247175231\ee\aolsoftware.exe |
"{1FB61DB5-14EA-4CBA-A2D1-DDF228DEB011}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
"{22740BC9-AFE1-418C-B1C8-0255E712ADDC}" = protocol=6 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{25686483-7285-4C67-84C9-9EEEF042525B}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{26BE4F13-C653-4D94-8833-A923988A7087}" = protocol=6 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
"{345FF411-34DA-4729-987C-34253BC7CD83}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{39239684-E90E-4521-B573-A79585C656BE}" = protocol=6 | dir=out | app=system |
"{3DA0A23E-AC45-4A4C-BAE5-A9640366B3D2}" = protocol=17 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{431BBFF6-F38D-410B-8960-7F0F59FF3192}" = protocol=6 | dir=in | app=c:\program files\dogpile toolbar\toolbarupdate.exe |
"{491674AE-AA69-48C1-8967-2BA3C1AF57F5}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{4AE82622-7092-4CAE-9020-BA040A8B4ED4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4FB1598D-D1E9-4206-A85C-DDAE8AECCAF0}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{524B8F2A-F1A6-4B16-ACA3-F044AEEACA09}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{53B77009-1B7F-4042-AE8C-C36C54FC6D0B}" = protocol=17 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{55F3634B-EB41-4C48-9B88-B9A035344879}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{5A1C1231-70DD-4FD9-B30B-332C8612F82A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5B595263-0320-487D-A7BB-0A07C0DE0AA6}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{5B912EBF-4A2C-48C6-88AE-E5718FFF4B93}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{658A1FF3-B442-4EE0-94AC-F4F593A80546}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{6D3EB0C1-27EB-45F9-98C8-B33105A64A5D}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{7143047E-C044-4699-8800-C20CD6954386}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{75F8A714-2C0E-41B1-821E-2DF74C2905A4}" = protocol=6 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{767F081D-284D-4697-B783-545C7C38D169}" = protocol=6 | dir=in | app=c:\program files\aol 9.1\waol.exe |
"{7FCFE5A3-A006-4310-A473-69308A357BF8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{813F70DB-717F-4282-BFCE-04ABFC1FCA4F}" = protocol=6 | dir=in | app=c:\program files\common files\aol\1247175231\ee\aolsoftware.exe |
"{818E4265-8BB8-4AC2-B2E0-69B5559993EE}" = protocol=17 | dir=in | app=c:\program files\dogpile toolbar\troubleshooter.exe |
"{83D40F2B-614C-4B83-B3C3-58E64DEE0E92}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{86D8A298-2B3F-47A1-AA68-DD0729577BC9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{87C8A4BD-DEA1-43DB-BFE8-9A41C3D520E9}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{89C8A3F4-0529-4027-826E-5C403551C3D5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{901D5C72-6910-4331-A2EE-81B28D647811}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{943B0BF2-E93B-4C71-86D3-7E6C3A1ED5B2}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{9F6D3715-D679-4CE5-B35A-57C53B396186}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A1ED1D60-9DF3-4122-9FE6-B187B0F6C484}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{A33A0B70-344E-4FAC-A863-0216496A9061}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{A412AA82-226E-404E-908C-6B6857A200A2}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{ADEFD7B6-FF1E-4E3E-BE14-4578FA967018}" = protocol=17 | dir=in | app=c:\program files\dogpile toolbar\toolbarupdate.exe |
"{B3AFBF8D-5EE4-4EAE-A2D1-743F396C115E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B47A7218-ECBD-487E-AAA6-563DA7E7BC32}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
"{B5DD87F7-898B-4813-9BBD-2AE3710E55B3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C7611845-E425-49AA-9DEC-6CB96CEB17E0}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{C80C1F27-DF52-484D-A5A7-6E41828CA3E0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CCC6928F-087B-4E99-AB93-B12A48798882}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CFA32FAC-7E74-44ED-89EC-2C98FB32F79F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
"{DA826795-BFB2-4820-8A3E-D89D6A78A06F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DD48B2D1-59DA-4D5B-AFC3-DF1AB6FC331E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DD49A77A-39A0-4611-A279-7CA8EF6B3FFC}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{E267CB99-EED9-4FA0-A782-1900AA55C7E0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E7F391FA-C2DA-4BAC-A7B7-BF4E84B2CC2C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EB5CE462-FF28-4C76-93A4-37DD0F5FA947}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{EE12E96E-0E6D-4A55-8F7C-02AF0E18AE90}" = protocol=17 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
