Thanks for your help, again!
OTL.txt
OTL logfile created on: 11/2/2010 8:31:24 PM - Run 3
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.06 Gb Free Space | 40.38% Space Free | Partition Type: NTFS
Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
PRC - [2010/09/07 15:40:04 | 001,819,504 | —- | M] (Symantec Corporation) – C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
PRC - [2010/03/23 10:54:55 | 000,028,496 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\waol.exe
PRC - [2010/03/23 10:54:54 | 000,054,608 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\shellmon.exe
PRC - [2010/02/10 09:19:09 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
PRC - [2009/09/14 20:47:37 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/09/13 18:52:50 | 001,048,392 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/11/21 17:01:26 | 002,356,088 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
PRC - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
PRC - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
PRC - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/04/02 08:33:32 | 000,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
PRC - [2006/11/03 19:02:14 | 000,050,688 | —- | M] (Avanquest Software ) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
PRC - [2004/07/27 17:50:42 | 000,221,184 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2004/04/18 23:45:50 | 000,761,856 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
========== Modules (SafeList) ==========
MOD - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
MOD - [2010/03/23 10:54:52 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2010/03/23 10:54:50 | 000,006,144 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\idleproc.dll
MOD - [2006/08/25 09:45:56 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\6to4v32.dll – (6to4)
SRV - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (LiveUpdate Notice)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (CLTNetCnService)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr)
SRV - [2008/05/23 14:51:16 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/04/19 00:50:42 | 000,029,744 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-010708-104812)
SRV - [2008/04/19 00:50:19 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/12/27 14:50:12 | 003,192,184 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2007/12/27 14:46:30 | 000,055,640 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe – (comHost)
SRV - [2007/12/11 04:39:12 | 000,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () [Auto | Running] – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe – (tcsd_win32.exe)
SRV - [2007/09/13 15:31:44 | 000,192,512 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe – (WaveEnrollmentService)
SRV - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) [Auto | Running] – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe – (TdmService)
SRV - [2007/08/31 18:39:18 | 000,486,400 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe – (SecureStorageService)
SRV - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) [Auto | Running] – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe – (NICCONFIGSVC)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\oksobxup.sys – (oksobxup)
DRV - File not found [Kernel | System | Stopped] – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{21C425F4-D933-43C8-9F1D-C785D864EFD2}\MpKslc38d941c.sys – (MpKslc38d941c)
DRV - [2010/06/22 14:52:12 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2010/06/16 12:09:32 | 000,002,304 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\msdemgr.sys – (msdemgr)
DRV - [2009/07/13 04:00:00 | 000,875,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVEX15.SYS – (NAVEX15)
DRV - [2009/07/13 04:00:00 | 000,087,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVENG.SYS – (NAVENG)
DRV - [2009/06/16 04:00:00 | 000,101,936 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/02/25 05:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIMMP)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIM)
DRV - [2009/02/19 12:31:16 | 000,184,496 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2009/02/19 12:31:16 | 000,096,560 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2009/02/19 12:31:16 | 000,038,576 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2009/02/19 12:31:16 | 000,037,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2009/02/19 12:31:16 | 000,022,320 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2009/02/19 12:31:16 | 000,013,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2009/02/09 18:59:18 | 000,251,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090730.002\SymIDSCo.sys – (SYMIDSCO)
DRV - [2009/01/08 21:53:46 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2008/09/05 14:31:42 | 000,447,024 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2008/07/30 17:42:12 | 000,023,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\COH_Mon.sys – (COH_Mon)
DRV - [2007/12/27 14:43:48 | 000,036,056 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\CO_Mon.sys – (CO_Mon)
DRV - [2007/12/05 21:07:36 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/12/02 19:26:22 | 000,989,952 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2007/11/30 23:57:12 | 000,317,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\srtspl.sys – (SRTSPL)
DRV - [2007/11/30 23:57:12 | 000,279,088 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\srtsp.sys – (SRTSP)
DRV - [2007/11/30 23:57:12 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srtspx.sys – (SRTSPX)
DRV - [2007/11/28 17:18:24 | 000,062,208 | —- | M] (O2Micro) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\oz776.sys – (guardian2)
DRV - [2007/10/09 05:17:42 | 001,123,328 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/09/10 10:55:00 | 000,161,280 | —- | M] (Wave Systems Corp.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\WavxDMgr.sys – (WavxDMgr)
DRV - [2007/09/07 10:57:14 | 000,026,608 | —- | M] (Dell Inc) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\PBADRV.sys – (PBADRV)
DRV - [2007/09/06 10:18:40 | 000,018,176 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WaveFDE.sys – (WaveFDE)
