Keweenaw
Topic Starter
You guys helped me with a problem on my desktop a few months ago, and I'm very thankful.
Now my Wife's laptop has been acting up. She got tricked by some antivirus8 popup install. I was able to kill the process and malwarebytes removed most of it I think. But some trojans are now popping up when AVG does a scan.
It's a Dell vostro with Vista Basic
I get several items that look like this after an AVG scan.
C:\Windows\Explorer.EXE (3888):\memory_00010000";"Trojan horse Adload_r.AKJ";"Object is inaccessible
Plus some whitesmoke carp** I know I didn't install.
Thanks in advance for any help.
I ran OTL
OTL.txt contents
OTL logfile created on: 11/8/2010 5:56:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Janet\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.47 Gb Total Space | 81.44 Gb Free Space | 59.67% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.40 Gb Free Space | 63.99% Space Free | Partition Type: NTFS
Drive E: | 12.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: JANET-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Janet\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Janet\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\WhiteSmoke Translator\WSTrayDictMode.exe ()
PRC - C:\Program Files\WhiteSmoke Translator\WhiteSmokeDictRegistration.exe (WhiteSmoke)
PRC - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe (Yahoo! Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\System32\wermgr.exe (Microsoft Corporation)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
PRC - C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\NetDrive\NetDrive.exe ()
PRC - C:\Program Files\NetDrive\wdService.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Janet\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
========== Win32 Services (SafeList) ==========
SRV - (FastUserSwitchingCompatibility) – C:\Windows\System32\FastUv32.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FlipShare Service) – C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (SlingAgentService) – C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (WebDriveService) – C:\Program Files\NetDrive\wdService.exe ()
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (RFNP32) – C:\Windows\System32\RFNP32.dll (River Front Software)
DRV - (WebDriveFSD) – C:\Program Files\NetDrive\rffsd.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[2009/02/23 23:10:32 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Mozilla\Extensions
[2009/02/23 23:10:32 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/29 07:32:06 | 000,002,077 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
O1 HOSTS File: ([2008/04/18 16:59:11 | 000,236,696 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 8287 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\7.0.517.44\npchrome_frame.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WebDriveTray] C:\Program Files\NetDrive\netdrive.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://mygmgw.gm.com/http://usabhembma31.m…om/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab (HPSDDX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\7.0.517.44\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (AVGRSSTX.DLL) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Janet\Pictures\2009-09-08 Porkies 2009\Porkies 2009 072.JPG
O24 - Desktop BackupWallPaper: C:\Users\Janet\Pictures\2009-09-08 Porkies 2009\Porkies 2009 072.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0010dbb3-c733-11df-9391-001d09adc265}\Shell - "" = AutoRun
O33 - MountPoints2\{0010dbb3-c733-11df-9391-001d09adc265}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{58423d10-a349-11df-b16b-001d09adc265}\Shell\AutoRun\command - "" = G:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{58423d10-a349-11df-b16b-001d09adc265}\Shell\Setup FlipShare\command - "" = G:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - C:\Windows\System32\FastUv32.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.3IV2 - C:\Windows\System32\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2010/11/08 15:33:52 | 000,000,000 | —D | C] – C:\Program Files\whitesmoketoolbar
[2010/11/08 15:33:44 | 000,000,000 | —D | C] – C:\Program Files\WhiteSmoke Translator
[2010/11/07 20:22:50 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Roaming\Malwarebytes
[2010/11/07 20:15:12 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/07 20:15:10 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/07 20:15:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/11/07 20:15:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/07 20:14:39 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
[2010/11/07 20:14:27 | 000,172,032 | —- | C] (Intel Corporation) – C:\Windows\System32\igfxres.dll
[2010/11/06 21:09:10 | 000,000,000 | —D | C] – C:\ProgramData\gEpPh02033
[2010/11/06 21:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/11/06 21:09:03 | 000,000,000 | —D | C] – C:\ProgramData\Update
[2010/10/29 14:45:53 | 000,000,000 | —D | C] – C:\Users\Janet\Documents\New Folder (2)
[2010/10/29 14:45:51 | 000,000,000 | —D | C] – C:\Users\Janet\Documents\M
[2010/10/26 18:34:14 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/10/26 16:30:14 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2010/10/26 16:30:12 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/26 16:30:12 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/23 09:13:41 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/10/20 19:30:32 | 000,000,000 | —D | C] – C:\Windows\System32\Adobe
[2010/10/13 02:03:45 | 000,000,000 | —D | C] – C:\0c5d54db98102ccbdae3f0d792
[2010/10/12 15:45:32 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/12 15:44:57 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/12 15:44:21 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/12 15:44:18 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/12 15:44:17 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/12 15:44:17 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/12 15:44:16 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/12 15:44:16 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/12 15:44:16 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/12 15:44:15 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/12 15:44:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/12 15:44:15 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/12 15:44:15 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/12 15:44:15 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/12 15:44:15 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/12 15:44:15 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/12 15:44:15 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/12 15:44:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/12 15:44:15 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/12 15:44:14 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/12 15:44:11 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/12 15:44:11 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/12 15:44:09 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/12 15:44:07 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/12 15:44:06 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[1996/11/17 16:00:00 | 000,018,944 | —- | C] ( ) – C:\Windows\IMPLODE.DLL
