This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

internet explorer got a malware virus

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello,

the IE browser won't connect. when it went down i received one of those crappy notices that i have many viruses and must download this malware program i can connect with mozilla firefox though it is just Internet Explorer.

here are the logs in order as requested. thx Yvonne.

OTL

OTL logfile created on: 12/18/2010 3:40:36 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Yvonne\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.28 Gb Total Space | 72.77 Gb Free Space | 52.24% Space Free | Partition Type: NTFS

Computer Name: YVONNE-PC | User Name: Yvonne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Yvonne\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Yvonne\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe (Acer Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
PRC - C:\Program Files\EMACHINES\eMachines Recovery Management\eRecovery\HidChk.exe (Acer Inc.)
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
PRC - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (Hewlett-Packard Co.)


========== Modules (SafeList) ==========

MOD - C:\Users\Yvonne\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
MOD - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\asOEHook.dll (Symantec Corporation)


========== Win32 Services (SafeList) ==========

SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe File not found
SRV - (N360) – C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (LiveUpdate) – c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (ETService) – C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
SRV - (NTIBackupSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (NTISchedulerSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
SRV - (BUNAgentSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (HPWirelessMgr) – C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe (Hewlett-Packard Co.)


========== Driver Services (SafeList) ==========

DRV - (WisINT15) – C:\Windows\System32\OEM\factory\WisINT15.SYS File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20101104.004\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20101107.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20101107.003\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (usbfilter) – C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NTIDrvr) – C:\Windows\System32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (UBHelper) – C:\Windows\System32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (regi) – C:\Windows\System32\drivers\regi.sys (InterVideo)
DRV - (Cdralw2k) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (DKbFltr) – C:\Windows\System32\drivers\DKbFltr.sys (Dritek System Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…0209&m=d620
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…0209&m=d620
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sellit2.us/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 2E DF 04 51 30 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:23012

========== FireFox ==========

FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/04/26 17:04:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/18 13:53:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/18 13:53:28 | 000,000,000 | —D | M]

