Here is the ESET log:
C:\Documents and Settings\Bruce Moody\Application Data\Sun\Java\Deployment\cache\6.0\27\212ee35b-1113a011 multiple threats
C:\Qoobox\Quarantine\C\Documents and Settings\Bruce Moody\Application Data\Adobe\plugs\KB19061531.exe.vir a variant of Win32/Cimag.EY trojan
C:\Qoobox\Quarantine\C\WINDOWS\kmsypw.dll.vir a variant of Win32/Cimag.EY trojan
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1\A0000018.exe a variant of Win32/Cimag.EY trojan
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1\A0000024.dll a variant of Win32/Cimag.EY trojan
C:\WINDOWS\system32\chkndlin.dll a variant of Win32/PSW.Papras.BS trojan
Operating memory a variant of Win32/PSW.Papras.BS trojan
——————————————————–
Here is the OTL logfile along with the associated OTL Extras log:
OTL logfile created on: 12/11/2010 4:16:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Bruce Moody\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 921.71 Gb Total Space | 904.77 Gb Free Space | 98.16% Space Free | Partition Type: NTFS
Drive K: | 614.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 465.11 Gb Total Space | 464.40 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 32.08 Gb Free Space | 28.70% Space Free | Partition Type: NTFS
Computer Name: BRUCE | User Name: Bruce Moody | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Bruce Moody\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Bruce Moody\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (WDSmartWareBackgroundService) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\DOCUME~1\BRUCEM~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (t3) – C:\WINDOWS\system32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (t3filt) – C:\WINDOWS\system32\drivers\t3filt.sys (Creative)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (ahcix86) – C:\WINDOWS\system32\drivers\ahcix86.sys (Advanced Micro Devices, Inc)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (adfs) – C:\WINDOWS\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.apsvideo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2010/04/30 20:23:45 | 000,000,000 | —D | M]
O1 HOSTS File: ([2010/12/11 11:00:34 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101103171757.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CTAPR2] C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] c:\Program Files\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 5.0\SetHook.exe (Fellowes, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SPIRun] C:\WINDOWS\System32\SPIRun.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
O4 - Startup: C:\Documents and Settings\Bruce Moody\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Bruce Moody\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bruce Moody\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/06/18 16:12:18 | 000,000,088 | R— | M] () - K:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/12/11 16:15:31 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bruce Moody\Desktop\OTL.exe
[2010/12/11 15:40:00 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/12/11 14:04:46 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/12/11 10:56:25 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/12/11 10:56:25 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/12/11 10:56:25 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/12/11 10:56:25 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/12/11 10:53:40 | 000,000,000 | —D | C] – C:\Qoobox
[2010/12/09 21:24:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2010/12/09 15:52:26 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/11/29 18:41:56 | 000,000,000 | —D | C] – C:\ComboFix
[2010/11/29 15:19:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Bruce Moody\Application Data\Malwarebytes
[2010/11/29 15:19:37 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 15:19:34 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/29 15:19:34 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/29 15:19:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/29 15:14:16 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Bruce Moody\Desktop\ATF_Cleaner.exe
[2010/11/29 12:31:26 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/11/15 20:21:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegSERVO
[2010/11/14 13:17:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Bruce Moody\Application Data\Macrovision