========== Files - Modified Within 30 Days ==========
[2010/11/08 17:59:59 | 000,764,928 | —- | M] () – C:\Windows\System32\drivers\hoaxy.sys
[2010/11/08 17:56:01 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/08 17:39:00 | 000,000,944 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3657080120-1320689142-1139454503-1000UA.job
[2010/11/08 17:00:43 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/08 17:00:43 | 000,108,772 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/08 16:59:51 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 16:59:51 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 16:53:45 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/08 15:33:47 | 000,001,855 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2010/11/08 15:33:47 | 000,001,316 | —- | M] () – C:\Users\Public\Desktop\Buy Whitesmoke Translator.lnk
[2010/11/08 15:33:44 | 000,001,535 | —- | M] () – C:\Users\Public\Desktop\Launch WhiteSmoke Translator.lnk
[2010/11/08 15:33:09 | 000,001,072 | —- | M] () – C:\Windows\System32\Improve Your PC.lnk
[2010/11/08 14:43:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/08 13:12:04 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3657080120-1320689142-1139454503-1000Core.job
[2010/11/08 13:03:18 | 067,359,366 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/11/08 12:59:51 | 000,002,319 | —- | M] () – C:\Users\Janet\Desktop\TEAM MANAGER.lnk
[2010/11/08 12:59:51 | 000,000,440 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C4A622D2-EB42-4C82-921F-68DD4AB9CB54}.job
[2010/11/07 20:57:11 | 2137,194,496 | -HS- | M] () – C:\hiberfil.sys
[2010/11/07 20:32:55 | 000,264,280 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/11/07 20:15:14 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/07 19:58:57 | 119,136,181 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/06 19:46:34 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
[2010/11/06 08:00:00 | 000,000,386 | —- | M] () – C:\Windows\tasks\rpc.job
[2010/11/04 15:39:43 | 000,002,089 | —- | M] () – C:\Users\Janet\Desktop\Google Chrome.lnk
[2010/11/04 15:39:43 | 000,002,051 | —- | M] () – C:\Users\Janet\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/03 19:18:30 | 000,017,089 | —- | M] () – C:\Users\Janet\Documents\marine food chain.docx
[2010/11/02 08:04:02 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2010/10/29 14:49:27 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/10/26 18:33:05 | 000,015,228 | —- | M] () – C:\Users\Janet\Documents\show don't tell.docx
[2010/10/23 09:14:00 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2010/10/21 05:42:26 | 000,016,382 | —- | M] () – C:\Users\Janet\Documents\Grace Periodic Tabel.xlsx
[2010/10/20 14:01:06 | 000,002,357 | —- | M] () – C:\Users\Janet\Desktop\Swim MM.lnk
========== Files Created - No Company Name ==========
[2010/11/08 15:33:47 | 000,001,855 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2010/11/08 15:33:47 | 000,001,316 | —- | C] () – C:\Users\Public\Desktop\Buy Whitesmoke Translator.lnk
[2010/11/08 15:33:44 | 000,001,535 | —- | C] () – C:\Users\Public\Desktop\Launch WhiteSmoke Translator.lnk
[2010/11/08 15:33:09 | 000,001,072 | —- | C] () – C:\Windows\System32\Improve Your PC.lnk
[2010/11/07 20:32:24 | 2137,194,496 | -HS- | C] () – C:\hiberfil.sys
[2010/11/07 20:15:14 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/06 21:09:32 | 000,764,928 | —- | C] () – C:\Windows\System32\drivers\hoaxy.sys
[2010/11/06 19:01:27 | 119,136,181 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/11/03 18:51:08 | 000,017,089 | —- | C] () – C:\Users\Janet\Documents\marine food chain.docx
[2010/10/26 18:33:05 | 000,015,228 | —- | C] () – C:\Users\Janet\Documents\show don't tell.docx
[2010/10/20 18:54:49 | 000,016,382 | —- | C] () – C:\Users\Janet\Documents\Grace Periodic Tabel.xlsx
[2010/06/08 18:41:21 | 000,503,808 | —- | C] () – C:\Windows\System32\RFHelper.dll
[2010/06/08 18:41:21 | 000,221,184 | —- | C] () – C:\Windows\System32\rfwdres.dll
[2010/06/08 18:41:21 | 000,126,976 | —- | C] () – C:\Windows\System32\rfshext.dll
[2010/06/08 18:41:21 | 000,032,768 | —- | C] () – C:\Windows\System32\rfhres.dll
[2010/06/08 18:41:21 | 000,024,576 | —- | C] () – C:\Windows\System32\rfshres.dll
[2010/06/08 18:41:21 | 000,020,480 | —- | C] () – C:\Windows\System32\rfstrres.dll
[2009/09/23 17:58:13 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/02/03 07:01:29 | 000,094,274 | —- | C] () – C:\Windows\System32\HPBHEALR.DLL
[2008/10/16 16:37:35 | 000,024,206 | —- | C] () – C:\Users\Janet\AppData\Roaming\UserTile.png
[2008/04/19 12:00:47 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/04/19 12:00:47 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/02/24 23:34:47 | 000,005,793 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – C:\Windows\System32\OpenQuicktimeLib.dll
[2008/02/14 13:13:01 | 000,000,680 | —- | C] () – C:\Users\Janet\AppData\Local\d3d9caps.dat
[2007/12/22 20:45:47 | 000,014,848 | —- | C] () – C:\Users\Janet\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/16 06:30:13 | 000,910,304 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/16 06:30:13 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2007/12/16 06:30:13 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1272.dll
[2007/12/16 06:30:06 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/12/16 06:29:56 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/12/15 22:47:22 | 000,065,536 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2009/10/28 20:14:46 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\BNeReader
[2009/02/23 23:10:25 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Flickr
[2009/01/24 13:37:26 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Gizmo5
[2008/06/07 20:24:52 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Image Zone Express
[2010/06/01 20:55:47 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\OverDrive
[2010/06/16 06:57:39 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\PeaZip
[2008/10/16 16:37:35 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\PeerNetworking