[2010/12/18 13:53:59 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Mozilla\Extensions
[2009/10/27 17:25:59 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\extensions
[2009/10/27 17:26:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/12/18 13:55:50 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\Profiles\dyc0h9x4.default\extensions
[2010/12/18 13:55:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\Profiles\dyc0h9x4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/18 15:03:27 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BkupTray] C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [cdloader] C:\Users\Yvonne\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [DW6] File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: 401k.com ([www] https in Trusted sites)
O16 - DPF: {01118F00-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/ssrc.cab (SupportSoft RemoteControl Class)
O16 - DPF: {01119400-3E00-11D2-8470-0060089874ED} http://symantec.atgnow.com/sdccommon/download/sprtctlln.cab (SupportSoft Listener Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E0B119-DCF2-4CD6-8DFB-7CFF1B70F7FF} https://bis.na.blackberry.com/html/web/clie…ls/TOImport.cab (TeamOn Import Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Yvonne\Pictures\DSC01386.JPG
O24 - Desktop BackupWallPaper: C:\Users\Yvonne\Pictures\DSC01386.JPG
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{5b931d25-b99f-11de-b36c-001d72f4c07c}\Shell - "" = AutoRun
O33 - MountPoints2\{5b931d25-b99f-11de-b36c-001d72f4c07c}\Shell\AutoRun\command - "" = F:\HPLauncher.exe – File not found
O33 - MountPoints2\{8741a25d-5051-11de-9b34-001d72f4c07c}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{8741a25d-5051-11de-9b34-001d72f4c07c}\Shell\phone\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
O33 - MountPoints2\F\Shell\phone\command - "" = F:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\Windows\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2010/12/18 13:53:45 | 000,000,000 | —D | C] – C:\Users\Yvonne\AppData\Local\Mozilla
[2010/12/18 13:52:49 | 008,582,536 | —- | C] (Mozilla) – C:\Users\Yvonne\Desktop\Firefox Setup 3.6.13.exe
[2010/12/18 12:40:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Picture It! 7
[2010/12/18 11:04:28 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/18 11:04:00 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/18 11:04:00 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/18 11:03:59 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/18 11:03:31 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/18 11:03:04 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/18 11:03:03 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/18 11:03:03 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/18 11:02:37 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/18 11:02:36 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/12/18 11:02:35 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/12/18 11:02:35 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/18 11:02:35 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/18 11:02:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/18 11:02:34 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/18 11:02:34 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/18 11:02:34 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/18 11:02:34 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/18 11:02:34 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/12/18 11:02:34 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/12/18 11:02:34 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/12/18 11:02:34 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/12/18 11:02:34 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/18 11:02:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/18 11:02:34 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/18 11:02:26 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/11/23 07:15:00 | 000,000,000 | —D | C] – C:\b9843d25900296c67329
[2010/11/21 19:47:38 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2010/11/21 19:47:38 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2010/11/21 19:47:38 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/18 15:17:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/18 15:03:56 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/18 15:03:27 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2010/12/18 15:03:19 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/18 15:03:19 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/18 15:03:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/18 15:02:56 | 1877,065,728 | -HS- | M] () – C:\hiberfil.sys
[2010/12/18 14:58:56 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/18 13:53:31 | 000,001,750 | —- | M] () – C:\Users\Yvonne\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/18 13:53:31 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/12/18 13:44:12 | 008,582,536 | —- | M] (Mozilla) – C:\Users\Yvonne\Desktop\Firefox Setup 3.6.13.exe
[2010/12/18 13:06:11 | 000,481,840 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/18 12:39:05 | 000,001,796 | —- | M] () – C:\Users\Yvonne\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN 8.lnk
[2010/12/18 10:55:29 | 000,002,545 | —- | M] () – C:\Users\Yvonne\Desktop\Vz In-Home Agent.lnk
[2010/12/15 10:39:43 | 000,002,633 | —- | M] () – C:\Users\Yvonne\Desktop\Microsoft Office Outlook 2007.lnk
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/23 07:16:48 | 000,602,730 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/23 07:16:47 | 000,104,138 | —- | M] () – C:\Windows\System32\perfc009.dat
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[10 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/18 13:53:31 | 000,001,750 | —- | C] () – C:\Users\Yvonne\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/18 13:53:31 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/12/18 12:39:05 | 000,001,796 | —- | C] () – C:\Users\Yvonne\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN 8.lnk
[2010/11/21 19:38:30 | 1877,065,728 | -HS- | C] () – C:\hiberfil.sys
[2009/12/01 06:53:59 | 000,000,000 | —- | C] () – C:\Users\Yvonne\AppData\Roaming\wklnhst.dat
[2009/11/30 05:44:12 | 000,000,552 | —- | C] () – C:\Users\Yvonne\AppData\Local\d3d8caps.dat