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/11 16:15:32 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bruce Moody\Desktop\OTL.exe
[2010/12/11 11:00:34 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/11 10:48:55 | 003,988,290 | R— | M] () – C:\Documents and Settings\Bruce Moody\Desktop\jgh.exe
[2010/12/11 10:47:43 | 000,000,120 | —- | M] () – C:\WINDOWS\Cvijobo.dat
[2010/12/11 10:47:43 | 000,000,000 | —- | M] () – C:\WINDOWS\Blelafuvahohi.bin
[2010/12/09 22:01:52 | 000,002,459 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\HiJackThis.lnk
[2010/12/09 22:00:17 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/09 21:59:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/09 21:59:52 | 000,069,112 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2010/12/09 21:59:47 | 3488,731,136 | -HS- | M] () – C:\hiberfil.sys
[2010/12/09 21:52:50 | 001,230,779 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\tdsskiller.zip
[2010/12/09 21:14:15 | 000,048,640 | -H– | M] () – C:\WINDOWS\System32\chkndlin.dll
[2010/12/09 19:24:34 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/09 15:05:29 | 000,051,200 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo SC w Log.doc
[2010/12/09 15:05:26 | 000,029,696 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo Slate.doc
[2010/12/09 14:56:19 | 000,002,515 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Microsoft Office Word 2007.lnk
[2010/12/08 14:14:42 | 000,013,602 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Mini-DV Label of J Card.docx
[2010/12/08 14:13:35 | 000,041,984 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Mini-DV Face Label on Tape WIDER.doc
[2010/12/08 14:11:14 | 000,040,960 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Generic DVD Label.mfp
[2010/12/08 14:06:34 | 000,050,688 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo NC 2 w Log.doc
[2010/12/07 08:11:55 | 000,013,793 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Briefcase Combination Locks Instructions.docx
[2010/12/06 21:27:04 | 000,000,542 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Ron Sparks Mael w Bruce 83.lnk
[2010/12/06 21:23:31 | 000,000,625 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Gordo Apollo WSS # 2 1968 LTA-01a copy w TITLE.lnk
[2010/12/06 21:23:21 | 000,000,622 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Gordo Apollo WSS # 1 1968 LTA-01b copyw TITLE.lnk
[2010/12/02 19:06:54 | 000,051,200 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo AR w Log.doc
[2010/12/02 10:16:21 | 000,013,226 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\SONY BCT.docx
[2010/12/02 09:51:42 | 002,724,054 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Sony 30s.jpg
[2010/12/01 16:57:04 | 002,099,247 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Skylab Guys.jpg
[2010/12/01 16:56:27 | 002,062,063 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Gemini Guys.jpg
[2010/12/01 12:18:41 | 000,016,701 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Briefcase.docx
[2010/12/01 10:41:02 | 000,169,081 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Foxwood Jacket Inside Label.jpg
[2010/12/01 09:21:30 | 003,679,807 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Foxwood Show Jacket.jpg
[2010/12/01 09:20:18 | 003,216,829 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\oncourse Grey Show Pants.jpg
[2010/12/01 09:19:18 | 003,831,597 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Striped Show Coat.jpg
[2010/11/29 15:19:39 | 000,000,698 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/29 15:12:08 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Bruce Moody\Desktop\ATF_Cleaner.exe
[2010/11/29 11:33:06 | 001,228,854 | —- | M] () – C:\0.000000sqwr.bmp
[2010/11/29 08:12:36 | 001,969,014 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\B w Carp & Staff 2 ASF 2010 020.JPG
[2010/11/28 14:50:10 | 000,245,760 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\This is My Book.doc
[2010/11/23 13:27:19 | 000,010,887 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Harrison H Schmitt.docx
[2010/11/22 21:50:40 | 004,014,722 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Duane Graveline LM.jpg
[2010/11/22 16:44:56 | 003,734,016 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Moonprint page.doc
[2010/11/20 21:41:06 | 004,536,506 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2.jpg