[2008/06/07 20:03:17 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Printer Info Cache
[2010/10/01 11:46:30 | 000,000,284 | —- | M] () – C:\Windows\Tasks\Regwork.job
[2010/11/06 08:00:00 | 000,000,386 | —- | M] () – C:\Windows\Tasks\rpc.job
[2010/11/08 16:52:24 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/08 12:59:51 | 000,000,440 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{C4A622D2-EB42-4C82-921F-68DD4AB9CB54}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/01/04 12:33:41 | 000,060,002 | —- | M] () – C:\AppStreamClient.log
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/12/16 06:30:22 | 000,004,438 | RH– | M] () – C:\dell.sdr
[2010/11/07 20:57:11 | 2137,194,496 | -HS- | M] () – C:\hiberfil.sys
[2007/02/01 03:24:24 | 000,258,048 | —- | M] (Hewlett-Packard) – C:\hpzids01.dll
[2008/01/05 15:04:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/01/05 15:04:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/07 20:57:09 | 2450,997,248 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 07:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/12/21 21:42:48 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/02 11:26:36 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2007/02/13 20:22:00 | 000,286,208 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4wm.dll
[2008/01/19 02:34:28 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2002/04/18 10:13:20 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\Windows\System32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2007/12/10 08:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\Windows\System32\spool\prtprocs\w32x86\ZIMFPRNT.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/10/30 09:02:34 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/07 07:16:44 | 000,000,286 | -HS- | M] () – C:\Users\Janet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/28 17:16:44 | 001,187,896 | —- | M] (Piriform Ltd) – C:\Users\Janet\Desktop\ccsetup236.exe
[2010/11/06 19:46:34 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-27 07:01:15
========== Alternate Data Streams ==========
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:62E2D794
< End of report >
Extras.Txt contents
OTL Extras logfile created on: 11/8/2010 5:56:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Janet\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.47 Gb Total Space | 81.44 Gb Free Space | 59.67% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.40 Gb Free Space | 63.99% Space Free | Partition Type: NTFS
Drive E: | 12.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: Janet-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [+ Add to separate archive(s)] – "C:\Program Files\PeaZip\PEAZIP.EXE" "-add2archive" "%1" (Giorgio Tani)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A4CF269-06CB-4895-AD7B-3183D7FA1E5D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{210FAEFA-C6FA-40D2-8045-B123D4D64378}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3602D2A1-DDFB-412A-B908-C5C35CB3A00C}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{3EC2E960-27F1-4548-876F-E4294D69188F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{3F4C92F6-24BF-4356-A855-4AD14F93796B}" = lport=445 | protocol=6 | dir=in | name=microsoft directory services |
"{517B1A66-E172-4870-8687-C9A2CF1DA9FB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6E45FE3D-FCED-4F84-A9C2-05E88FB30478}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7FAD7C12-5552-411C-8FED-E4C0AD6EF5E9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{85A40072-55B5-40BB-8297-DB47801ACAB5}" = lport=10421 | protocol=17 | dir=in | name=singleclick discovery protocol |
"{897284F2-14E5-45A0-B810-97A443A30CDD}" = lport=139 | protocol=6 | dir=in | name=netbios file/printer sharing |
"{9DD71AF8-2CB4-4E18-B1DB-6B18F0B9D5C5}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A54582AB-60E6-4A12-AE7B-EC4E0EC75862}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A98D8612-CCEA-40BF-A507-9A4E73DAC645}" = lport=138 | protocol=17 | dir=in | name=netbios datagram service |
"{C6B0DFDC-4104-4F74-AB34-8A553CAADDF8}" = lport=10426 | protocol=17 | dir=in | name=singleclick icc |
"{DE3B9C1D-7B97-4CF2-B471-AE6CB880B2E6}" = lport=137 | protocol=17 | dir=in | name=netbios name service |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1981D697-4EF3-478E-8C0D-D7679C421B43}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1A466314-62C7-4C18-A7EE-A41B1E143292}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{2A0C8C49-4B44-4956-9C9E-FD00BE7DCF30}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{392795FC-CCDE-4FAD-BE5D-FA24EC6D8711}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{42C33F46-73EC-4871-8B93-6022AAE4E809}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4AC0579D-3E44-43CD-AF79-A388139A7F64}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{539602DC-DD59-43D7-A953-9D76EF260EB0}" = protocol=6 | dir=in | app=e:\setup.exe |
"{5C943B5C-73F0-458B-974D-DDAE5EC882B8}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8871201D-9187-4D29-8AA3-4CF48BE725E6}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{91923B56-AB77-4614-9843-FD0F2C2E1F22}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{9387FBC9-C169-481E-9E6B-48C13996CAB1}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{95FC3300-AE20-4623-869D-86D990ED4096}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{AAEB326F-59AB-475C-8F08-31742E47DA43}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{ADB82C72-6EE3-4C1C-A95D-68C27137E0A8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AEC56A39-503F-45DE-BA0D-F885DCE2039B}" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{B35DDD3E-0A92-4021-A2E2-DFF8C953CE6E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C97607A6-6058-450A-888B-28DB08B7F640}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{D8177698-D4D1-40E7-84A0-F6FE58178041}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{ED8B1B92-A48D-401C-A3B8-0C16776014A5}" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{EE017CEE-2050-4BEC-AF9D-5E0BF3FC5523}" = protocol=17 | dir=in | app=e:\setup.exe |