DRV - [2007/08/06 17:27:28 | 006,835,744 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2007/07/17 20:46:12 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/07/17 20:46:10 | 000,056,832 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/07/17 20:46:08 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/07/17 15:16:36 | 000,161,792 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2007/05/24 14:59:14 | 000,202,912 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/08/18 14:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 12:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 12:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2006/01/19 10:17:38 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrUsbSer.sys – (BrUsbSer)
DRV - [2006/01/19 05:44:46 | 000,053,248 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrSerIf.sys – (BrSerIf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2004/10/15 12:50:20 | 000,015,295 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrScnUsb.sys – (BrScnUsb)
DRV - [2004/08/12 18:45:54 | 000,137,728 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/08/04 00:07:44 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2004/08/04 00:07:44 | 000,041,088 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2004/08/03 23:07:56 | 000,059,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2003/01/10 17:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search Defender"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.aol.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "
http://www.search-results.com/web?o=15868&l;=dis&prt;=PRT&chn;=UN&geo;=US&ver;=UN&q;="
FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/02/13 11:35:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 16:07:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/01 16:07:30 | 000,000,000 | —D | M]
[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions
[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions\[removed]
[2010/11/01 19:47:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions
[2009/10/30 00:12:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/15 19:49:53 | 000,004,555 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\aol-search.xml
[2010/06/24 11:10:08 | 000,002,425 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\askcom.xml
[2010/10/11 12:36:23 | 000,002,698 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\search-defender.xml
[2010/11/01 16:18:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/13 09:00:04 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2010/04/13 09:00:04 | 000,185,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2010/04/13 09:00:23 | 000,046,408 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
[2009/08/25 09:05:45 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/04/13 09:00:02 | 000,061,848 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2008/06/30 23:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009/09/29 19:35:55 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (HttpWatch Basic) - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll (Simtec Limited)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [AOL Fast Start] C:\Program Files\AOL 9.5\aol.exe (AOL Inc.)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll (Simtec Limited)
O9 - Extra 'Tools' menuitem : HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (MetaStreamCtl Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740}
http://o.aolcdn.com/pictures/ap/Resources/…ns.10.6.0.8.cab (AOL Newport Editor Ctrl)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab (GameHouse Games Player)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - AppInit_DLLs: (c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll) - C:\WINDOWS\System32\hisakite.dll File not found
O20 - AppInit_DLLs: (pemobupo.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (waveGina.dll) - C:\WINDOWS\System32\waveGina.dll (Wave Systems Corp.)
O20 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\gemsafe: DllName - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - C:\WINDOWS\System32\teyufeve.dll File not found
O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - C:\WINDOWS\System32\moriyava.dll File not found
O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {002401d3-541f-4a08-a167-988bcde63d5e} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0a42816f-86a2-4018-8e75-c7490c653054} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {1cf542fb-1517-4773-b966-ffd3dbab02dc} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {289d3c51-2110-4650-8827-bb3d197b98ad} - jugezatag - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {429a2580-6151-47fb-af1d-cc581c2bd535} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {6a1355d4-879e-4d83-b740-d59902b31b6c} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {71a41e06-4419-479b-b44c-12ddf5528c1c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {95a847ee-8b44-460f-8d4e-6f242ea7682f} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9675de18-8f52-4612-a8f9-c16451dbbefe} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - tokatiluy - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {c66ae819-8c35-4f9f-a643-63045cbebecf} - tokatiluy - C:\WINDOWS\System32\moriyava.dll File not found
O22 - SharedTaskScheduler: {d09ec36b-34df-4f50-a0ec-868f49b6094b} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {f3e2d788-efd6-491f-a8b2-725b06fc5828} - gahurihor - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\phone\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/02 13:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134
[2010/11/02 00:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/10/26 22:51:15 | 000,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2010/10/26 22:51:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2010/10/26 22:47:35 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.5
[2010/10/13 16:10:50 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/12 20:48:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/02 13:21:45 | 000,133,528 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134.zip
[2010/11/02 12:16:52 | 000,161,168 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\Weeklyworksheet11-1-10.pdf