[2009/10/09 17:24:20 | 000,000,071 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SNDUpgrade.log
[2009/09/28 21:30:50 | 000,000,680 | —- | C] () – C:\Users\Yvonne\AppData\Local\d3d9caps.dat
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/21 18:40:53 | 000,017,920 | —- | C] () – C:\Users\Yvonne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/19 15:37:02 | 000,000,026 | —- | C] () – C:\Windows\UPGRADE5.INI
[2009/07/19 14:02:18 | 000,032,768 | —- | C] () – C:\Windows\System32\GexEncryptorCOM.dll
[2009/05/26 15:06:14 | 000,000,045 | —- | C] () – C:\Windows\wininit.ini
[2009/04/22 20:11:38 | 000,000,089 | —- | C] () – C:\Windows\NavWin.INI
[2009/04/22 04:59:52 | 000,118,784 | —- | C] () – C:\Windows\System32\G32_TICK.DLL
[2009/04/22 04:59:52 | 000,081,920 | —- | C] () – C:\Windows\System32\G32_rkey.dll
[2009/03/15 19:17:21 | 000,000,129 | —- | C] () – C:\Users\Yvonne\AppData\Local\fusioncache.dat
[2009/02/25 12:59:04 | 000,159,744 | —- | C] () – C:\Windows\System32\libssl32.dll
[2009/02/22 13:50:27 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2008/11/24 14:23:42 | 000,041,984 | —- | C] () – C:\Windows\System32\ZFExt.dll
[2008/08/27 17:14:28 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2008/08/27 17:14:28 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008/08/27 16:49:15 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/08/27 16:48:57 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/08/14 23:47:01 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/06/28 12:49:23 | 000,000,268 | —- | C] () – C:\Users\Yvonne\AppData\Roaming\LMCPaper.dat
[2008/06/28 12:49:13 | 000,003,932 | —- | C] () – C:\Users\Yvonne\AppData\Roaming\LMLayout.dat
[2008/06/24 11:45:51 | 000,032,768 | —- | C] () – C:\Windows\System32\ktdll.dll
[2007/12/12 12:29:31 | 000,000,864 | —- | C] () – C:\Windows\wsnk.ini
[2007/10/09 13:04:47 | 000,000,165 | —- | C] () – C:\Windows\Quicken.ini
[2006/12/28 13:22:00 | 000,000,214 | —- | C] () – C:\Windows\HP_48BitScanUpdatePatch.ini
[2006/11/27 18:47:29 | 000,000,237 | —- | C] () – C:\Windows\ActiveAct.INI
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/10/11 12:59:37 | 000,001,115 | —- | C] () – C:\Windows\lexstat.ini
[2006/07/12 16:34:04 | 000,004,096 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ScheduledItems
[2006/06/26 18:53:57 | 000,001,786 | -HS- | C] () – C:\Windows\System32\KGyGaAvL.sys
[2006/06/26 18:53:57 | 000,000,056 | RHS- | C] () – C:\Windows\System32\CB5678212A.sys
[2006/06/10 10:49:55 | 000,135,104 | —- | C] () – C:\Windows\Tab16d20.dll
[2006/06/10 10:49:55 | 000,002,702 | —- | C] () – C:\Windows\Ssds32.ini
[2006/06/10 10:49:55 | 000,002,554 | —- | C] () – C:\Windows\SSDS16.INI
[2006/06/10 10:49:55 | 000,002,371 | —- | C] () – C:\Windows\ssnew05.ini
[2006/06/10 10:49:55 | 000,002,371 | —- | C] () – C:\Windows\ssnew04.ini
[2006/06/10 10:49:55 | 000,002,371 | —- | C] () – C:\Windows\ssnew03.ini
[2006/06/10 10:49:55 | 000,002,371 | —- | C] () – C:\Windows\ssnew02.ini
[2006/06/10 10:49:55 | 000,002,371 | —- | C] () – C:\Windows\ssnew01.ini
[2006/06/10 10:49:54 | 000,048,176 | —- | C] () – C:\Windows\Imp16d20.dll
[2006/06/10 10:49:54 | 000,012,800 | —- | C] () – C:\Windows\SS16FT.DLL
[2006/06/10 10:49:54 | 000,002,269 | —- | C] () – C:\Windows\Ssdef32.ini
[2006/06/10 10:49:54 | 000,002,267 | —- | C] () – C:\Windows\SSDEF16.INI
[2006/06/10 10:49:54 | 000,000,029 | —- | C] () – C:\Windows\MyScan.ini
[2006/06/10 10:49:42 | 000,004,256 | —- | C] () – C:\Windows\System32\LMStatus.ini
[2006/05/21 18:58:57 | 000,002,791 | —- | C] () – C:\Windows\wavemix.ini
[2006/05/21 18:58:57 | 000,000,466 | —- | C] () – C:\Windows\METAL.INI
[2006/05/01 16:53:49 | 000,000,206 | —- | C] () – C:\Windows\HPGdiPlus.ini
[2005/12/31 18:09:23 | 000,000,635 | —- | C] () – C:\Windows\Sta2.INI
[2005/12/04 18:23:43 | 000,000,712 | —- | C] () – C:\Windows\SIERRA.INI
[2005/09/01 07:03:56 | 000,000,063 | —- | C] () – C:\Windows\mdm.ini
[2005/05/04 14:31:36 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2005/03/29 00:58:20 | 000,159,744 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2005/03/29 00:58:10 | 000,847,872 | —- | C] () – C:\Windows\System32\libeay32.dll
[2004/07/27 09:41:42 | 000,000,620 | —- | C] () – C:\Program Files\Shortcut to TaxEstimator35.lnk
[2004/05/19 15:03:02 | 000,000,019 | —- | C] () – C:\Windows\vaLangChoice.ini
[2004/05/19 15:01:41 | 000,000,150 | —- | C] () – C:\Windows\System32\LM_SUPPORT.INI
[2004/03/29 16:44:19 | 000,019,968 | —- | C] () – C:\Windows\System32\Cpuinf32.dll
[2004/02/26 10:02:02 | 000,040,960 | —- | C] () – C:\Windows\System32\bCastRingSvr.dll
[2004/02/17 17:31:04 | 000,000,014 | —- | C] () – C:\Windows\pagesuit.ini
[2004/01/11 15:37:05 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2003/10/28 11:46:02 | 000,139,776 | —- | C] () – C:\Windows\System32\UserEdit.dll
[2003/09/22 23:48:43 | 000,077,824 | —- | C] () – C:\Windows\System32\LXBFLCNP.DLL
[2003/09/04 12:38:10 | 000,006,890 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2003/09/04 12:24:35 | 000,077,824 | —- | C] () – C:\Windows\System32\SynTPCoI.dll
[2003/09/04 12:19:17 | 000,000,750 | —- | C] () – C:\Windows\orun32.ini
[2003/04/25 09:10:00 | 000,536,576 | —- | C] () – C:\Windows\System32\Tx32.dll
[2003/04/16 02:02:00 | 000,000,478 | —- | C] () – C:\Windows\System32\ic32.ini
[2003/03/13 10:15:26 | 000,029,184 | —- | C] () – C:\Windows\System32\tdsExSvr.dll
[2002/11/13 13:40:22 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbfvs.dll
[2002/09/09 09:15:50 | 000,000,061 | —- | C] () – C:\Windows\smscfg.ini
[2002/09/09 08:49:10 | 000,004,161 | —- | C] () – C:\Windows\ODBCINST.INI
[2002/09/04 12:42:38 | 000,000,188 | —- | C] () – C:\Windows\System32\lxbfcoin.ini
[2002/03/18 16:23:40 | 000,040,960 | —- | C] () – C:\Windows\System32\TunnelThruDll.dll
[2001/12/26 17:12:30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 00:46:38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 17:33:56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 23:04:36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll
[2000/04/12 15:28:12 | 000,118,784 | —- | C] () – C:\Windows\System32\lfkodak.dll
[2000/04/12 15:24:10 | 000,338,944 | —- | C] () – C:\Windows\System32\lffpx7.dll
[1998/03/26 00:12:00 | 000,053,248 | —- | C] () – C:\Windows\System32\Zlib.dll