"TCP Query User{2C49FAF1-3A9E-4811-A351-40DED92F0A35}C:\program files\dell network assistant\ezi_hnm2.exe" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"TCP Query User{35671D8D-E47A-4214-9FE5-C77D22D97E7D}C:\program files\gizmo5\gizmo5.exe" = protocol=6 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"TCP Query User{3EED900F-15EF-4089-810E-43E16ED2CFAD}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{56964716-B09F-4991-943B-D25DB2F4615C}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=6 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"TCP Query User{D42AEDBB-F257-4FC2-B539-015F52B46EEB}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=6 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"TCP Query User{F0D92233-00F3-4E0E-BA98-E3727111841B}C:\program files\gizmo5\gizmo5.exe" = protocol=6 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{14EABBD1-BBC7-4CA3-998D-A8892FD3F019}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1E114C7C-094D-4A8B-9132-F5B1D3A3CA89}C:\program files\dell network assistant\ezi_hnm2.exe" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"UDP Query User{8E67B5B9-FB9B-4E69-AD87-5EEE2BF8ED91}C:\program files\gizmo5\gizmo5.exe" = protocol=17 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{A5792444-0FD2-4E18-BA39-444685A6BBAD}C:\program files\gizmo5\gizmo5.exe" = protocol=17 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{B264FFD5-EFE2-478A-91EF-7391DE3F5707}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=17 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"UDP Query User{D5819914-5BC2-415D-9512-EC841E0F48A3}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=17 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1ADB7BF5-F8EB-4F76-98FD-65A7FFBEAECE}" = Whitesmoke Translator
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{335B1821-D274-4EFD-9EFE-3C0FD38EBE65}" = BN eReader
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D08333C-C366-425D-8C2D-D05630D68A46}" = SlingPlayer
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{58F58158-8DFE-31DA-AC1F-7E5D89A0F74F}" = Google Talk Plugin
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 2.7
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7736FD0A-9BF4-40F3-AF12-2E95D65D964F}" = TEAM MANAGER 5.0 for Swimming
"{7CE480FF-5B49-490E-BC18-1C663ECC0B61}" = MEET MANAGER 2.0 for Swimming
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_BASICR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_BASICR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_BASICR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91120000-0013-0000-0000-0000000FF1CE}" = Microsoft Office Basic 2007
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}" = MEET MANAGER 3.0 for Swimming
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG Free 9.0
"BASICR" = Microsoft Office Basic 2007
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Flickr Uploadr" = Flickr Uploadr 3.1.3
"Gizmo5" = Gizmo5
"Google Chrome Frame" = Google Chrome Frame
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.480
"Hardwood Euchre" = Hardwood Euchre
"InstallShield_{3D08333C-C366-425D-8C2D-D05630D68A46}" = SlingPlayer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NetDrive" = NetDrive
"SynTPDeinstKey" = Dell Touchpad
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/1/2010 11:34:50 AM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 10/5/2010 8:00:46 AM | Computer Name = Janet-PC | Source = VSS | ID = 8194
Description =
Error - 10/6/2010 8:31:24 PM | Computer Name = Janet-PC | Source = MsiInstaller | ID = 11321
Description =
Error - 10/6/2010 8:31:27 PM | Computer Name = Janet-PC | Source = MsiInstaller | ID = 1024
Description =
Error - 10/17/2010 11:38:03 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.2.3.231, time stamp 0x4c19bfc2,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x07521b48, process id 0x178c, application start time 0x01cb6e1138d5eb50.
Error - 10/17/2010 6:01:22 PM | Computer Name = Janet-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18975 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 9e8 Start Time: 01cb6e45a6705ea0 Termination Time: 15
Error - 10/26/2010 8:48:30 AM | Computer Name = Janet-PC | Source = VSS | ID = 8194
Description =
Error - 10/29/2010 1:37:17 PM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 10/29/2010 3:49:22 PM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 11/4/2010 9:17:50 AM | Computer Name = Janet-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 123c Start Time: 01cb7bbc839f3bb0 Termination Time: 8
[ Broadcom Wireless LAN Events ]
Error - 9/7/2010 8:03:13 AM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 08:03:13, Tue, Sep 07, 10 Error - Unable to gain access to user store
Error - 9/23/2010 12:54:28 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 12:54:28, Thu, Sep 23, 10 Error - Unable to gain access to user store
Error - 10/13/2010 1:40:02 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 13:40:01, Wed, Oct 13, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:02:41 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:02:40, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:07:02 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:07:02, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:38:23 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:38:23, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:49:59 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:49:59, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 10:13:25 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 22:13:25, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/7/2010 9:33:36 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:33:34, Sun, Nov 07, 10 Error - Unable to gain access to user store
Error - 11/7/2010 9:57:48 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:57:48, Sun, Nov 07, 10 Error - Unable to gain access to user store
[ OSession Events ]
Error - 1/11/2008 6:14:17 PM | Computer Name = Janet-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 272
seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/28/2009 11:04:00 AM | Computer Name = Janet-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 11/7/2010 9:13:40 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:13:40 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:14:14 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:14:14 PM | Computer Name = Janet-PC | Source = DCOM | ID = 10005
Description =
Error - 11/7/2010 9:14:16 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:33:46 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 11/7/2010 9:57:29 PM | Computer Name = Janet-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:55:21 PM on 11/7/2010 was unexpected.
Error - 11/7/2010 9:58:03 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 11/8/2010 1:59:13 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 11/8/2010 5:54:32 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7032
Description =
< End of report >
Now my Wife's laptop has been acting up. She got tricked by some antivirus8 popup install. I was able to kill the process and malwarebytes removed most of it I think. But some trojans are now popping up when AVG does a scan.
It's a Dell vostro with Vista Basic
I get several items that look like this after an AVG scan.