[2010/11/02 10:05:52 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/02 10:03:38 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/02 10:01:18 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/11/02 09:59:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/02 09:59:27 | 2145,521,664 | -HS- | M] () – C:\hiberfil.sys
[2010/11/02 00:53:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/31 00:47:49 | 003,634,519 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\Dogs_Home_TV_Ad_(every_home_needs_a_Harvey)2.wmv
[2010/10/26 22:55:43 | 000,000,612 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.5.lnk
[2010/10/20 18:58:33 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/10/19 21:47:05 | 000,443,392 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Desktop\CKScanner.exe
[2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/12 20:49:03 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[2010/10/12 19:06:12 | 000,000,008 | RHS- | M] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 21:40:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/10/11 21:19:36 | 000,020,043 | —- | M] () – C:\WINDOWS\System32\nvwsapps.xml
[2010/10/11 20:50:32 | 000,000,144 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/02 13:21:41 | 000,133,528 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134.zip
[2010/11/02 12:16:49 | 000,161,168 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\Weeklyworksheet11-1-10.pdf
[2010/10/31 00:47:06 | 003,634,519 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\Dogs_Home_TV_Ad_(every_home_needs_a_Harvey)2.wmv
[2010/10/26 22:55:43 | 000,000,612 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.5.lnk
[2010/10/19 21:46:45 | 000,443,392 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Desktop\CKScanner.exe
[2010/10/12 19:01:38 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 20:50:31 | 000,000,144 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[2010/06/16 12:09:32 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\msdemgr.sys
[2009/02/20 23:53:56 | 000,000,135 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\fusioncache.dat
[2009/01/13 16:40:52 | 014,564,931 | —- | C] () – C:\Program Files\ysitebuilder.exe
[2008/11/28 01:07:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/07/17 23:34:22 | 000,000,000 | —- | C] () – C:\Program Files\Firefox Setup 3.0.1.exe
[2008/07/06 14:39:18 | 000,000,811 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/07/06 14:39:18 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/07/06 14:38:18 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/07/06 14:38:18 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2008/07/06 14:36:58 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/06/22 19:32:45 | 000,018,274 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/06/03 11:58:27 | 000,009,728 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/11 21:34:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\WavXMapDrive.bat
[2008/04/19 01:08:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/19 00:42:15 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/19 00:42:15 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/19 00:30:19 | 000,080,368 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2008/04/19 00:27:42 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2008/04/19 00:27:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2008/04/19 00:23:00 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/04/19 00:22:56 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/04/18 23:55:26 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/04/18 23:55:26 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/04/18 23:55:25 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/04/18 23:55:25 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/04/18 23:55:12 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/04/18 23:53:43 | 000,001,122 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/09/13 15:42:30 | 000,499,712 | —- | C] () – C:\WINDOWS\System32\AmRes_ru.dll
[2007/09/13 15:42:30 | 000,471,040 | —- | C] () – C:\WINDOWS\System32\AmRes_pt-BR.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_it.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_fr.dll
[2007/09/13 15:42:28 | 000,462,848 | —- | C] () – C:\WINDOWS\System32\AmRes_ko.dll
[2007/09/13 15:42:28 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\AmRes_ja.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_es.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_de.dll
[2007/09/13 15:42:26 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\AmRes_en.dll
[2007/09/13 15:42:26 | 000,434,176 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHT.dll
[2007/09/13 15:36:24 | 000,438,272 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHS.dll
[2007/09/12 16:05:08 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_pt.dll
[2007/09/12 16:04:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHT.dll
[2007/09/12 16:04:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ko.dll
[2007/09/12 16:04:06 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_es.dll
[2007/09/12 16:03:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Internationalization_ru.dll
[2007/09/12 16:03:24 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ja.dll
[2007/09/12 16:03:04 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_it.dll
[2007/09/12 16:02:44 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_de.dll
[2007/09/12 16:02:22 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_fr.dll
[2007/09/12 16:02:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHS.dll
[2007/09/10 10:53:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\wxvault.dll
[2007/06/15 11:19:20 | 000,835,584 | —- | C] () – C:\WINDOWS\System32\DemoLicense.dll
[2007/01/03 11:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 11:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 11:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/08/14 12:02:10 | 000,072,192 | —- | C] () – C:\WINDOWS\System32\xltZlib.dll
[2006/06/12 09:01:16 | 000,348,160 | —- | C] () – C:\WINDOWS\tsp.dll
[2004/09/10 14:34:00 | 000,917,504 | —- | C] () – C:\WINDOWS\System32\lmgr10.dll
[2004/09/10 14:34:00 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ADsSecurity.dll
[2004/08/11 18:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 18:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