========== LOP Check ==========

[2010/03/14 16:22:15 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Blackberry Desktop
[2009/05/26 22:35:52 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Centra
[2009/12/31 19:54:54 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/05/26 22:35:58 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\CrystalButton
[2009/05/26 19:19:20 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\GetRightToGo
[2009/05/26 22:35:58 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\gtk-2.0
[2009/05/26 22:35:58 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\InterTrust
[2009/11/01 08:50:35 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\InterVideo
[2009/12/01 13:29:42 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\mjusbsp
[2010/03/14 16:15:55 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Research In Motion
[2009/05/26 22:36:39 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Saba
[2009/05/26 18:47:50 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Spearit
[2009/12/01 06:54:11 | 000,000,000 | —D | M] – C:\Users\Yvonne\AppData\Roaming\Template
[2010/12/18 15:01:57 | 000,032,566 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/01/13 21:50:58 | 000,235,008 | —- | M] () – C:\#266 dept. mkdwn tracks.xls
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 20:34:29 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2008/08/27 16:52:01 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2005/01/16 12:37:48 | 000,045,485 | —- | M] () – C:\DSC00003.JPG
[2010/12/18 15:02:56 | 1877,065,728 | -HS- | M] () – C:\hiberfil.sys
[2004/02/16 16:07:50 | 000,000,519 | —- | M] () – C:\hpfr3420.xml
[2004/02/16 16:07:50 | 000,016,666 | —- | M] () – C:\hpfr3425.log
[2004/09/14 11:00:39 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2007/11/10 12:35:41 | 000,000,134 | —- | M] () – C:\inferno.log
[2009/12/29 17:04:28 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/12/21 14:11:00 | 000,003,746 | —- | M] () – C:\jetscan.log
[2010/05/31 12:11:09 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/12/29 17:04:28 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/30 08:34:58 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/21 08:54:56 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/18 15:02:53 | 2190,864,384 | -HS- | M] () – C:\pagefile.sys
[2008/08/27 16:50:14 | 000,000,426 | —- | M] () – C:\RHDSetup.log
[2008/06/24 06:44:23 | 000,000,136 | —- | M] () – C:\SerialSync.txt
[2004/01/11 17:10:32 | 000,000,199 | —- | M] () – C:\setup.log
[2004/01/11 17:10:18 | 000,000,851 | —- | M] () – C:\tempbmm.iss
[2009/02/22 13:55:11 | 000,386,460 | —- | M] () – C:\vcredist_x86.log

< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/05/26 19:55:53 | 000,000,113 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 03:46:03 | 000,070,144 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNBPP3.DLL
[2009/03/17 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2009/03/17 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2006/12/29 08:57:18 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2002/07/11 13:33:14 | 000,176,128 | —- | M] (DeviceGuys) – C:\Windows\System32\spool\prtprocs\w32x86\LMPriNT.dll
[2003/07/21 08:13:34 | 000,078,336 | —- | M] () – C:\Windows\System32\spool\prtprocs\w32x86\LXBFPP5C.DLL
[2003/01/16 18:37:14 | 000,011,264 | —- | M] (BVRP Software) – C:\Windows\System32\spool\prtprocs\w32x86\lxprint2000.dll
[2004/03/22 15:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2009/05/26 21:07:36 | 000,000,620 | —- | M] () – C:\Program Files\Shortcut to TaxEstimator35.lnk

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/16 18:01:44 | 000,000,650 | -HS- | M] () – C:\Users\Yvonne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2002/09/09 08:57:36 | 000,000,079 | —- | M] () – C:\Users\Yvonne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/12/18 13:44:12 | 008,582,536 | —- | M] (Mozilla) – C:\Users\Yvonne\Desktop\Firefox Setup 3.6.13.exe
[2009/03/18 19:53:12 | 007,941,896 | —- | M] ( ) – C:\Users\Yvonne\Desktop\gimp-2.2.17-i586-setup.exe
[2009/03/18 18:34:19 | 020,712,368 | —- | M] ( ) – C:\Users\Yvonne\Desktop\gimp-2.7.0-r28070-i686-setup.exe
[2009/12/29 15:20:19 | 017,835,800 | —- | M] (Intuit ) – C:\Users\Yvonne\Desktop\QW08R9Patch.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2005/06/16 14:15:44 | 000,336,896 | —- | M] (Expertcity) – C:\Windows\java\remote.exe

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-18 18:30:18

< Update\Results\Install|LastSuccessTime /rs >

< End of report >


OTL #2

OTL Extras logfile created on: 12/18/2010 3:40:36 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Yvonne\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.28 Gb Total Space | 72.77 Gb Free Space | 52.24% Space Free | Partition Type: NTFS