C:\Windows\Explorer.EXE (3888):\memory_00010000";"Trojan horse Adload_r.AKJ";"Object is inaccessible
Plus some whitesmoke carp** I know I didn't install.
Thanks in advance for any help.
I ran OTL
OTL.txt contents
OTL logfile created on: 11/8/2010 5:56:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Janet\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.47 Gb Total Space | 81.44 Gb Free Space | 59.67% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.40 Gb Free Space | 63.99% Space Free | Partition Type: NTFS
Drive E: | 12.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: JANET-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Janet\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Janet\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\WhiteSmoke Translator\WSTrayDictMode.exe ()
PRC - C:\Program Files\WhiteSmoke Translator\WhiteSmokeDictRegistration.exe (WhiteSmoke)
PRC - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe (Yahoo! Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\System32\wermgr.exe (Microsoft Corporation)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
PRC - C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\NetDrive\NetDrive.exe ()
PRC - C:\Program Files\NetDrive\wdService.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Janet\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
========== Win32 Services (SafeList) ==========
SRV - (FastUserSwitchingCompatibility) – C:\Windows\System32\FastUv32.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FlipShare Service) – C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (SlingAgentService) – C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (WebDriveService) – C:\Program Files\NetDrive\wdService.exe ()
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (RFNP32) – C:\Windows\System32\RFNP32.dll (River Front Software)
DRV - (WebDriveFSD) – C:\Program Files\NetDrive\rffsd.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[2009/02/23 23:10:32 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Mozilla\Extensions
[2009/02/23 23:10:32 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/29 07:32:06 | 000,002,077 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
O1 HOSTS File: ([2008/04/18 16:59:11 | 000,236,696 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 8287 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\7.0.517.44\npchrome_frame.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WhiteSmoke Toolbar) - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WebDriveTray] C:\Program Files\NetDrive\netdrive.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://mygmgw.gm.com/http://usabhembma31.m…om/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab (HPSDDX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\7.0.517.44\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (AVGRSSTX.DLL) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Janet\Pictures\2009-09-08 Porkies 2009\Porkies 2009 072.JPG
O24 - Desktop BackupWallPaper: C:\Users\Janet\Pictures\2009-09-08 Porkies 2009\Porkies 2009 072.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0010dbb3-c733-11df-9391-001d09adc265}\Shell - "" = AutoRun
O33 - MountPoints2\{0010dbb3-c733-11df-9391-001d09adc265}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{58423d10-a349-11df-b16b-001d09adc265}\Shell\AutoRun\command - "" = G:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{58423d10-a349-11df-b16b-001d09adc265}\Shell\Setup FlipShare\command - "" = G:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - C:\Windows\System32\FastUv32.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.3IV2 - C:\Windows\System32\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2010/11/08 15:33:52 | 000,000,000 | —D | C] – C:\Program Files\whitesmoketoolbar
[2010/11/08 15:33:44 | 000,000,000 | —D | C] – C:\Program Files\WhiteSmoke Translator
[2010/11/07 20:22:50 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Roaming\Malwarebytes
[2010/11/07 20:15:12 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/07 20:15:10 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/07 20:15:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/11/07 20:15:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/07 20:14:39 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
[2010/11/07 20:14:27 | 000,172,032 | —- | C] (Intel Corporation) – C:\Windows\System32\igfxres.dll
[2010/11/06 21:09:10 | 000,000,000 | —D | C] – C:\ProgramData\gEpPh02033
[2010/11/06 21:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/11/06 21:09:03 | 000,000,000 | —D | C] – C:\ProgramData\Update
[2010/10/29 14:45:53 | 000,000,000 | —D | C] – C:\Users\Janet\Documents\New Folder (2)
[2010/10/29 14:45:51 | 000,000,000 | —D | C] – C:\Users\Janet\Documents\M
[2010/10/26 18:34:14 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2010/10/26 16:30:14 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2010/10/26 16:30:12 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/26 16:30:12 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/23 09:13:41 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/10/20 19:30:32 | 000,000,000 | —D | C] – C:\Windows\System32\Adobe
[2010/10/13 02:03:45 | 000,000,000 | —D | C] – C:\0c5d54db98102ccbdae3f0d792
[2010/10/12 15:45:32 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/12 15:44:57 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/12 15:44:21 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/12 15:44:18 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/12 15:44:17 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/12 15:44:17 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/12 15:44:16 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/12 15:44:16 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/12 15:44:16 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/12 15:44:15 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/12 15:44:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/12 15:44:15 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/12 15:44:15 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/12 15:44:15 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/12 15:44:15 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/12 15:44:15 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/12 15:44:15 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/12 15:44:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/12 15:44:15 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/12 15:44:14 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/12 15:44:11 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/12 15:44:11 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/12 15:44:09 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/12 15:44:07 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/12 15:44:06 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[1996/11/17 16:00:00 | 000,018,944 | —- | C] ( ) – C:\Windows\IMPLODE.DLL