"{F008D351-B43D-42AD-A3F1-06DA5487D22F}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{F56614AC-7FE7-4102-B197-763E96BDBE73}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{0537D3F9-7F3A-4A21-AB0E-076A2E2A67DC}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{11577FF1-44A9-4347-BC97-052BEAB3F259}C:\program files\spyware terminator\spywareterminatorupdate.exe" = protocol=6 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe |
"TCP Query User{3985B8FD-2A78-4CC5-9B05-20058DAF7568}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{66876DAE-DF08-4E0B-BB20-75D8CF213E5D}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{6E4C043F-5087-43BA-9DA0-B89E08348125}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{C5163E26-A370-4420-9977-F749BD15A278}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{ECDE436C-60C6-4669-BF4C-A7D8972DA683}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{0436DD74-0D57-461C-A636-B069F5D907F2}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{15E5FE34-EDBB-4D74-BF1F-A2183F0E057F}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{76220FEE-756F-48BF-9AE1-CD888DFAF986}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{8D36EED2-7E84-4199-A416-E7245B7CA6CA}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{9A99ED54-5C27-4FCC-B6D3-CC65AED10B4F}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{B0651297-E071-425B-9240-E1591C7118C1}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{ED36FD34-BD48-4389-97EC-F924130736AC}C:\program files\spyware terminator\spywareterminatorupdate.exe" = protocol=17 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{053C30EA-D4C6-47A0-8537-8D231D9BE873}" = DELL0703
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0904ED3B-0FCD-A153-2F80-F7F5AB0329BA}" = Catalyst Control Center Graphics Previews Vista
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{0F090069-6450-9559-72BD-2437FF935EEC}" = CCC Help Swedish
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34386C65-FD55-CEBD-AF7F-5126751BAA98}" = Catalyst Control Center InstallProxy
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3643D422-9AFF-81D6-252C-14A8A3AD88D3}" = CCC Help Korean
"{3889CA7B-A8FC-09CB-C6D4-B134A2336DD9}" = CCC Help Portuguese
"{394B918B-47B0-D281-6AB8-E58871B54C91}" = Catalyst Control Center Core Implementation
"{3B7E26A8-4B67-D878-3AE3-0079686C52B6}" = CCC Help Spanish
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51B6CDCD-8802-B41A-61E4-FC6A65FF217B}" = CCC Help French
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{531DDC1D-6563-8796-764A-A9C4E83C23E0}" = CCC Help English
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56F4CA69-B3BC-81E6-304A-E650F3BB93A8}" = Catalyst Control Center Graphics Previews Common
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F548A02-80BC-404D-BAE6-F05F9BF6B449}" = Nero DiscCopyGadget 10 Help (CHM)
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{61D9B6B3-B72E-C642-F0B0-8659EADB4CAA}" = Skins
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6FB141D8-1543-6588-623A-7D95969CB330}" = Catalyst Control Center Localization All
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{791A4569-E893-CA1F-664D-1DE63A5600A1}" = ccc-utility
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7C0AEF0E-BB23-5C44-4933-88F6AE1057D8}" = Catalyst Control Center Graphics Full New
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80052E79-4A36-69BA-F44F-882A2E321116}" = CCC Help German
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{87460EB7-E62D-C963-4DDB-D2146478F59F}" = CCC Help Finnish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8BD8412A-40FB-9114-A8AE-CFB94C24C078}" = CCC Help Norwegian
"{8C2522F0-8B10-139C-3379-3620EA6A254D}" = CCC Help Dutch
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8FCE7358-DA6B-789A-44AB-E52256ACB330}" = CCC Help Chinese Traditional
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}" = Nero DiscCopy Gadget 10
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{958DF0E4-CC0D-BDD5-28D1-A1B961E48A85}" = ccc-core-static
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8E83877-671C-A1A3-F4D3-C3D74E5AE8B9}" = CCC Help Chinese Standard
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{ADB4809A-3857-F18D-153F-391EB1D37C59}" = Catalyst Control Center Graphics Full Existing
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B354E49B-DBDC-442D-5615-BD07B3A0B932}" = Catalyst Control Center Graphics Light
"{B787CD67-506B-4C9A-8A99-D2C4460D055F}" = Catalyst Control Center - Branding
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{B96C8D6D-B0E5-CD7B-BC5D-739D5051E911}" = CCC Help Japanese
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB72877A-D2BF-6F18-2D0A-52C4036E2DF6}" = CCC Help Russian
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D809E781-A654-3530-2B92-91FF959C507A}" = CCC Help Danish