[2010/11/20 21:40:54 | 043,350,935 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2.psd
[2010/11/20 21:33:56 | 000,270,380 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2 smaller.jpg
[2010/11/20 21:33:42 | 001,661,083 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2 smaller.psd
[2010/11/20 20:48:58 | 000,012,941 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Characteristics.docx
[2010/11/20 14:50:37 | 000,016,167 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Roland Space Echo.docx
[2010/11/19 15:38:53 | 002,017,906 | —- | M] () – C:\Documents and Settings\Bruce Moody\Desktop\B & P 1981.JPG
[2010/11/18 20:29:49 | 000,030,720 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo Slate Janssen.doc
[2010/11/18 20:28:06 | 000,050,688 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo SC Janssen.doc
[2010/11/16 21:42:44 | 000,050,176 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Depo NC 3 w Log.doc
[2010/11/15 18:02:26 | 000,094,208 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Tom Stafford.doc
[2010/11/15 14:49:22 | 000,013,740 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Fulton County Small Claims.docx
[2010/11/15 10:07:34 | 000,001,731 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/15 09:56:55 | 000,463,862 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/15 09:56:55 | 000,078,958 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/12 11:57:31 | 000,030,720 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\Keenan.doc
[2010/11/12 11:50:16 | 000,030,720 | —- | M] () – C:\Documents and Settings\Bruce Moody\My Documents\APS Letterhead.doc
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/11 13:33:12 | 001,230,779 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\tdsskiller.zip
[2010/12/11 10:56:25 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/12/11 10:56:25 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/12/11 10:56:25 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/12/11 10:56:25 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/12/11 10:56:25 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/11 10:48:55 | 003,988,290 | R— | C] () – C:\Documents and Settings\Bruce Moody\Desktop\jgh.exe
[2010/12/09 21:59:47 | 3488,731,136 | -HS- | C] () – C:\hiberfil.sys
[2010/12/09 21:14:15 | 000,048,640 | -H– | C] () – C:\WINDOWS\System32\chkndlin.dll
[2010/12/09 15:42:45 | 000,000,000 | —- | C] () – C:\WINDOWS\Blelafuvahohi.bin
[2010/12/07 08:11:54 | 000,013,793 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Briefcase Combination Locks Instructions.docx
[2010/12/06 21:27:04 | 000,000,542 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Ron Sparks Mael w Bruce 83.lnk
[2010/12/06 21:23:31 | 000,000,625 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Gordo Apollo WSS # 2 1968 LTA-01a copy w TITLE.lnk
[2010/12/06 21:23:21 | 000,000,622 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Shortcut to Gordo Apollo WSS # 1 1968 LTA-01b copyw TITLE.lnk
[2010/12/02 09:56:43 | 000,013,226 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\SONY BCT.docx
[2010/12/02 09:51:40 | 002,724,054 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Sony 30s.jpg
[2010/12/01 16:51:05 | 002,062,063 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Gemini Guys.jpg
[2010/12/01 16:48:47 | 002,099,247 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Skylab Guys.jpg
[2010/12/01 10:41:24 | 000,169,081 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Foxwood Jacket Inside Label.jpg
[2010/12/01 09:21:28 | 003,679,807 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Foxwood Show Jacket.jpg
[2010/12/01 09:20:17 | 003,216,829 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\oncourse Grey Show Pants.jpg
[2010/12/01 09:19:16 | 003,831,597 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Striped Show Coat.jpg
[2010/11/29 15:19:39 | 000,000,698 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/29 10:14:04 | 001,228,854 | —- | C] () – C:\0.000000sqwr.bmp
[2010/11/27 16:25:41 | 000,016,701 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Briefcase.docx
[2010/11/22 21:50:37 | 004,014,722 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Duane Graveline LM.jpg
[2010/11/22 16:44:23 | 003,734,016 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Moonprint page.doc