========== Files - Modified Within 30 Days ==========
[2010/11/08 17:59:59 | 000,764,928 | —- | M] () – C:\Windows\System32\drivers\hoaxy.sys
[2010/11/08 17:56:01 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/08 17:39:00 | 000,000,944 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3657080120-1320689142-1139454503-1000UA.job
[2010/11/08 17:00:43 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/08 17:00:43 | 000,108,772 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/08 16:59:51 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 16:59:51 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/08 16:53:45 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/08 15:33:47 | 000,001,855 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2010/11/08 15:33:47 | 000,001,316 | —- | M] () – C:\Users\Public\Desktop\Buy Whitesmoke Translator.lnk
[2010/11/08 15:33:44 | 000,001,535 | —- | M] () – C:\Users\Public\Desktop\Launch WhiteSmoke Translator.lnk
[2010/11/08 15:33:09 | 000,001,072 | —- | M] () – C:\Windows\System32\Improve Your PC.lnk
[2010/11/08 14:43:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/08 13:12:04 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3657080120-1320689142-1139454503-1000Core.job
[2010/11/08 13:03:18 | 067,359,366 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/11/08 12:59:51 | 000,002,319 | —- | M] () – C:\Users\Janet\Desktop\TEAM MANAGER.lnk
[2010/11/08 12:59:51 | 000,000,440 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C4A622D2-EB42-4C82-921F-68DD4AB9CB54}.job
[2010/11/07 20:57:11 | 2137,194,496 | -HS- | M] () – C:\hiberfil.sys
[2010/11/07 20:32:55 | 000,264,280 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/11/07 20:15:14 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/07 19:58:57 | 119,136,181 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/06 19:46:34 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
[2010/11/06 08:00:00 | 000,000,386 | —- | M] () – C:\Windows\tasks\rpc.job
[2010/11/04 15:39:43 | 000,002,089 | —- | M] () – C:\Users\Janet\Desktop\Google Chrome.lnk
[2010/11/04 15:39:43 | 000,002,051 | —- | M] () – C:\Users\Janet\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/03 19:18:30 | 000,017,089 | —- | M] () – C:\Users\Janet\Documents\marine food chain.docx
[2010/11/02 08:04:02 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2010/10/29 14:49:27 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/10/26 18:33:05 | 000,015,228 | —- | M] () – C:\Users\Janet\Documents\show don't tell.docx
[2010/10/23 09:14:00 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2010/10/21 05:42:26 | 000,016,382 | —- | M] () – C:\Users\Janet\Documents\Grace Periodic Tabel.xlsx
[2010/10/20 14:01:06 | 000,002,357 | —- | M] () – C:\Users\Janet\Desktop\Swim MM.lnk
========== Files Created - No Company Name ==========
[2010/11/08 15:33:47 | 000,001,855 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
[2010/11/08 15:33:47 | 000,001,316 | —- | C] () – C:\Users\Public\Desktop\Buy Whitesmoke Translator.lnk
[2010/11/08 15:33:44 | 000,001,535 | —- | C] () – C:\Users\Public\Desktop\Launch WhiteSmoke Translator.lnk
[2010/11/08 15:33:09 | 000,001,072 | —- | C] () – C:\Windows\System32\Improve Your PC.lnk
[2010/11/07 20:32:24 | 2137,194,496 | -HS- | C] () – C:\hiberfil.sys
[2010/11/07 20:15:14 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/06 21:09:32 | 000,764,928 | —- | C] () – C:\Windows\System32\drivers\hoaxy.sys
[2010/11/06 19:01:27 | 119,136,181 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/11/03 18:51:08 | 000,017,089 | —- | C] () – C:\Users\Janet\Documents\marine food chain.docx
[2010/10/26 18:33:05 | 000,015,228 | —- | C] () – C:\Users\Janet\Documents\show don't tell.docx
[2010/10/20 18:54:49 | 000,016,382 | —- | C] () – C:\Users\Janet\Documents\Grace Periodic Tabel.xlsx
[2010/06/08 18:41:21 | 000,503,808 | —- | C] () – C:\Windows\System32\RFHelper.dll
[2010/06/08 18:41:21 | 000,221,184 | —- | C] () – C:\Windows\System32\rfwdres.dll
[2010/06/08 18:41:21 | 000,126,976 | —- | C] () – C:\Windows\System32\rfshext.dll
[2010/06/08 18:41:21 | 000,032,768 | —- | C] () – C:\Windows\System32\rfhres.dll
[2010/06/08 18:41:21 | 000,024,576 | —- | C] () – C:\Windows\System32\rfshres.dll
[2010/06/08 18:41:21 | 000,020,480 | —- | C] () – C:\Windows\System32\rfstrres.dll
[2009/09/23 17:58:13 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/02/03 07:01:29 | 000,094,274 | —- | C] () – C:\Windows\System32\HPBHEALR.DLL
[2008/10/16 16:37:35 | 000,024,206 | —- | C] () – C:\Users\Janet\AppData\Roaming\UserTile.png
[2008/04/19 12:00:47 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/04/19 12:00:47 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/02/24 23:34:47 | 000,005,793 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – C:\Windows\System32\OpenQuicktimeLib.dll
[2008/02/14 13:13:01 | 000,000,680 | —- | C] () – C:\Users\Janet\AppData\Local\d3d9caps.dat
[2007/12/22 20:45:47 | 000,014,848 | —- | C] () – C:\Users\Janet\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/16 06:30:13 | 000,910,304 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/16 06:30:13 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2007/12/16 06:30:13 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1272.dll
[2007/12/16 06:30:06 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/12/16 06:29:56 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/12/15 22:47:22 | 000,065,536 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2009/10/28 20:14:46 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\BNeReader
[2009/02/23 23:10:25 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Flickr
[2009/01/24 13:37:26 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Gizmo5
[2008/06/07 20:24:52 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Image Zone Express
[2010/06/01 20:55:47 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\OverDrive
[2010/06/16 06:57:39 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\PeaZip
[2008/10/16 16:37:35 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\PeerNetworking
[2008/06/07 20:03:17 | 000,000,000 | —D | M] – C:\Users\Janet\AppData\Roaming\Printer Info Cache
[2010/10/01 11:46:30 | 000,000,284 | —- | M] () – C:\Windows\Tasks\Regwork.job
