Patrick's Mom
Topic Starter
Hello again! My son is home for Thanksgiving, and wants a new PC because his is so slow and freezes up unexpectedly. I'd like to clean it up first - rather than buy a PC - it's only 15 months old. I am hesitant to try to clean it up on my own. Can you assist? I appreciate any help you can give - thank you in advance!
Sara
Here are the OTL files:
OTL.txt:
OTL logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (alssvc) – C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NvtSp50) – C:\Windows\System32\Drivers\NvtSp50.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (HECI) Intel® – C:\Windows\system32\drivers\heci.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (WavxDMgr) – C:\Windows\System32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (cvusbdrv) – C:\Windows\System32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rixdpcie) – C:\Windows\system32\drivers\rixdpe86.sys (REDC)
DRV - (risdpcie) – C:\Windows\system32\drivers\risdpe86.sys (REDC)
DRV - (rimspci) – C:\Windows\system32\drivers\rimspe86.sys (REDC)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (PBADRV) – C:\Windows\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.adultswim.com/shows/metalocalyp…tour/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.timanderic.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 17:25:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/11 11:33:34 | 000,000,000 | —D | M]
[2009/10/02 00:52:54 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Extensions
[2010/11/21 11:47:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions
[2009/10/02 10:34:02 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/03 22:53:12 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/18 01:02:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\[removed]
[2009/11/03 22:53:17 | 000,004,554 | —- | M] () – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\searchplugins\aim-search.xml
[2009/10/02 00:52:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/08/03 04:11:58 | 000,094,208 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/09/03 15:20:16 | 000,000,051 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2001/08/03 04:11:58 | 000,094,208 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/11/15 15:21:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/11/15 09:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2010/11/15 09:49:56 | 000,000,000 | —D | C] – C:\Users\Pat\Documents\Vindictus
[2010/11/15 09:47:05 | 000,000,000 | —D | C] – C:\Program Files\BandiMPEG1
[2010/10/27 09:43:59 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/27 09:43:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 09:37:28 | 000,258,536 | —- | C] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/27 09:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Screentime
[2010/10/27 09:37:20 | 000,000,000 | —D | C] – C:\Users\Pat\AppData\Local\Screentime
[2010/10/24 02:21:20 | 000,000,000 | —D | C] – C:\Users\Pat\Desktop
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/21 20:17:41 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/21 20:01:01 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/21 19:45:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/21 11:40:20 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/21 11:40:20 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/21 11:35:47 | 000,000,000 | —- | M] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2010/11/21 11:35:42 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2010/11/18 19:39:26 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/17 19:05:39 | 000,001,536 | —- | M] () – C:\Users\Pat\Contacts\Desktop\NO$GBA.INP
[2010/11/17 18:23:52 | 000,008,268 | —- | M] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2010/11/15 15:21:39 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/11/15 09:47:06 | 000,000,207 | —- | M] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/27 09:37:28 | 000,258,536 | —- | M] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/26 19:44:15 | 000,000,295 | —- | M] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/10/24 02:01:41 | 000,012,288 | —- | M] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/15 09:47:06 | 000,000,207 | —- | C] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/26 19:44:15 | 000,000,295 | —- | C] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/07/02 19:35:00 | 000,056,320 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2010/07/02 19:28:22 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/30 20:12:11 | 000,000,208 | —- | C] () – C:\Windows\TLCAPPS.INI
[2010/06/30 20:11:31 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2010/05/18 12:16:03 | 000,065,536 | —- | C] () – C:\Windows\System32\HPPLVS.dll
[2010/05/11 11:02:13 | 000,000,552 | —- | C] () – C:\Users\Pat\AppData\Local\d3d8caps.dat
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\Users\Pat\AppData\Local\ru6R
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\ProgramData\ru6R
[2009/10/07 12:48:46 | 000,008,268 | —- | C] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/08/31 18:43:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/30 13:01:10 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/08/07 21:30:08 | 000,000,036 | -H– | C] () – C:\Windows\System32\swk.ini