Computer Name: YVONNE-PC | User Name: Yvonne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A7A8726F-E819-4119-81FD-BE7DDF22C511}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{B56DB884-DE05-48A1-A155-39A897039281}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FBB1CF20-DC3C-4B7F-8038-31DD00889B0C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0DB68C68-A2B9-48E0-AFD5-4A3ADB9281FE}" = protocol=17 | dir=in | app=c:\users\yvonne\appdata\roaming\mjusbsp\magicjack.exe |
"{172F9ECB-8E6C-40AB-B685-1498EEB88EDD}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{17B898DD-5C65-41F9-B9A6-9E3770546C56}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{3DA27CAA-81BC-4AD8-B788-C032D1C808F5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{45F7A748-2251-429F-92DF-B2AF70BE8281}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60533F90-DB5C-4C2A-8B49-C1E6239E5C60}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{6AB12C0F-7296-4904-82A8-F7DBB734FE06}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{6FF7E1B5-5BC6-4834-BF7F-324FEB7EA417}" = protocol=6 | dir=in | app=c:\users\yvonne\appdata\roaming\mjusbsp\magicjack.exe |
"{948EB7ED-60C2-4F4F-8FC7-E15E70386E34}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{966F0BB0-3966-4CDE-B31E-85E97BA5ACBA}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{C1DAA8F0-48F6-4107-9D38-27953ED7E840}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{ECFFA4EE-B164-46BD-934A-9D176F67AED5}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000000-3976-4267-9F39-1DC4745090B7}" = Microsoft Learning and Research Plus Support Files
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08715547-A3E5-D54A-C7C3-84348C0624EE}" = Catalyst Control Center Localization Portuguese
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B473FE5-A37A-FAEC-375A-DF7FACB974C2}" = Catalyst Control Center Localization Swedish
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{11F681FC-9FE2-4958-AE24-FF9E3450E4DD}" = RTM
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{141F2872-D2F9-4A89-95D3-E222D1CBCC56}" = Vz In Home Agent
"{169E24D1-2972-4B51-AC47-D5BDEC93F453}" = PCmover
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1985865F-013F-E7E0-64C1-D426A0AE2C8E}" = CCC Help Czech
"{1D25EB8B-61CD-2936-D6F6-596C9278F2F0}" = Catalyst Control Center InstallProxy
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1EB321CB-3D1D-4cf2-ACB5-9F20874B8E69}" = HP Officejet Pro All-In-One Series
"{1F7D7D0A-5696-F1AA-8967-C780DA8C3536}" = Catalyst Control Center Localization Chinese Traditional
"{1FCF767C-2B53-442D-965D-A1248F4499EB}" = SafeGuard
"{20385C16-2E18-7874-A4F6-68D0B14CFD2D}" = Catalyst Control Center Graphics Light
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{223CADD2-5E02-350D-C7D9-1092D38CF049}" = CCC Help Dutch
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24261D9F-6057-447A-B55D-F0A1B195C91D}" = Extreme Charts and Simutrade Manager
"{25EF00BE-F17B-11D6-88EA-000476CD2443}" = Verizon Online
"{26346FB6-4F69-453D-95CE-B6BA3A5382F8}" = Broderbund Media Manager
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{27E957E9-D6DF-1C12-EA88-81DDA54508FB}" = Catalyst Control Center Localization Italian
"{27FB1657-2F26-955B-34D3-381323E159B6}" = Catalyst Control Center Graphics Full Existing
"{2893110C-5623-20C0-4D99-4F717F16FC81}" = Catalyst Control Center Graphics Full New
"{29BC0BC3-CCC0-39C5-21F9-F17230F1F4F3}" = ccc-core-static
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2B9FEAEC-EB33-99FE-B582-33A45D272F03}" = Catalyst Control Center Localization Russian
"{2D8E1E31-5B41-11C8-C88C-E69106AA5EC1}" = CCC Help Spanish
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{2E9A0D49-B758-638C-3639-896041E683F8}" = Catalyst Control Center Localization Finnish
"{31BAC22A-0717-F8CE-FC67-F74B57C71460}" = CCC Help German
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{369B36BE-3D64-4641-9AEA-808D436FE130}" = Microsoft Picture It! Express 7.0
"{384A95F1-EDDA-4BBE-BC6B-7FAA886380F6}" = Trade Navigator
"{3A2CC72F-DDE4-A81E-475D-DA286113652C}" = Catalyst Control Center Graphics Previews Vista
"{3AC21843-7DB1-8BF6-88AC-330BC2B7DA8E}" = CCC Help Japanese
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{44454932-7EE9-2903-549F-45CFF97D2B82}" = CCC Help Korean
"{44D077C3-A31F-CD46-499B-7BF1D8B2C4ED}" = CCC Help Thai
"{463E4C5C-77EE-EBD6-7798-5FB2DB3DA5CC}" = CCC Help Danish
"{47A0A904-290D-315F-F90D-8CCDA69B18F9}" = Catalyst Control Center Localization Polish
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{513BA0B0-248A-A705-89EF-866C4D3B86A7}" = Catalyst Control Center Localization Turkish
"{51F95BEE-66CB-4241-9150-7995D274EC41}" = eNeighborhoods
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{608E2E77-C78D-072A-28E2-71E62BF54592}" = Catalyst Control Center Localization Dutch
"{6251545D-5058-CB7F-D93A-F87A192A4378}" = CCC Help Portuguese
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{6A0BE0CF-B901-4C81-B308-6C08B393C2AC}" = Catalyst Control Center Localization Hungarian
"{6B64C9D6-EEBA-4712-8477-69D6C55ADD6F}" = L7700
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FC25653-65CC-0B75-1C14-676342A15259}" = Catalyst Control Center Localization Chinese Standard
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73706EE4-90E4-A65B-40BD-86672156A626}" = Skins
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7766AA5D-3DB1-A633-92A2-0CA13E2568DD}" = CCC Help French
"{78386976-46A3-F5C3-36B4-98280F3B81E7}" = CCC Help Turkish
"{796F53F9-A098-3ED2-A4FC-E1C24430A243}" = Catalyst Control Center Localization Japanese
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7ECB1FE2-408E-D314-D812-0FC3FA048C61}" = CCC Help Hungarian
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{7F9ADEE3-E5E0-34A5-345A-590BC90D4E33}" = CCC Help Italian
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81E55AB8-83FC-C7D7-F599-B8C9AA9BD207}" = CCC Help Russian
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11019760}" = eMachines
"{873D68B3-EDE5-4DFD-85AC-FFC430FB7EE2}" = Form Viewer
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{88739060-F683-11D3-B761-00105AD153C1}" = Lexmark X125
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CE5A7A2-BC80-EFD3-6489-E92A2BCB1BF2}" = ccc-utility
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOKR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOKR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOKR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOKR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOKR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOKR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2DB513F-A9AA-D30F-B00D-B6C3056F5608}" = Catalyst Control Center Localization Norwegian
"{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A68341CE-7AB6-3984-420A-D197E6BB72E7}" = CCC Help Greek
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{A8F2DCDE-AE4E-4AC9-BECD-496FB80FBF6A}" = Notebook Utilities
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5AC297-3F0D-11D5-AD7D-00A0CCE88B12}" = Mark-It Advantage Xi
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADF34BD2-879C-63EA-1C7E-2F2CDA9E5950}" = CCC Help Chinese Standard
"{AEEDFE42-D580-54D6-6947-E805FD5CECCB}" = CCC Help English
"{AF18FA75-1239-B316-AED9-08151CB34737}" = Catalyst Control Center Localization Korean
"{AF7AA100-3160-480B-DB62-BABE42A6B618}" = CCC Help Norwegian
"{B0C037F9-7BD7-6417-6ADF-A08EEC011AF0}" = CCC Help Swedish
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{BD7D29B1-903C-45DB-2685-C154C17FDDA5}" = ATI Catalyst Install Manager
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BF7AB326-92C8-C250-5B99-0DB96A2634D9}" = Catalyst Control Center Localization Greek
"{C17F7063-4BBC-EC05-4312-7F33DA5641E0}" = Catalyst Control Center Localization Spanish
"{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery
"{C46B4678-0F42-4791-9D19-BE01BB3DD358}" = Roxio Easy DVD Copy
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C95159F2-6A71-C74D-855A-22943F1016C3}" = Catalyst Control Center Localization French
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D1D8C9C4-89BE-4f37-9EC4-B80E3C239C41}" = Copy
"{D513B90E-92C9-2A48-044C-6F6264E5AF6A}" = Catalyst Control Center Core Implementation
"{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E4ABB302-9D82-4D18-83D5-AD1DFE786AA8}" = Unload
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B4B94E-AFE8-3635-857A-8AE7F90E9DDD}" = Catalyst Control Center Localization Thai
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{E863E701-B897-C5BC-5F9B-5F3E7484E81C}" = CCC Help Finnish
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4D0FC65-E6D0-0AC3-F87B-06BF11435DE0}" = Catalyst Control Center Localization Czech
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F719C40B-FDE9-402B-8F9C-2D47517DC813}" = Catalyst Control Center Localization German
"{F9015FF1-09EB-4A43-8E69-0136F890C656}" = CCC Help Chinese Traditional
"{FB26EA24-AE01-4C86-BEBC-424D5B81E66E}" = The Print Shop
"{FC67D87A-ABDB-69BE-2988-3CDCCD84B211}" = Catalyst Control Center Localization Danish
"{FDCCB6E0-73E8-11D5-9249-0001022E75DF}_1" = WyldFyre 7 Installed in: C:\PROGRAM FILES\WYLDFYRE\WYLDFYRE 7
"{FDD357D8-A4EB-1DBB-1CB2-74E9F259817B}" = CCC Help Polish
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Ask Toolbar
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CentraClient" = Centra Client
"CentraOneClient" = CentraOne
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CompuCram Texas Real Estate Salesperson" = CompuCram Texas Real Estate Salesperson
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Lexmark X6100 Series" = Lexmark X6100 Series
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNMS" = MSN Internet Software
"N360" = Norton 360 Premier Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OUTLOOKR" = Microsoft Office Outlook 2007
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"Shockwave" = Shockwave
"ST4UNST #1" = FinancialCalculator
"ST6UNST #2" = TaxEstimator353
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Verizon Help and Support" = Verizon Help and Support Tool
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.5
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZipForm Desktop" = ZipForm Desktop