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F31D838B-E7F3-1E70-F54F-B009CD9219EE}" = CCC Help Italian
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F6BB6248-C507-46FE-8A35-1B16F35E0441}" = ITECIR
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"AOL Emergency Connect Utility 1.0" = Uninstall AOL Emergency Connect Utility 1.0
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AV Voice Changer Software DIAMOND 6.0" = AV Voice Changer Software DIAMOND 6.0
"BFG-Awakening - The Dreamless Castle" = Awakening: The Dreamless Castle
"BFGC" = Big Fish Games: Game Manager
"BFG-Escape the Lost Kingdom" = Escape the Lost Kingdom
"BFG-Mystery Trackers - The Void Collector's Edition" = Mystery Trackers: The Void Collector's Edition
"BFG-Mystic Diary - Haunted Island" = Mystic Diary: Haunted Island
"BFG-Nightfall Mysteries - Asylum Conspiracy" = Nightfall Mysteries: Asylum Conspiracy
"BFG-Nightmare Adventures - The Witch's Prison" = Nightmare Adventures: The Witch's Prison
"BFG-Redemption Cemetery - Curse of the Raven" = Redemption Cemetery: Curse of the Raven
"BFG-Redrum - Time Lies" = Redrum: Time Lies
"BFG-Special Enquiry Detail - The Hand that Feeds" = Special Enquiry Detail: The Hand that Feeds
"BFG-Strange Cases - The Tarot Card Mystery" = Strange Cases: The Tarot Card Mystery
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Dogpile Toolbar" = Dogpile Toolbar
"DVDFab 8_is1" = DVDFab 8.0.0.5 (25/08/2010)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"GameHouse" = GameHouse
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"LimeWire" = LimeWire PRO 5.1.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"mIRC" = mIRC
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"MSC" = McAfee SecurityCenter
"Notepad++" = Notepad++
"PalTalk8.2" = PaltalkScene
"Playsushi" = Playsushi
"Polipo" = Polipo [removed]
"Snood 4_is1" = Snood 4
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpellRead P.A.T ® Builder Exercise" = SpellRead P.A.T ® Builder Exercise
"ToggleEN Toolbar" = ToggleEN Toolbar
"Tor" = Tor 0.2.1.26
"Vidalia" = Vidalia 0.2.10
"ViewpointMediaPlayer" = Viewpoint Media Player
"Web Games Player Plugin" = Web Games Player Plugin
"WildTangent dell Master Uninstall" = WildTangent Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WT079614" = Zuma's Revenge
"WT087308" = Cradle of Rome
"Xilisoft iPhone Ringtone Maker" = Xilisoft iPhone Ringtone Maker
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Acrobat Connect Add-in" = Adobe Acrobat Connect Add-in
"BitTorrent" = BitTorrent
"Move Media Player" = Move Media Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/12/2010 6:07:03 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2137
Error - 10/12/2010 6:07:03 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2137
Error - 10/12/2010 6:07:04 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 10/12/2010 6:07:04 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4009
Error - 10/12/2010 6:07:04 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4009
Error - 10/12/2010 7:09:43 PM | Computer Name = patricia-PC | Source = Application Hang | ID = 1002
Description = The program waol.exe version 9.5.0.1 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 1f94 Start Time: 01cb6a6249e0f550 Termination Time: 10
Error - 10/12/2010 7:13:58 PM | Computer Name = patricia-PC | Source = WinMgmt | ID = 10
Description =
Error - 10/12/2010 10:10:33 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 10/12/2010 10:10:33 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1139
Error - 10/12/2010 10:10:33 PM | Computer Name = patricia-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1139
[ Media Center Events ]
Error - 10/7/2009 4:22:36 PM | Computer Name = patricia-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 10/31/2009 5:46:49 PM | Computer Name = patricia-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.
Error - 1/30/2010 5:46:05 PM | Computer Name = patricia-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.
[ System Events ]
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 10/22/2010 12:22:16 PM | Computer Name = patricia-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
< End of report >
Malwarebytes' Anti-Malware 1.44
Database version: 3596
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975
10/22/2010 11:10:45 AM
mbam-log-2010-10-22 (11-10-36).txt
Scan type: Quick Scan
Objects scanned: 103405
Time elapsed: 6 minute(s), 28 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
C:\Users\patricia\AppData\Roaming\Microsoft\svchost.exe (Backdoor.Bot) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Backdoor.Bot) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\patricia\AppData\Roaming\Microsoft\svchost.exe (Backdoor.Bot) -> No action taken.