[2009/08/07 21:27:49 | 000,012,288 | —- | C] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/01 13:13:07 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/01 13:05:21 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/01 10:06:42 | 000,000,000 | —- | C] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2009/07/27 20:32:24 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/07/27 20:21:57 | 000,279,888 | —- | C] () – C:\Windows\System32\brcmbsp.dll
[2009/07/27 20:19:21 | 000,080,368 | —- | C] () – C:\Windows\System32\pbadrvdll.dll
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/04/22 08:58:30 | 000,126,976 | —- | C] () – C:\Windows\System32\DTMessageLib.dll
[2009/04/10 11:01:12 | 000,143,360 | R— | C] () – C:\Windows\System32\preflib.dll
[2009/02/26 15:54:52 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_tr.dll
[2009/02/26 15:54:50 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_ro.dll
[2009/02/26 15:54:48 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt-BR.dll
[2009/02/26 15:54:48 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_hu.dll
[2009/02/26 15:54:46 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_he.dll
[2009/02/26 15:54:44 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_el.dll
[2009/02/26 15:54:44 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_fi.dll
[2009/02/26 15:54:42 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_cs.dll
[2009/02/26 15:54:40 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_ar.dll
[2009/02/26 15:54:40 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHT.dll
[2009/02/26 15:54:38 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHS.dll
[2009/02/26 15:54:36 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_sv.dll
[2009/02/26 15:54:34 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt.dll
[2009/02/26 15:54:34 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_ru.dll
[2009/02/26 15:54:32 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pl.dll
[2009/02/26 15:54:32 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_no.dll
[2009/02/26 15:54:30 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_nl.dll
[2009/02/26 15:54:28 | 000,090,112 | —- | C] () – C:\Windows\System32\Internationalization_ja.dll
[2009/02/26 15:54:28 | 000,086,016 | —- | C] () – C:\Windows\System32\Internationalization_ko.dll
[2009/02/26 15:54:26 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_it.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_fr.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_es.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_de.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_da.dll
[2009/02/17 08:51:28 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_es.dll
[2009/02/17 08:51:28 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_en.dll
[2009/02/17 08:51:26 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_fr.dll
[2009/02/17 08:51:24 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_it.dll
[2009/02/17 08:51:24 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_ja.dll
[2009/02/17 08:51:24 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_ko.dll
[2009/02/17 08:51:22 | 000,565,248 | —- | C] () – C:\Windows\System32\AmRes_ru.dll
[2009/02/17 08:51:22 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_pt-BR.dll
[2009/02/17 08:51:20 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_fi.dll
[2009/02/17 08:51:20 | 000,479,232 | —- | C] () – C:\Windows\System32\AmRes_zh-CHT.dll
[2009/02/17 08:51:20 | 000,475,136 | —- | C] () – C:\Windows\System32\AmRes_zh-CHS.dll
[2009/02/17 08:51:18 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_da.dll
[2009/02/17 08:51:16 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_nl.dll
[2009/02/17 08:51:16 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_pl.dll
[2009/02/17 08:51:16 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_no.dll
[2009/02/17 08:51:14 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_sv.dll
[2009/02/17 08:51:04 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_cs.dll
[2009/02/17 08:51:04 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_ar.dll
[2009/02/17 08:51:02 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_el.dll
[2009/02/17 08:51:02 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_he.dll
[2009/02/17 08:51:00 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_pt-PT.dll
[2009/02/17 08:51:00 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_hu.dll
[2009/02/17 08:50:58 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_ro.dll
[2009/02/17 08:50:58 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_tr.dll
[2009/02/17 07:46:36 | 000,544,768 | —- | C] () – C:\Windows\System32\AmRes_de.dll
[2009/01/06 15:25:36 | 000,010,752 | —- | C] () – C:\Windows\System32\Wavx_ESC_Logging.dll
[2008/12/22 13:13:54 | 000,249,856 | —- | C] () – C:\Windows\System32\wxvault.dll
[2008/10/06 17:36:56 | 000,839,680 | —- | C] () – C:\Windows\System32\DemoLicense.dll
[2008/03/25 08:46:00 | 000,077,536 | —- | C] () – C:\Windows\System32\xltZlib.dll
[2007/04/19 04:52:16 | 000,080,720 | —- | C] () – C:\Windows\System32\AsfBios.dll
[2007/04/19 04:28:10 | 000,025,424 | —- | C] () – C:\Windows\System32\drivers\netamsg.dll