[2010/11/06 08:00:00 | 000,000,386 | —- | M] () – C:\Windows\Tasks\rpc.job
[2010/11/08 16:52:24 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/08 12:59:51 | 000,000,440 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{C4A622D2-EB42-4C82-921F-68DD4AB9CB54}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/01/04 12:33:41 | 000,060,002 | —- | M] () – C:\AppStreamClient.log
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/12/16 06:30:22 | 000,004,438 | RH– | M] () – C:\dell.sdr
[2010/11/07 20:57:11 | 2137,194,496 | -HS- | M] () – C:\hiberfil.sys
[2007/02/01 03:24:24 | 000,258,048 | —- | M] (Hewlett-Packard) – C:\hpzids01.dll
[2008/01/05 15:04:13 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/01/05 15:04:13 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/07 20:57:09 | 2450,997,248 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 07:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/12/21 21:42:48 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/02/02 11:26:36 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2007/02/13 20:22:00 | 000,286,208 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4wm.dll
[2008/01/19 02:34:28 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2002/04/18 10:13:20 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\Windows\System32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2007/12/10 08:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\Windows\System32\spool\prtprocs\w32x86\ZIMFPRNT.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/10/30 09:02:34 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/07 07:16:44 | 000,000,286 | -HS- | M] () – C:\Users\Janet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/28 17:16:44 | 001,187,896 | —- | M] (Piriform Ltd) – C:\Users\Janet\Desktop\ccsetup236.exe
[2010/11/06 19:46:34 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Janet\Desktop\mbam-setup-1.46.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-27 07:01:15
========== Alternate Data Streams ==========
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:62E2D794
< End of report >
Extras.Txt contents
OTL Extras logfile created on: 11/8/2010 5:56:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Janet\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.47 Gb Total Space | 81.44 Gb Free Space | 59.67% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.40 Gb Free Space | 63.99% Space Free | Partition Type: NTFS
Drive E: | 12.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: Janet-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [+ Add to separate archive(s)] – "C:\Program Files\PeaZip\PEAZIP.EXE" "-add2archive" "%1" (Giorgio Tani)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A4CF269-06CB-4895-AD7B-3183D7FA1E5D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{210FAEFA-C6FA-40D2-8045-B123D4D64378}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3602D2A1-DDFB-412A-B908-C5C35CB3A00C}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{3EC2E960-27F1-4548-876F-E4294D69188F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{3F4C92F6-24BF-4356-A855-4AD14F93796B}" = lport=445 | protocol=6 | dir=in | name=microsoft directory services |
"{517B1A66-E172-4870-8687-C9A2CF1DA9FB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6E45FE3D-FCED-4F84-A9C2-05E88FB30478}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7FAD7C12-5552-411C-8FED-E4C0AD6EF5E9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{85A40072-55B5-40BB-8297-DB47801ACAB5}" = lport=10421 | protocol=17 | dir=in | name=singleclick discovery protocol |
"{897284F2-14E5-45A0-B810-97A443A30CDD}" = lport=139 | protocol=6 | dir=in | name=netbios file/printer sharing |
"{9DD71AF8-2CB4-4E18-B1DB-6B18F0B9D5C5}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A54582AB-60E6-4A12-AE7B-EC4E0EC75862}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A98D8612-CCEA-40BF-A507-9A4E73DAC645}" = lport=138 | protocol=17 | dir=in | name=netbios datagram service |
"{C6B0DFDC-4104-4F74-AB34-8A553CAADDF8}" = lport=10426 | protocol=17 | dir=in | name=singleclick icc |
"{DE3B9C1D-7B97-4CF2-B471-AE6CB880B2E6}" = lport=137 | protocol=17 | dir=in | name=netbios name service |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1981D697-4EF3-478E-8C0D-D7679C421B43}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1A466314-62C7-4C18-A7EE-A41B1E143292}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{2A0C8C49-4B44-4956-9C9E-FD00BE7DCF30}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{392795FC-CCDE-4FAD-BE5D-FA24EC6D8711}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{42C33F46-73EC-4871-8B93-6022AAE4E809}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4AC0579D-3E44-43CD-AF79-A388139A7F64}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{539602DC-DD59-43D7-A953-9D76EF260EB0}" = protocol=6 | dir=in | app=e:\setup.exe |
"{5C943B5C-73F0-458B-974D-DDAE5EC882B8}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8871201D-9187-4D29-8AA3-4CF48BE725E6}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{91923B56-AB77-4614-9843-FD0F2C2E1F22}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{9387FBC9-C169-481E-9E6B-48C13996CAB1}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{95FC3300-AE20-4623-869D-86D990ED4096}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{AAEB326F-59AB-475C-8F08-31742E47DA43}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{ADB82C72-6EE3-4C1C-A95D-68C27137E0A8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AEC56A39-503F-45DE-BA0D-F885DCE2039B}" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{B35DDD3E-0A92-4021-A2E2-DFF8C953CE6E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C97607A6-6058-450A-888B-28DB08B7F640}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{D8177698-D4D1-40E7-84A0-F6FE58178041}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{ED8B1B92-A48D-401C-A3B8-0C16776014A5}" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{EE017CEE-2050-4BEC-AF9D-5E0BF3FC5523}" = protocol=17 | dir=in | app=e:\setup.exe |