========== LOP Check ==========
[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wave Systems Corp
[2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\05524319
[2010/01/11 22:11:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\112FD
[2009/11/09 00:09:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\18269
[2010/03/12 10:52:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\23146
[2009/10/22 21:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24100714
[2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24368225
[2009/10/22 21:11:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\26039020
[2010/02/10 00:18:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\30109
[2009/10/28 08:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33834324
[2009/10/21 22:45:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\37198230
[2009/10/25 20:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\48452831
[2009/10/24 23:33:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\52948836
[2009/10/21 22:45:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\72663832
[2009/10/25 00:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\78977644
[2010/01/08 21:37:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A186
[2008/07/08 19:15:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/06/13 12:57:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/05/23 14:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/01/22 01:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\D1A5
[2008/10/16 00:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ExtendMedia
[2010/03/17 19:21:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/10/10 23:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/04/19 00:27:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2008/06/10 23:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/10/08 19:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/10/19 21:11:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/26 22:51:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/09/10 09:31:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2009/02/13 22:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/30 18:09:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BA892C10-A262-42D0-B6AD-2ADE4916F871}
[2008/05/12 13:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\acccore
[2008/06/23 14:25:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Canon
[2010/02/07 11:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Coby Media Manager
[2009/02/13 23:21:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\iPod Copy Expert
[2008/07/20 21:30:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mobipocket
[2008/07/06 14:40:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\PC-FAX TX
[2008/10/30 18:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\PhotoWorks
[2008/06/13 13:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\ScanSoft
[2008/10/30 18:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Seven Zip
[2009/01/22 11:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Skinux
[2009/01/21 17:22:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Snapfish
[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Wave Systems Corp
[2010/06/08 09:50:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\webex
[2008/05/15 10:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Windows Desktop Search
[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Wave Systems Corp
[2010/06/23 17:48:54 | 000,000,450 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/11/02 10:05:52 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\qrbktbal.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\moyhzgde.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\mdkmbdhm.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\kbtlinqq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\jniyjvsh.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\hudaxxum.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\axjlnrvq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\aqnlfvxs.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\ukixszmw.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\pbkutgqb.sys:changelist
@Alternate Data Stream - 2886 bytes -> C:\WINDOWS\System32\drivers\dfvrfjfh.sys:changelist
@Alternate Data Stream - 2394 bytes -> C:\WINDOWS\System32\drivers\hzmbkdfs.sys:changelist
@Alternate Data Stream - 2194 bytes -> C:\WINDOWS\System32\drivers\pzcbqmtc.sys:changelist
@Alternate Data Stream - 2094 bytes -> C:\WINDOWS\System32\drivers\baydmjwe.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zwewnaus.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zomwmskw.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zmtxlczd.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\uhfnajas.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\pykjaewj.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\oybfwpmi.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\diketwvy.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\voakaxjx.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ukzevqef.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\tgctseaf.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\qhkkhbcn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oxogayzn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oosdjhyl.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\nltagavr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\lohomwre.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\kugfpeya.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ivfhaoiq.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\exmvswjr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\eabfohna.sys:changelist
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
Extras.Txt
OTL Extras logfile created on: 11/2/2010 8:31:24 PM - Run 3
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.06 Gb Free Space | 40.38% Space Free | Partition Type: NTFS
Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}" = HttpWatch Basic 6.2.39
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{177D1318-3E4B-4A7C-A300-AC4E21BE090B}" = Broadcom Management Programs
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}" = tsp patch