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/30 11:58:44 | 000,176,128 | R— | C] () – C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 11:58:44 | 000,126,976 | R— | C] () – C:\Windows\System32\bioapi100.dll
[2004/09/10 12:34:00 | 000,917,504 | —- | C] () – C:\Windows\System32\lmgr10.dll
[2004/09/10 12:34:00 | 000,057,344 | —- | C] () – C:\Windows\System32\ADsSecurity.dll
========== LOP Check ==========
[2009/11/03 22:45:29 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\acccore
[2009/08/01 10:06:40 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Broadcom
[2010/11/21 20:25:28 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\DNA
[2010/10/24 02:21:23 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\GetRightToGo
[2010/02/08 22:59:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\NeopleLauncherDFO
[2009/10/24 20:33:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Recruitment Viewer
[2009/08/01 10:06:58 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Wave Systems Corp
[2010/11/21 02:15:13 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 20:34:29 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/07/27 22:58:15 | 000,004,848 | RH– | M] () – C:\dell.sdr
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2009/11/03 22:45:18 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2010/05/18 12:17:13 | 000,020,012 | —- | M] () – C:\P1005.log
[2010/11/21 11:35:12 | 4059,037,696 | -HS- | M] () – C:\pagefile.sys
[2009/08/01 13:13:10 | 000,000,272 | —- | M] () – C:\Sonic-and-Knuckles-(JUE)-[!].srm
< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/22 10:50:36 | 000,293,888 | —- | M] (Hewlett-Packard ) – C:\Windows\System32\spool\prtprocs\w32x86\HP1006S.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/08/30 13:01:16 | 000,191,488 | —- | M] (ScreenTime Media) – C:\Windows\Final Fantasy VII Advent Children.scr
[2008/12/04 21:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 21:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/07 21:26:27 | 000,000,286 | -HS- | M] () – C:\Users\Pat\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 15:11:15
========== Files - Unicode (All) ==========
[2010/11/15 09:52:24 | 000,000,000 | —D | M](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
[2010/11/15 09:52:24 | 000,000,000 | —D | C](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613
< End of report >
extras.txt:
OTL Extras logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2D5CDB5B-24D0-4104-908E-D6B082A02396}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7E88AC9D-D5C0-40DB-ACE6-6401E26B3CCD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{9F8D2359-04C3-4611-98A1-26BF3B933726}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05128281-0438-4E44-BDBE-7FCAA6A03A48}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{1F5BDB5F-427A-4387-A322-0B24057539A2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{23CE22F3-84B8-421D-A12F-5EF235E579D6}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{23FA1FFE-2603-4600-B2D0-DD69F675810E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{3ECE04F1-553F-4146-8601-41D51B463E8D}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{420F21E6-9FC7-476C-A122-8FCEDB73AAB1}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{5ADCDF6F-293A-4C61-B9C7-5F80B70C7BE5}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{641BA14C-3609-4E3D-93F6-DC68CB78B019}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{69062C4B-C3A0-4C7A-BBD9-0F4B68E7BC1D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{712C0BCD-E2C0-4911-8C6F-C146F244B4C0}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{8C5AF45F-CC6D-434E-A21B-95799617B9F2}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{91F5B763-B607-4432-AF65-B952E03484F7}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B935B986-C31C-4672-B1E5-10A13CB4A13D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BF6C7D7F-0306-451D-BFEA-74225DDB862A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C4C34B1B-6F9A-410D-86CC-6E366187AF33}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C78631D8-6EAC-49F7-A9C4-EA5A9D43751B}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{CD88E44B-7724-4AD8-A33A-0C283A6E879C}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{D41B1B59-ECE4-4A94-ACF5-0D090198F49B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{D65C970B-CC58-44D6-9D28-2DB1F9FC80AD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D90BC12F-5C7E-4775-B99C-98474E032BC8}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F914F5B0-16BF-4E59-BB3B-C180244204FA}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{FECBC724-A526-4E10-A650-BE1B085EB0FE}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"TCP Query User{0E6CC991-DFA1-4E7C-9EC1-D566616DC538}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"TCP Query User{203E858A-550D-4152-B8A0-BA61D4A7CCE5}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=6 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"TCP Query User{3C3E48B0-EE80-45C0-B50D-767B0E3705BA}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=6 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |
"TCP Query User{42B96B34-23A3-48F6-8BAF-5ED69CC75A92}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"TCP Query User{8FCD378D-E8AE-4358-8DAF-FC4FCF81EF4B}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{B1903BA0-C013-4097-8F78-3970B0EADE9F}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{EDBA7BAE-DEA5-4A92-A368-FD71C705C4FB}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{025BF687-FFAE-43CE-A167-E44036761C61}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"UDP Query User{0A89863C-14FC-4F46-9456-9C4219566277}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{3477C977-4216-4D9B-BB6E-ED319E0A5A4D}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=17 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"UDP Query User{655E4FE9-75C0-4996-9019-3BFF8C3D5EA4}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{78B8CB36-8117-47A1-8663-70F472E6BE88}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{7F9800BB-CB29-42FB-B0DB-0E0BC94A4030}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{90F59E27-A25B-4279-8BAB-5AF6046F3F95}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=17 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{10133CDD-50B9-4783-B336-8B48F3653715}" = Star Wars Galactic Battlegrounds: Saga
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2220CF3A-EBD6-4070-94D0-0C7337B537A7}" = All Day Battery Life Configuration
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2484631E-A7B3-4847-ACBB-4D881E6E9D5A}" = Dell ControlPoint Connection Manager
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4994A7CB-2BF4-4664-8FCE-DB66055ECEBC}" = Broadcom USH Host Components
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{5AF4F4C5-C71C-418F-B0B1-3903A345BD71}" = Ambient Light Sensor
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{67436268-FB14-4DFB-AE73-1B1EFA2B0213}" = Dell ControlPoint System Manager
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D3963B0-E13B-4FC3-B0FF-506A304BB043}" = Cisco EAP-FAST Module
"{6EA8A52B-8EA1-4A59-85AB-48132299061A}" = Intel® PRO Alerting Agent
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{86A8FD76-3268-4102-9674-7118881EC2C0}" = Wave Infrastructure Installer
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99E39418-A6C1-4D2B-AF9F-9152C93F03A9}" = Dell Control Point
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9BCAC864-84C0-409F-8D12-364109622D18}_is1" = Europa Barbarorum 1.1
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"{BB93D30B-B395-44BB-A9ED-A0E057F07E53}" = NTRU TCG Software Stack
"{BC52E419-B185-488F-9973-049A88E5DCBE}" = Gemalto
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DAC07FB2-2C63-44B2-8344-AB7542C936D2}" = DCP32MMWrapper
"{DB58A549-42CA-4081-986A-633479DE413F}" = SO32MMWrapper
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"9D57DE505B6D8C710EF3B74BE638DBB936EED8A3" = Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdventureTime_Screensaver" = AdventureTime_Screensaver
"AIM Toolbar" = AIM Toolbar
"avast5" = avast! Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility
"CleanUp!" = CleanUp!
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Defraggler" = Defraggler
"Dell Webcam Central" = Dell Webcam Central
"DFO" = DFOLauncher
"DVD Player_is1" = DVD Player 1.0
"EB Documentation_is1" = EB Documentation 1.1
"EB Trivial Script_is1" = EB Trivial Script 0.125
"Final Fantasy VII Advent Children" = Final Fantasy VII Advent Children?????????
"GOM Player" = GOM Player
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007 Trial
"PROSetDX" = Intel® Network Connections 13.0.42.0
"Recruitment Viewer_is1" = Recruitment Viewer 0.9
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Sonic and Knuckles 2_is1" = Sonic and Knuckles 2 1.0
"Sonic and Knuckles 3_is1" = Sonic and Knuckles 3 1.0
"Sonic and Knuckles_is1" = Sonic and Knuckles
"Vindictus" = Vindictus
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/15/2010 5:46:17 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/15/2010 5:47:01 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/15/2010 5:47:02 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 2:24:34 AM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =
Error - 4/16/2010 3:45:57 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/16/2010 3:46:05 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 3:46:07 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 8:03:08 PM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =
Error - 4/16/2010 8:04:14 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/16/2010 8:04:40 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
[ Broadcom Wireless LAN Events ]
Error - 11/21/2010 3:56:00 AM | Computer Name = Pat-PC | Source = WLAN-Tray | ID = 0
Description = 01:56:00, Sun, Nov 21, 10 Error - Unable to gain access to user store
[ System Events ]
Error - 11/19/2010 12:55:34 AM | Computer Name = PAT-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/19/2010 12:55:30 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/19/2010 10:39:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/20/2010 1:51:01 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:07:53 PM on 11/19/2010 was unexpected.
Error - 11/20/2010 1:51:09 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/20/2010 4:36:45 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 3:54:05 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:31:35 AM on 11/21/2010 was unexpected.