[2010/11/22 15:12:00 | 000,010,887 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Harrison H Schmitt.docx
[2010/11/20 14:50:54 | 000,012,941 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Characteristics.docx
[2010/11/19 15:38:52 | 002,017,906 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\B & P 1981.JPG
[2010/11/18 07:54:54 | 000,270,380 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2 smaller.jpg
[2010/11/18 07:54:44 | 001,661,083 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2 smaller.psd
[2010/11/15 17:57:19 | 000,094,208 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Tom Stafford.doc
[2010/11/15 14:41:16 | 000,013,740 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Fulton County Small Claims.docx
[2010/11/15 10:07:34 | 000,001,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/14 11:58:17 | 004,536,506 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2.jpg
[2010/11/14 11:46:02 | 043,350,935 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\Bruce Spacesuit 2.psd
[2010/11/13 10:15:17 | 001,969,014 | —- | C] () – C:\Documents and Settings\Bruce Moody\Desktop\B w Carp & Staff 2 ASF 2010 020.JPG
[2010/11/12 11:55:14 | 000,030,720 | —- | C] () – C:\Documents and Settings\Bruce Moody\My Documents\Keenan.doc
[2010/07/28 07:22:12 | 000,000,934 | —- | C] () – C:\WINDOWS\lsrslt.ini
[2010/05/26 17:05:07 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/04/28 15:00:36 | 000,006,144 | —- | C] () – C:\Documents and Settings\Bruce Moody\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/28 09:07:29 | 000,002,202 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/02/05 02:27:24 | 000,032,914 | —- | C] () – C:\WINDOWS\System32\t3.ini
[2010/02/05 02:25:47 | 000,001,154 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2010/02/05 00:51:19 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/02/05 00:40:37 | 000,118,850 | —- | C] () – C:\WINDOWS\System32\CTPcie.dll
[2010/02/05 00:40:37 | 000,008,535 | —- | C] () – C:\WINDOWS\sfsyn.ini
[2010/02/05 00:40:36 | 000,145,920 | —- | C] () – C:\WINDOWS\System32\OemSpi.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2008/04/25 16:26:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 04:22:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/05/24 17:04:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\lttls13n.dll
[2004/05/24 17:03:20 | 000,708,608 | —- | C] () – C:\WINDOWS\System32\ltcry13n.dll
[2004/05/24 17:01:02 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\lfkodak.dll
[2004/05/24 17:00:48 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
< End of report >
OTL Extras logfile created on: 12/11/2010 4:16:52 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Bruce Moody\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 921.71 Gb Total Space | 904.77 Gb Free Space | 98.16% Space Free | Partition Type: NTFS
Drive K: | 614.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 465.11 Gb Total Space | 464.40 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 32.08 Gb Free Space | 28.70% Space Free | Partition Type: NTFS
Computer Name: BRUCE | User Name: Bruce Moody | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{01483DCE-733A-A6B6-F086-702156A76EE0}" = Catalyst Control Center Localization Thai
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{0FF8BB01-9FB8-0002-86B7-F80215F1F528}" = CCC Help Japanese
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18AEF617-F8A9-7843-A98D-E42BB6716723}" = Catalyst Control Center Localization Czech
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1A33CCAB-A0CF-5B1A-8AC4-ABD5B8539CD2}" = Catalyst Control Center Localization Polish
"{1B9EA89A-7626-00D2-CF48-0E1363BB92C2}" = Catalyst Control Center Graphics Light
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{219AAA69-33E1-0FED-291B-DC4572399707}" = Catalyst Control Center Graphics Full Existing
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22D745C2-D532-50F1-2BA9-76B02281138F}" = CCC Help German
"{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare
"{246E4030-61CB-F57E-9A5A-C064E4E6899B}" = CCC Help Polish
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{310F69FB-1788-3446-1F53-3D613AA498B6}" = CCC Help French
"{340A1E7F-C6A3-33BB-5A97-97CBA19F0EA2}" = Catalyst Control Center Localization German
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{362215E8-A1D9-645E-A77D-9292D93D0FB7}" = Catalyst Control Center Localization Dutch