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3643EF5F-D28D-4B25-9FA1-8859FC303710}" = Coby Media Manager
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40036C98-9777-45C2-9183-304B82B549BA}" = Symantec Real Time Storage Protection Component
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{4BF18ED6-C888-4BCF-A4AF-AC7A16305BC1}" = GemSafe Standard Edition 5.1
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5EC5F187-9D2B-4051-8906-88656819A869}" = Dell Drivers MSI
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7A2CF4CC-21A9-461D-85E3-7B4589302F65}" = SymNet
"{7A647B7A-9FE7-44A2-9041-C04528D44EB9}" = NBC Direct Beta
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9EDA3DD1-130D-4EE1-A3D2-5A3D795CC8C9}" = MFCLOC
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-1033-0000-BA7E-000000000003}" = Adobe Acrobat 8 Standard
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B52D7A21-03E5-4C0C-82FA-FD8EB4C92149}" = AxessManager
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DCC72248-D3D2-4846-8499-A400053A430E}" = TWC User Controls
"{E0F1D3B6-F50E-49AE-A942-FFDFFA16F9A9}" = PhotoStreamer 2
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EB4DF30B-102B-4F0C-927A-D50E037A325D}" = AuthenTec Fingerprint Sensor Minimum Install
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{ECC22AFA-B905-4A6A-8072-10F52B9E09B7}" = Wave Infrastructure Installer
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF05BA0F-AC15-4D12-AC5C-276225F5E751}" = Gemalto
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F1802FA6-54E9-4B24-BD2A-B50866819795}" = EMBASSY Trust Suite by Wave Systems
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FBEC50B7-537C-4A0E-8B0B-F7A8F8BF13CE}" = upekmsi
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FEC193E4-6C5F-40E9-A249-7D8C8404A9EC}" = NTRU TCG Software Stack
"ActiveTouchMeetingClient" = WebEx
"Adobe Acrobat 8 Standard" = Adobe Acrobat 8.1.2 Standard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"AOL Pictures" = AOL Pictures Tools (version 10.6.0.8)
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.13)" = Mozilla Firefox (3.5.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStreamer 2" = PhotoStreamer 2
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 12.0" = RealPlayer
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Dell Touchpad
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder
"YInstHelper" = Yahoo! Install Manager
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/1/2010 8:17:47 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x019f0f53.
Error - 11/1/2010 8:19:38 PM | Computer Name = DLSCONSULTING | Source = MsiInstaller | ID = 11706
Description = Product: ScanSoft OmniPage SE 4.0 – Error 1706.No valid source could
be found for product ScanSoft OmniPage SE 4.0. The Windows Installer cannot continue.
Error - 11/1/2010 8:20:29 PM | Computer Name = DLSCONSULTING | Source = MsiInstaller | ID = 11706
Description = Product: ScanSoft OmniPage SE 4.0 – Error 1706.No valid source could
be found for product ScanSoft OmniPage SE 4.0. The Windows Installer cannot continue.
Error - 11/1/2010 11:16:25 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02e70f12.
Error - 11/2/2010 10:12:26 AM | Computer Name = DLSCONSULTING | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072efe, P2 endsearch, P3 search, P4 2.0.6212.0,
P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 11/2/2010 11:26:03 AM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x001a3bef.
Error - 11/2/2010 12:16:27 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x03110f42.
Error - 11/2/2010 3:18:43 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x031c0fa0.
Error - 11/2/2010 3:18:56 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x031c0faf.
Error - 11/2/2010 3:19:02 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1001
Description = Fault bucket 663107094.
[ OSession Events ]
Error - 2/1/2009 3:54:38 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 211714
seconds with 960 seconds of active time. This session ended with a crash.
Error - 2/18/2009 1:47:45 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 706
seconds with 660 seconds of active time. This session ended with a crash.
Error - 2/24/2009 3:14:22 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11411
seconds with 5220 seconds of active time. This session ended with a crash.
Error - 2/25/2009 3:41:54 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1812
seconds with 240 seconds of active time. This session ended with a crash.
Error - 5/11/2009 11:51:31 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2796
seconds with 540 seconds of active time. This session ended with a crash.
Error - 6/18/2009 8:18:53 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 14
seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/11/2010 3:05:25 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 273 seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/11/2010 3:05:36 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 3 seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/11/2010 3:05:55 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 7 seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/11/2010 3:06:03 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 2 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 11/2/2010 1:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 11/2/2010 2:08:35 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 11/2/2010 2:08:36 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 11/2/2010 2:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 11/2/2010 3:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 11/2/2010 3:20:56 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 11/2/2010 4:16:15 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 11/2/2010 5:16:15 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 11/2/2010 5:18:57 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 11/2/2010 6:16:16 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
< End of report >
ckscanner.txt
CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\dedrie smith\my documents\resumes\transtech\brent mccracken.doc
c:\documents and settings\dedrie smith\my documents\resumes\transtech\~$ent mccracken.doc
scanner sequence 3.AA.11
—– EOF —–