Error - 11/21/2010 3:54:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 1:35:25 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 1:35:28 PM | Computer Name = Pat-PC | Source = Service Control Manager | ID = 7001
Description =
< End of report >
Sara
Here are the OTL files:
OTL.txt:
OTL logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (alssvc) – C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NvtSp50) – C:\Windows\System32\Drivers\NvtSp50.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (HECI) Intel® – C:\Windows\system32\drivers\heci.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (WavxDMgr) – C:\Windows\System32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (cvusbdrv) – C:\Windows\System32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rixdpcie) – C:\Windows\system32\drivers\rixdpe86.sys (REDC)
DRV - (risdpcie) – C:\Windows\system32\drivers\risdpe86.sys (REDC)
DRV - (rimspci) – C:\Windows\system32\drivers\rimspe86.sys (REDC)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (PBADRV) – C:\Windows\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.adultswim.com/shows/metalocalyp…tour/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.timanderic.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 17:25:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/11 11:33:34 | 000,000,000 | —D | M]
[2009/10/02 00:52:54 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Extensions
[2010/11/21 11:47:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions
[2009/10/02 10:34:02 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/03 22:53:12 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/18 01:02:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\[removed]
[2009/11/03 22:53:17 | 000,004,554 | —- | M] () – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\searchplugins\aim-search.xml
[2009/10/02 00:52:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/08/03 04:11:58 | 000,094,208 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/09/03 15:20:16 | 000,000,051 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2001/08/03 04:11:58 | 000,094,208 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/11/15 15:21:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/11/15 09:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2010/11/15 09:49:56 | 000,000,000 | —D | C] – C:\Users\Pat\Documents\Vindictus
[2010/11/15 09:47:05 | 000,000,000 | —D | C] – C:\Program Files\BandiMPEG1
[2010/10/27 09:43:59 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/27 09:43:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 09:37:28 | 000,258,536 | —- | C] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/27 09:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Screentime
[2010/10/27 09:37:20 | 000,000,000 | —D | C] – C:\Users\Pat\AppData\Local\Screentime
[2010/10/24 02:21:20 | 000,000,000 | —D | C] – C:\Users\Pat\Desktop
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/21 20:17:41 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/21 20:01:01 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/21 19:45:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/21 11:40:20 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/21 11:40:20 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/21 11:35:47 | 000,000,000 | —- | M] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2010/11/21 11:35:42 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2010/11/18 19:39:26 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/17 19:05:39 | 000,001,536 | —- | M] () – C:\Users\Pat\Contacts\Desktop\NO$GBA.INP
[2010/11/17 18:23:52 | 000,008,268 | —- | M] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2010/11/15 15:21:39 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/11/15 09:47:06 | 000,000,207 | —- | M] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/27 09:37:28 | 000,258,536 | —- | M] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/26 19:44:15 | 000,000,295 | —- | M] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/10/24 02:01:41 | 000,012,288 | —- | M] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/15 09:47:06 | 000,000,207 | —- | C] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/26 19:44:15 | 000,000,295 | —- | C] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/07/02 19:35:00 | 000,056,320 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2010/07/02 19:28:22 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/30 20:12:11 | 000,000,208 | —- | C] () – C:\Windows\TLCAPPS.INI
[2010/06/30 20:11:31 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2010/05/18 12:16:03 | 000,065,536 | —- | C] () – C:\Windows\System32\HPPLVS.dll
[2010/05/11 11:02:13 | 000,000,552 | —- | C] () – C:\Users\Pat\AppData\Local\d3d8caps.dat
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\Users\Pat\AppData\Local\ru6R
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\ProgramData\ru6R
[2009/10/07 12:48:46 | 000,008,268 | —- | C] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/08/31 18:43:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/30 13:01:10 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/08/07 21:30:08 | 000,000,036 | -H– | C] () – C:\Windows\System32\swk.ini