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.0.0.320

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:33 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:33 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ OSession Events ]
Error - 10/7/2009 9:31:13 PM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/31/2010 6:45:06 PM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 70
seconds with 60 seconds of active time. This session ended with a crash.

Error - 3/15/2010 9:51:18 AM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Fax Lexmark X6100 Series because
the print processor lxPrint2000 could not be found. Please obtain and install a
new version of the driver from the manufacturer (if available), or choose an alternate
driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Fax Lexmark X6100 Series failed to initialize because a suitable
CAPTURE FAX driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer HP LaserJet 5 failed to initialize because a suitable HP LaserJet
5 driver could not be found. The new printer settings that you specified have not
taken effect. Install or reinstall the printer driver. You might need to contact
the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer HP LaserJet 5 (Copy 1) failed to initialize because a suitable
HP LaserJet 5 driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Lexmark X125 because the print
processor LMPriNT could not be found. Please obtain and install a new version of
the driver from the manufacturer (if available), or choose an alternate driver
that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Lexmark X125 failed to initialize because a suitable Lexmark
X125 driver could not be found. The new printer settings that you specified have
not taken effect. Install or reinstall the printer driver. You might need to contact
the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Lexmark X6100 Series because
the print processor Lexmark X6100 Series Print Processor could not be found. Please
obtain and install a new version of the driver from the manufacturer (if available),
or choose an alternate driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Lexmark X6100 Series failed to initialize because a suitable
Lexmark X6100 Series driver could not be found. The new printer settings that you
specified have not taken effect. Install or reinstall the printer driver. You might
need to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Microsoft Office Document Image
Writer because the print processor ModiPrint could not be found. Please obtain
and install a new version of the driver from the manufacturer (if available), or
choose an alternate driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Microsoft Office Document Image Writer failed to initialize
because a suitable Microsoft Office Document Image Writer Driver driver could not
be found. The new printer settings that you specified have not taken effect. Install
or reinstall the printer driver. You might need to contact the vendor for an updated
driver.