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{37835166-81A0-1E1C-E1AD-92B96503471A}" = Catalyst Control Center Localization French
"{380799E3-C523-15BF-A3E9-1EA491F74DC0}" = CCC Help Hungarian
"{38DAE5F5-EC70-4aa5-801B-D11CA0A33B41}" = BPDSoftware
"{391B0B7E-EE0E-AABD-2DD4-CBE26BD39830}" = CCC Help Thai
"{39B1E682-2114-BF50-A3ED-E19F40A745A6}" = Catalyst Control Center Localization Danish
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{497DA5D9-5139-5EF7-9AB1-962B47AC820D}" = Catalyst Control Center Localization Korean
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4B759796-0626-D564-6CE0-D0421C995CD1}" = Catalyst Control Center Localization Spanish
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4F252E5A-F52E-E337-5EB4-D514BA019CF8}" = Catalyst Control Center Localization Greek
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{56FC0340-ABFF-43C9-6F33-8F012D8DBEF6}" = CCC Help Chinese Standard
"{57F60D52-630B-43C5-BD20-176F5CD4EED6}" = bpd_scan
"{5C53C986-5AA0-1123-D8F9-58CCC5973B26}" = Catalyst Control Center Localization Hungarian
"{5D356C69-C1FE-884E-8519-DD68FEA3D555}" = CCC Help Portuguese
"{5F132F97-A0FD-3F62-EEAB-19483951BAF3}" = Catalyst Control Center Localization Chinese Traditional
"{63376681-3B57-1FB1-DA9D-D00C1D332643}" = Catalyst Control Center Graphics Previews Common
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{676981B7-A2D9-49D0-9F4C-03018F131DA9}" = DocProc
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6A1ACC15-7632-45ba-A3AB-0250EBD4B7DD}" = 6500_E709a
"{6CC080F1-2E00-41D5-BE47-A3BC784E9DFB}" = BPDSoftware_Ini
"{6DAAC734-8076-51D6-94EB-9258D3882792}" = Catalyst Control Center Localization Turkish
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply
"{70A3C0E1-1953-4A95-9C66-99FDCDD5E357}" = MediaFACE 5.0
"{70B7E764-7117-1452-EA8C-3894FC1570EA}" = CCC Help Swedish
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72AE5ECD-0CAF-4017-BC86-E2908014C09C}" = E-Transcript Bundle Viewer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7A085B75-CA0D-DD78-C946-132C12E16BD9}" = Catalyst Control Center Localization Italian
"{7CCC7010-D0FE-2E3D-5AC3-0235BCE464F2}" = Catalyst Control Center Localization Norwegian
"{800E784D-53E3-4948-B491-9E7FA5EACBDC}" = SmartWebPrinting
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86023B97-8280-3106-F27B-CCA091CE3733}" = Catalyst Control Center Localization Swedish
"{8611D7BC-7594-9C7B-7FFB-40AD0AB0659D}" = CCC Help Italian
"{87A9A9A9-FAB7-4224-9328-0FA2058C0FD5}" = Network
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ABDE213-501B-27DB-6082-709EE5AD408D}" = Catalyst Control Center Localization Finnish
"{8ED407A6-2B26-42FE-D806-575ED7EF904F}" = Catalyst Control Center Core Implementation
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{903679E8-44C8-4C07-9600-05C92654FC50}" = QualXServ Service Agreement
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9129B46A-51F0-431b-9838-DF7272F3204E}" = ProductContext
"{913574EA-B946-D166-B4E1-E18F54561C5C}" = Skins
"{9292B575-0270-BB9C-9CD9-BB6205F0FB92}" = CCC Help English
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan
"{A0998D79-27D3-128E-BD2F-ED039E060969}" = Catalyst Control Center Localization Portuguese
"{A1C19116-33E2-D2C6-8C38-7AB6D44BF73B}" = CCC Help Turkish
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A4BEE562-FD1A-B834-454B-9AEBE79BA35A}" = ccc-core-preinstall
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC629411-9BF8-E825-6034-95B649FD7196}" = ccc-utility
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B33E1644-2097-C80B-3A88-4746DED78022}" = CCC Help Chinese Traditional
"{B5837D44-429B-0625-F760-5115753B7451}" = Catalyst Control Center Localization Japanese
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BF1057E3-910C-50F9-874B-D63E9C043A61}" = CCC Help Czech
"{BF2A8383-ED7C-07B7-BB17-F4BBF99DCB12}" = CCC Help Dutch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C29C1940-CB85-4F3B-906C-33FEE0E67103}" = DocMgr
"{C3735ECA-1972-378A-6720-48015B503E3D}" = CCC Help Finnish
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4B6914D-E6DA-8764-C0FA-639196A9334E}" = Catalyst Control Center Localization Chinese Standard
"{C4D08984-28CA-471D-8F25-DD0467298976}" = Catalyst Control Center Localization Russian
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C93170A0-CBF9-481F-B972-B4FA5AEE0E06}" = Sound Blaster X-Fi