[2009/08/07 21:27:49 | 000,012,288 | —- | C] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/01 13:13:07 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/01 13:05:21 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/01 10:06:42 | 000,000,000 | —- | C] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2009/07/27 20:32:24 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/07/27 20:21:57 | 000,279,888 | —- | C] () – C:\Windows\System32\brcmbsp.dll
[2009/07/27 20:19:21 | 000,080,368 | —- | C] () – C:\Windows\System32\pbadrvdll.dll
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/04/22 08:58:30 | 000,126,976 | —- | C] () – C:\Windows\System32\DTMessageLib.dll
[2009/04/10 11:01:12 | 000,143,360 | R— | C] () – C:\Windows\System32\preflib.dll
[2009/02/26 15:54:52 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_tr.dll
[2009/02/26 15:54:50 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_ro.dll
[2009/02/26 15:54:48 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt-BR.dll
[2009/02/26 15:54:48 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_hu.dll
[2009/02/26 15:54:46 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_he.dll
[2009/02/26 15:54:44 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_el.dll
[2009/02/26 15:54:44 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_fi.dll
[2009/02/26 15:54:42 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_cs.dll
[2009/02/26 15:54:40 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_ar.dll
[2009/02/26 15:54:40 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHT.dll
[2009/02/26 15:54:38 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHS.dll
[2009/02/26 15:54:36 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_sv.dll
[2009/02/26 15:54:34 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt.dll
[2009/02/26 15:54:34 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_ru.dll
[2009/02/26 15:54:32 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pl.dll
[2009/02/26 15:54:32 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_no.dll
[2009/02/26 15:54:30 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_nl.dll
[2009/02/26 15:54:28 | 000,090,112 | —- | C] () – C:\Windows\System32\Internationalization_ja.dll
[2009/02/26 15:54:28 | 000,086,016 | —- | C] () – C:\Windows\System32\Internationalization_ko.dll
[2009/02/26 15:54:26 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_it.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_fr.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_es.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_de.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_da.dll
[2009/02/17 08:51:28 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_es.dll
[2009/02/17 08:51:28 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_en.dll
[2009/02/17 08:51:26 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_fr.dll
[2009/02/17 08:51:24 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_it.dll
[2009/02/17 08:51:24 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_ja.dll
[2009/02/17 08:51:24 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_ko.dll
[2009/02/17 08:51:22 | 000,565,248 | —- | C] () – C:\Windows\System32\AmRes_ru.dll
[2009/02/17 08:51:22 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_pt-BR.dll
[2009/02/17 08:51:20 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_fi.dll
[2009/02/17 08:51:20 | 000,479,232 | —- | C] () – C:\Windows\System32\AmRes_zh-CHT.dll
[2009/02/17 08:51:20 | 000,475,136 | —- | C] () – C:\Windows\System32\AmRes_zh-CHS.dll
[2009/02/17 08:51:18 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_da.dll
[2009/02/17 08:51:16 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_nl.dll
[2009/02/17 08:51:16 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_pl.dll
[2009/02/17 08:51:16 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_no.dll
[2009/02/17 08:51:14 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_sv.dll
[2009/02/17 08:51:04 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_cs.dll
[2009/02/17 08:51:04 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_ar.dll
[2009/02/17 08:51:02 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_el.dll
[2009/02/17 08:51:02 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_he.dll
[2009/02/17 08:51:00 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_pt-PT.dll
[2009/02/17 08:51:00 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_hu.dll
[2009/02/17 08:50:58 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_ro.dll
[2009/02/17 08:50:58 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_tr.dll
[2009/02/17 07:46:36 | 000,544,768 | —- | C] () – C:\Windows\System32\AmRes_de.dll
[2009/01/06 15:25:36 | 000,010,752 | —- | C] () – C:\Windows\System32\Wavx_ESC_Logging.dll
[2008/12/22 13:13:54 | 000,249,856 | —- | C] () – C:\Windows\System32\wxvault.dll
[2008/10/06 17:36:56 | 000,839,680 | —- | C] () – C:\Windows\System32\DemoLicense.dll
[2008/03/25 08:46:00 | 000,077,536 | —- | C] () – C:\Windows\System32\xltZlib.dll
[2007/04/19 04:52:16 | 000,080,720 | —- | C] () – C:\Windows\System32\AsfBios.dll
[2007/04/19 04:28:10 | 000,025,424 | —- | C] () – C:\Windows\System32\drivers\netamsg.dll
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/30 11:58:44 | 000,176,128 | R— | C] () – C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 11:58:44 | 000,126,976 | R— | C] () – C:\Windows\System32\bioapi100.dll