"TCP Query User{2C49FAF1-3A9E-4811-A351-40DED92F0A35}C:\program files\dell network assistant\ezi_hnm2.exe" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"TCP Query User{35671D8D-E47A-4214-9FE5-C77D22D97E7D}C:\program files\gizmo5\gizmo5.exe" = protocol=6 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"TCP Query User{3EED900F-15EF-4089-810E-43E16ED2CFAD}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{56964716-B09F-4991-943B-D25DB2F4615C}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=6 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"TCP Query User{D42AEDBB-F257-4FC2-B539-015F52B46EEB}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=6 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"TCP Query User{F0D92233-00F3-4E0E-BA98-E3727111841B}C:\program files\gizmo5\gizmo5.exe" = protocol=6 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{14EABBD1-BBC7-4CA3-998D-A8892FD3F019}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{1E114C7C-094D-4A8B-9132-F5B1D3A3CA89}C:\program files\dell network assistant\ezi_hnm2.exe" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"UDP Query User{8E67B5B9-FB9B-4E69-AD87-5EEE2BF8ED91}C:\program files\gizmo5\gizmo5.exe" = protocol=17 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{A5792444-0FD2-4E18-BA39-444685A6BBAD}C:\program files\gizmo5\gizmo5.exe" = protocol=17 | dir=in | app=c:\program files\gizmo5\gizmo5.exe |
"UDP Query User{B264FFD5-EFE2-478A-91EF-7391DE3F5707}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=17 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
"UDP Query User{D5819914-5BC2-415D-9512-EC841E0F48A3}C:\program files\joost\xulrunner\tvprunner.exe" = protocol=17 | dir=in | app=c:\program files\joost\xulrunner\tvprunner.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1ADB7BF5-F8EB-4F76-98FD-65A7FFBEAECE}" = Whitesmoke Translator
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{335B1821-D274-4EFD-9EFE-3C0FD38EBE65}" = BN eReader
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D08333C-C366-425D-8C2D-D05630D68A46}" = SlingPlayer
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{58F58158-8DFE-31DA-AC1F-7E5D89A0F74F}" = Google Talk Plugin
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 2.7
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7736FD0A-9BF4-40F3-AF12-2E95D65D964F}" = TEAM MANAGER 5.0 for Swimming
"{7CE480FF-5B49-490E-BC18-1C663ECC0B61}" = MEET MANAGER 2.0 for Swimming
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_BASICR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_BASICR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_BASICR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91120000-0013-0000-0000-0000000FF1CE}" = Microsoft Office Basic 2007
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}" = MEET MANAGER 3.0 for Swimming
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG Free 9.0
"BASICR" = Microsoft Office Basic 2007
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Flickr Uploadr" = Flickr Uploadr 3.1.3
"Gizmo5" = Gizmo5
"Google Chrome Frame" = Google Chrome Frame
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.480
"Hardwood Euchre" = Hardwood Euchre
"InstallShield_{3D08333C-C366-425D-8C2D-D05630D68A46}" = SlingPlayer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NetDrive" = NetDrive
"SynTPDeinstKey" = Dell Touchpad
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/1/2010 11:34:50 AM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 10/5/2010 8:00:46 AM | Computer Name = Janet-PC | Source = VSS | ID = 8194
Description =
Error - 10/6/2010 8:31:24 PM | Computer Name = Janet-PC | Source = MsiInstaller | ID = 11321
Description =
Error - 10/6/2010 8:31:27 PM | Computer Name = Janet-PC | Source = MsiInstaller | ID = 1024
Description =
Error - 10/17/2010 11:38:03 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.2.3.231, time stamp 0x4c19bfc2,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x07521b48, process id 0x178c, application start time 0x01cb6e1138d5eb50.
Error - 10/17/2010 6:01:22 PM | Computer Name = Janet-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18975 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 9e8 Start Time: 01cb6e45a6705ea0 Termination Time: 15
Error - 10/26/2010 8:48:30 AM | Computer Name = Janet-PC | Source = VSS | ID = 8194
Description =
Error - 10/29/2010 1:37:17 PM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 10/29/2010 3:49:22 PM | Computer Name = Janet-PC | Source = EventSystem | ID = 4621
Description =
Error - 11/4/2010 9:17:50 AM | Computer Name = Janet-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 123c Start Time: 01cb7bbc839f3bb0 Termination Time: 8
[ Broadcom Wireless LAN Events ]
Error - 9/7/2010 8:03:13 AM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 08:03:13, Tue, Sep 07, 10 Error - Unable to gain access to user store
Error - 9/23/2010 12:54:28 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 12:54:28, Thu, Sep 23, 10 Error - Unable to gain access to user store
Error - 10/13/2010 1:40:02 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 13:40:01, Wed, Oct 13, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:02:41 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:02:40, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:07:02 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:07:02, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:38:23 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:38:23, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 8:49:59 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:49:59, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/6/2010 10:13:25 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 22:13:25, Sat, Nov 06, 10 Error - Unable to gain access to user store
Error - 11/7/2010 9:33:36 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:33:34, Sun, Nov 07, 10 Error - Unable to gain access to user store
Error - 11/7/2010 9:57:48 PM | Computer Name = Janet-PC | Source = WLAN-Tray | ID = 0
Description = 20:57:48, Sun, Nov 07, 10 Error - Unable to gain access to user store
[ OSession Events ]
Error - 1/11/2008 6:14:17 PM | Computer Name = Janet-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 272
seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/28/2009 11:04:00 AM | Computer Name = Janet-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 11/7/2010 9:13:40 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:13:40 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:14:14 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:14:14 PM | Computer Name = Janet-PC | Source = DCOM | ID = 10005
Description =
Error - 11/7/2010 9:14:16 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/7/2010 9:33:46 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 11/7/2010 9:57:29 PM | Computer Name = Janet-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:55:21 PM on 11/7/2010 was unexpected.
Error - 11/7/2010 9:58:03 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 11/8/2010 1:59:13 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 11/8/2010 5:54:32 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7032
Description =
< End of report >