"{CB0FEE8C-320B-A515-B373-344CD4B0214F}" = CCC Help Russian
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DE13432E-F0C1-4842-A5BA-CC997DA72A70}" = 6500_E709_eDocs
"{DE74CBBC-1DD1-88B4-89DA-8EE23321916D}" = CCC Help Korean
"{E00B477F-8558-45DA-B25A-69935FB89A94}" = Dell Dock
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E481DB0E-52F2-4EE0-9BDA-9EE173FA6EA2}" = Catalyst Control Center - Branding
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{EFA43C94-07AF-0A2A-F2BE-239848A073EC}" = CCC Help Danish
"{F00E17C5-E9D4-0E83-9E47-A5E3996F54E0}" = CCC Help Spanish
"{F0622510-B2D0-CEF5-C3D7-317C83A94504}" = CCC Help Norwegian
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F185B35D-38E5-4D88-B275-15C8C7FC4357}" = 6500_E709_Help
"{F4EE52C6-5B61-8CDC-DCEF-EEB397CDAB8D}" = Catalyst Control Center Graphics Full New
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA0F0A01-4631-4161-A6C2-948BF694382E}" = HP Officejet 6500 E709 Series
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FD131FEE-4543-945E-2155-BE8AD15FD124}" = ccc-core-static
"{FEC6A9F8-77A5-4B90-134A-613961747CEC}" = CCC Help Greek
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"ATI Display Driver" = ATI Display Driver
"AudioCS" = Creative Audio Control Panel
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Host OpenAL" = Host OpenAL
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 12.0
"HPOCR" = OCR Software by I.R.I.S. 12.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{70A3C0E1-1953-4A95-9C66-99FDCDD5E357}" = MediaFACE 5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Shop for HP Supplies" = Shop for HP Supplies
"Spell Checker For OE 2.1" = Spell Checker For OE 2.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/9/2010 10:38:36 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 12/9/2010 10:38:37 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 12/9/2010 10:38:42 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 12/9/2010 10:38:42 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 12/9/2010 10:38:42 PM | Computer Name = BRUCE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 12/9/2010 10:48:30 PM | Computer Name = BRUCE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 0.0.0.0, fault address 0x00000000.
Error - 12/9/2010 11:00:44 PM | Computer Name = BRUCE | Source = Windows Search Service | ID = 3013
Description = The entry
SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
Error - 12/9/2010 11:00:44 PM | Computer Name = BRUCE | Source = Windows Search Service | ID = 3013
Description = The entry
SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
Error - 12/9/2010 11:00:44 PM | Computer Name = BRUCE | Source = Windows Search Service | ID = 3013
Description = The entry
SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
Error - 12/9/2010 11:00:44 PM | Computer Name = BRUCE | Source = Windows Search Service | ID = 3013
Description = The entry
SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)
[ System Events ]
Error - 9/15/2010 9:56:47 AM | Computer Name = BRUCE | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 002564F2E213 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 9/15/2010 10:00:42 AM | Computer Name = BRUCE | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 002564F2E213 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 9/15/2010 12:17:50 PM | Computer Name = BRUCE | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 002564F2E213 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 9/15/2010 12:26:34 PM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126
Error - 9/15/2010 12:26:40 PM | Computer Name = BRUCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service HPSLPSVC with
arguments "" in order to run the server: {10DA4F3C-CC99-4190-BE4D-58330754E882}
Error - 9/15/2010 12:26:40 PM | Computer Name = BRUCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service hpqcxs08 with
arguments "" in order to run the server: {1DAEDD8A-30ED-4585-9CF1-13BDF7791DDE}
Error - 9/15/2010 12:26:40 PM | Computer Name = BRUCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 9/15/2010 12:26:40 PM | Computer Name = BRUCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error - 9/15/2010 12:26:40 PM | Computer Name = BRUCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 10/4/2010 8:06:02 AM | Computer Name = BRUCE | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126
< End of report >