[2004/09/10 12:34:00 | 000,917,504 | —- | C] () – C:\Windows\System32\lmgr10.dll
[2004/09/10 12:34:00 | 000,057,344 | —- | C] () – C:\Windows\System32\ADsSecurity.dll
========== LOP Check ==========
[2009/11/03 22:45:29 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\acccore
[2009/08/01 10:06:40 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Broadcom
[2010/11/21 20:25:28 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\DNA
[2010/10/24 02:21:23 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\GetRightToGo
[2010/02/08 22:59:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\NeopleLauncherDFO
[2009/10/24 20:33:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Recruitment Viewer
[2009/08/01 10:06:58 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Wave Systems Corp
[2010/11/21 02:15:13 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 20:34:29 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/07/27 22:58:15 | 000,004,848 | RH– | M] () – C:\dell.sdr
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2009/11/03 22:45:18 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2010/05/18 12:17:13 | 000,020,012 | —- | M] () – C:\P1005.log
[2010/11/21 11:35:12 | 4059,037,696 | -HS- | M] () – C:\pagefile.sys
[2009/08/01 13:13:10 | 000,000,272 | —- | M] () – C:\Sonic-and-Knuckles-(JUE)-[!].srm
< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/22 10:50:36 | 000,293,888 | —- | M] (Hewlett-Packard ) – C:\Windows\System32\spool\prtprocs\w32x86\HP1006S.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/08/30 13:01:16 | 000,191,488 | —- | M] (ScreenTime Media) – C:\Windows\Final Fantasy VII Advent Children.scr
[2008/12/04 21:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 21:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/07 21:26:27 | 000,000,286 | -HS- | M] () – C:\Users\Pat\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 15:11:15
========== Files - Unicode (All) ==========
[2010/11/15 09:52:24 | 000,000,000 | —D | M](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
[2010/11/15 09:52:24 | 000,000,000 | —D | C](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613
< End of report >
extras.txt:
OTL Extras logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2D5CDB5B-24D0-4104-908E-D6B082A02396}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7E88AC9D-D5C0-40DB-ACE6-6401E26B3CCD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{9F8D2359-04C3-4611-98A1-26BF3B933726}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05128281-0438-4E44-BDBE-7FCAA6A03A48}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{1F5BDB5F-427A-4387-A322-0B24057539A2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{23CE22F3-84B8-421D-A12F-5EF235E579D6}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{23FA1FFE-2603-4600-B2D0-DD69F675810E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{3ECE04F1-553F-4146-8601-41D51B463E8D}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{420F21E6-9FC7-476C-A122-8FCEDB73AAB1}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{5ADCDF6F-293A-4C61-B9C7-5F80B70C7BE5}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{641BA14C-3609-4E3D-93F6-DC68CB78B019}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{69062C4B-C3A0-4C7A-BBD9-0F4B68E7BC1D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{712C0BCD-E2C0-4911-8C6F-C146F244B4C0}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{8C5AF45F-CC6D-434E-A21B-95799617B9F2}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{91F5B763-B607-4432-AF65-B952E03484F7}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B935B986-C31C-4672-B1E5-10A13CB4A13D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BF6C7D7F-0306-451D-BFEA-74225DDB862A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C4C34B1B-6F9A-410D-86CC-6E366187AF33}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C78631D8-6EAC-49F7-A9C4-EA5A9D43751B}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{CD88E44B-7724-4AD8-A33A-0C283A6E879C}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{D41B1B59-ECE4-4A94-ACF5-0D090198F49B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{D65C970B-CC58-44D6-9D28-2DB1F9FC80AD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D90BC12F-5C7E-4775-B99C-98474E032BC8}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F914F5B0-16BF-4E59-BB3B-C180244204FA}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{FECBC724-A526-4E10-A650-BE1B085EB0FE}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"TCP Query User{0E6CC991-DFA1-4E7C-9EC1-D566616DC538}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"TCP Query User{203E858A-550D-4152-B8A0-BA61D4A7CCE5}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=6 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"TCP Query User{3C3E48B0-EE80-45C0-B50D-767B0E3705BA}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=6 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |
"TCP Query User{42B96B34-23A3-48F6-8BAF-5ED69CC75A92}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"TCP Query User{8FCD378D-E8AE-4358-8DAF-FC4FCF81EF4B}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{B1903BA0-C013-4097-8F78-3970B0EADE9F}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{EDBA7BAE-DEA5-4A92-A368-FD71C705C4FB}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{025BF687-FFAE-43CE-A167-E44036761C61}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"UDP Query User{0A89863C-14FC-4F46-9456-9C4219566277}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{3477C977-4216-4D9B-BB6E-ED319E0A5A4D}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=17 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"UDP Query User{655E4FE9-75C0-4996-9019-3BFF8C3D5EA4}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{78B8CB36-8117-47A1-8663-70F472E6BE88}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{7F9800BB-CB29-42FB-B0DB-0E0BC94A4030}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{90F59E27-A25B-4279-8BAB-5AF6046F3F95}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=17 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{10133CDD-50B9-4783-B336-8B48F3653715}" = Star Wars Galactic Battlegrounds: Saga
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2220CF3A-EBD6-4070-94D0-0C7337B537A7}" = All Day Battery Life Configuration
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2484631E-A7B3-4847-ACBB-4D881E6E9D5A}" = Dell ControlPoint Connection Manager
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4994A7CB-2BF4-4664-8FCE-DB66055ECEBC}" = Broadcom USH Host Components
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{5AF4F4C5-C71C-418F-B0B1-3903A345BD71}" = Ambient Light Sensor
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{67436268-FB14-4DFB-AE73-1B1EFA2B0213}" = Dell ControlPoint System Manager
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D3963B0-E13B-4FC3-B0FF-506A304BB043}" = Cisco EAP-FAST Module
"{6EA8A52B-8EA1-4A59-85AB-48132299061A}" = Intel® PRO Alerting Agent
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{86A8FD76-3268-4102-9674-7118881EC2C0}" = Wave Infrastructure Installer
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99E39418-A6C1-4D2B-AF9F-9152C93F03A9}" = Dell Control Point
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9BCAC864-84C0-409F-8D12-364109622D18}_is1" = Europa Barbarorum 1.1
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"{BB93D30B-B395-44BB-A9ED-A0E057F07E53}" = NTRU TCG Software Stack
"{BC52E419-B185-488F-9973-049A88E5DCBE}" = Gemalto
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DAC07FB2-2C63-44B2-8344-AB7542C936D2}" = DCP32MMWrapper
"{DB58A549-42CA-4081-986A-633479DE413F}" = SO32MMWrapper
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"9D57DE505B6D8C710EF3B74BE638DBB936EED8A3" = Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdventureTime_Screensaver" = AdventureTime_Screensaver
"AIM Toolbar" = AIM Toolbar
"avast5" = avast! Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility
"CleanUp!" = CleanUp!
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Defraggler" = Defraggler
"Dell Webcam Central" = Dell Webcam Central
"DFO" = DFOLauncher
"DVD Player_is1" = DVD Player 1.0
"EB Documentation_is1" = EB Documentation 1.1
"EB Trivial Script_is1" = EB Trivial Script 0.125
"Final Fantasy VII Advent Children" = Final Fantasy VII Advent Children?????????
"GOM Player" = GOM Player
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007 Trial
"PROSetDX" = Intel® Network Connections 13.0.42.0
"Recruitment Viewer_is1" = Recruitment Viewer 0.9
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Sonic and Knuckles 2_is1" = Sonic and Knuckles 2 1.0
"Sonic and Knuckles 3_is1" = Sonic and Knuckles 3 1.0
"Sonic and Knuckles_is1" = Sonic and Knuckles
"Vindictus" = Vindictus
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/15/2010 5:46:17 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/15/2010 5:47:01 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/15/2010 5:47:02 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 2:24:34 AM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =
Error - 4/16/2010 3:45:57 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/16/2010 3:46:05 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 3:46:07 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
Error - 4/16/2010 8:03:08 PM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =
Error - 4/16/2010 8:04:14 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =
Error - 4/16/2010 8:04:40 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM
[ Broadcom Wireless LAN Events ]
Error - 11/21/2010 3:56:00 AM | Computer Name = Pat-PC | Source = WLAN-Tray | ID = 0
Description = 01:56:00, Sun, Nov 21, 10 Error - Unable to gain access to user store
[ System Events ]
Error - 11/19/2010 12:55:34 AM | Computer Name = PAT-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/19/2010 12:55:30 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/19/2010 10:39:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/20/2010 1:51:01 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:07:53 PM on 11/19/2010 was unexpected.
Error - 11/20/2010 1:51:09 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/20/2010 4:36:45 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 3:54:05 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:31:35 AM on 11/21/2010 was unexpected.
Error - 11/21/2010 3:54:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 1:35:25 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =
Error - 11/21/2010 1:35:28 PM | Computer Name = Pat-PC | Source = Service Control Manager | ID = 7001
Description =
< End of report >