< End of report >

hijack this

OTL Extras logfile created on: 12/18/2010 3:40:36 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Yvonne\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.28 Gb Total Space | 72.77 Gb Free Space | 52.24% Space Free | Partition Type: NTFS

Computer Name: YVONNE-PC | User Name: Yvonne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{A7A8726F-E819-4119-81FD-BE7DDF22C511}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{B56DB884-DE05-48A1-A155-39A897039281}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FBB1CF20-DC3C-4B7F-8038-31DD00889B0C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0DB68C68-A2B9-48E0-AFD5-4A3ADB9281FE}" = protocol=17 | dir=in | app=c:\users\yvonne\appdata\roaming\mjusbsp\magicjack.exe |
"{172F9ECB-8E6C-40AB-B685-1498EEB88EDD}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{17B898DD-5C65-41F9-B9A6-9E3770546C56}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{3DA27CAA-81BC-4AD8-B788-C032D1C808F5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{45F7A748-2251-429F-92DF-B2AF70BE8281}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60533F90-DB5C-4C2A-8B49-C1E6239E5C60}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{6AB12C0F-7296-4904-82A8-F7DBB734FE06}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{6FF7E1B5-5BC6-4834-BF7F-324FEB7EA417}" = protocol=6 | dir=in | app=c:\users\yvonne\appdata\roaming\mjusbsp\magicjack.exe |
"{948EB7ED-60C2-4F4F-8FC7-E15E70386E34}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{966F0BB0-3966-4CDE-B31E-85E97BA5ACBA}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{C1DAA8F0-48F6-4107-9D38-27953ED7E840}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{ECFFA4EE-B164-46BD-934A-9D176F67AED5}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000000-3976-4267-9F39-1DC4745090B7}" = Microsoft Learning and Research Plus Support Files
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08715547-A3E5-D54A-C7C3-84348C0624EE}" = Catalyst Control Center Localization Portuguese
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B473FE5-A37A-FAEC-375A-DF7FACB974C2}" = Catalyst Control Center Localization Swedish
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{11F681FC-9FE2-4958-AE24-FF9E3450E4DD}" = RTM
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{141F2872-D2F9-4A89-95D3-E222D1CBCC56}" = Vz In Home Agent
"{169E24D1-2972-4B51-AC47-D5BDEC93F453}" = PCmover
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1985865F-013F-E7E0-64C1-D426A0AE2C8E}" = CCC Help Czech
"{1D25EB8B-61CD-2936-D6F6-596C9278F2F0}" = Catalyst Control Center InstallProxy
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1EB321CB-3D1D-4cf2-ACB5-9F20874B8E69}" = HP Officejet Pro All-In-One Series
"{1F7D7D0A-5696-F1AA-8967-C780DA8C3536}" = Catalyst Control Center Localization Chinese Traditional
"{1FCF767C-2B53-442D-965D-A1248F4499EB}" = SafeGuard
"{20385C16-2E18-7874-A4F6-68D0B14CFD2D}" = Catalyst Control Center Graphics Light
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{223CADD2-5E02-350D-C7D9-1092D38CF049}" = CCC Help Dutch
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24261D9F-6057-447A-B55D-F0A1B195C91D}" = Extreme Charts and Simutrade Manager
"{25EF00BE-F17B-11D6-88EA-000476CD2443}" = Verizon Online
"{26346FB6-4F69-453D-95CE-B6BA3A5382F8}" = Broderbund Media Manager
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{27E957E9-D6DF-1C12-EA88-81DDA54508FB}" = Catalyst Control Center Localization Italian
"{27FB1657-2F26-955B-34D3-381323E159B6}" = Catalyst Control Center Graphics Full Existing
"{2893110C-5623-20C0-4D99-4F717F16FC81}" = Catalyst Control Center Graphics Full New
"{29BC0BC3-CCC0-39C5-21F9-F17230F1F4F3}" = ccc-core-static
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2B9FEAEC-EB33-99FE-B582-33A45D272F03}" = Catalyst Control Center Localization Russian
"{2D8E1E31-5B41-11C8-C88C-E69106AA5EC1}" = CCC Help Spanish
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{2E9A0D49-B758-638C-3639-896041E683F8}" = Catalyst Control Center Localization Finnish
"{31BAC22A-0717-F8CE-FC67-F74B57C71460}" = CCC Help German
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{369B36BE-3D64-4641-9AEA-808D436FE130}" = Microsoft Picture It! Express 7.0
"{384A95F1-EDDA-4BBE-BC6B-7FAA886380F6}" = Trade Navigator
"{3A2CC72F-DDE4-A81E-475D-DA286113652C}" = Catalyst Control Center Graphics Previews Vista
"{3AC21843-7DB1-8BF6-88AC-330BC2B7DA8E}" = CCC Help Japanese
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{44454932-7EE9-2903-549F-45CFF97D2B82}" = CCC Help Korean
"{44D077C3-A31F-CD46-499B-7BF1D8B2C4ED}" = CCC Help Thai
"{463E4C5C-77EE-EBD6-7798-5FB2DB3DA5CC}" = CCC Help Danish
"{47A0A904-290D-315F-F90D-8CCDA69B18F9}" = Catalyst Control Center Localization Polish
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{513BA0B0-248A-A705-89EF-866C4D3B86A7}" = Catalyst Control Center Localization Turkish
"{51F95BEE-66CB-4241-9150-7995D274EC41}" = eNeighborhoods
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{608E2E77-C78D-072A-28E2-71E62BF54592}" = Catalyst Control Center Localization Dutch
"{6251545D-5058-CB7F-D93A-F87A192A4378}" = CCC Help Portuguese
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{6A0BE0CF-B901-4C81-B308-6C08B393C2AC}" = Catalyst Control Center Localization Hungarian
"{6B64C9D6-EEBA-4712-8477-69D6C55ADD6F}" = L7700
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FC25653-65CC-0B75-1C14-676342A15259}" = Catalyst Control Center Localization Chinese Standard
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73706EE4-90E4-A65B-40BD-86672156A626}" = Skins
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7766AA5D-3DB1-A633-92A2-0CA13E2568DD}" = CCC Help French
"{78386976-46A3-F5C3-36B4-98280F3B81E7}" = CCC Help Turkish
"{796F53F9-A098-3ED2-A4FC-E1C24430A243}" = Catalyst Control Center Localization Japanese
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7ECB1FE2-408E-D314-D812-0FC3FA048C61}" = CCC Help Hungarian
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{7F9ADEE3-E5E0-34A5-345A-590BC90D4E33}" = CCC Help Italian
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81E55AB8-83FC-C7D7-F599-B8C9AA9BD207}" = CCC Help Russian
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11019760}" = eMachines
"{873D68B3-EDE5-4DFD-85AC-FFC430FB7EE2}" = Form Viewer
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{88739060-F683-11D3-B761-00105AD153C1}" = Lexmark X125
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CE5A7A2-BC80-EFD3-6489-E92A2BCB1BF2}" = ccc-utility
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOKR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOKR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOKR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOKR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOKR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOKR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2DB513F-A9AA-D30F-B00D-B6C3056F5608}" = Catalyst Control Center Localization Norwegian
"{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A68341CE-7AB6-3984-420A-D197E6BB72E7}" = CCC Help Greek
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{A8F2DCDE-AE4E-4AC9-BECD-496FB80FBF6A}" = Notebook Utilities
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5AC297-3F0D-11D5-AD7D-00A0CCE88B12}" = Mark-It Advantage Xi
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADF34BD2-879C-63EA-1C7E-2F2CDA9E5950}" = CCC Help Chinese Standard
"{AEEDFE42-D580-54D6-6947-E805FD5CECCB}" = CCC Help English
"{AF18FA75-1239-B316-AED9-08151CB34737}" = Catalyst Control Center Localization Korean
"{AF7AA100-3160-480B-DB62-BABE42A6B618}" = CCC Help Norwegian
"{B0C037F9-7BD7-6417-6ADF-A08EEC011AF0}" = CCC Help Swedish
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{BD7D29B1-903C-45DB-2685-C154C17FDDA5}" = ATI Catalyst Install Manager
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BF7AB326-92C8-C250-5B99-0DB96A2634D9}" = Catalyst Control Center Localization Greek
"{C17F7063-4BBC-EC05-4312-7F33DA5641E0}" = Catalyst Control Center Localization Spanish
"{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery
"{C46B4678-0F42-4791-9D19-BE01BB3DD358}" = Roxio Easy DVD Copy
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C95159F2-6A71-C74D-855A-22943F1016C3}" = Catalyst Control Center Localization French
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D1D8C9C4-89BE-4f37-9EC4-B80E3C239C41}" = Copy
"{D513B90E-92C9-2A48-044C-6F6264E5AF6A}" = Catalyst Control Center Core Implementation
"{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E4ABB302-9D82-4D18-83D5-AD1DFE786AA8}" = Unload
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B4B94E-AFE8-3635-857A-8AE7F90E9DDD}" = Catalyst Control Center Localization Thai
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{E863E701-B897-C5BC-5F9B-5F3E7484E81C}" = CCC Help Finnish
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4D0FC65-E6D0-0AC3-F87B-06BF11435DE0}" = Catalyst Control Center Localization Czech
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F719C40B-FDE9-402B-8F9C-2D47517DC813}" = Catalyst Control Center Localization German
"{F9015FF1-09EB-4A43-8E69-0136F890C656}" = CCC Help Chinese Traditional
"{FB26EA24-AE01-4C86-BEBC-424D5B81E66E}" = The Print Shop
"{FC67D87A-ABDB-69BE-2988-3CDCCD84B211}" = Catalyst Control Center Localization Danish
"{FDCCB6E0-73E8-11D5-9249-0001022E75DF}_1" = WyldFyre 7 Installed in: C:\PROGRAM FILES\WYLDFYRE\WYLDFYRE 7
"{FDD357D8-A4EB-1DBB-1CB2-74E9F259817B}" = CCC Help Polish
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Ask Toolbar
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CentraClient" = Centra Client
"CentraOneClient" = CentraOne
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CompuCram Texas Real Estate Salesperson" = CompuCram Texas Real Estate Salesperson
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Lexmark X6100 Series" = Lexmark X6100 Series
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNMS" = MSN Internet Software
"N360" = Norton 360 Premier Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OUTLOOKR" = Microsoft Office Outlook 2007
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"Shockwave" = Shockwave
"ST4UNST #1" = FinancialCalculator
"ST6UNST #2" = TaxEstimator353
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Verizon Help and Support" = Verizon Help and Support Tool
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.5
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZipForm Desktop" = ZipForm Desktop

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.0.0.320

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:32 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:33 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:40:33 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/21/2010 9:51:19 PM | Computer Name = Yvonne-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ OSession Events ]
Error - 10/7/2009 9:31:13 PM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/31/2010 6:45:06 PM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 70
seconds with 60 seconds of active time. This session ended with a crash.

Error - 3/15/2010 9:51:18 AM | Computer Name = Yvonne-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Fax Lexmark X6100 Series because
the print processor lxPrint2000 could not be found. Please obtain and install a
new version of the driver from the manufacturer (if available), or choose an alternate
driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Fax Lexmark X6100 Series failed to initialize because a suitable
CAPTURE FAX driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer HP LaserJet 5 failed to initialize because a suitable HP LaserJet
5 driver could not be found. The new printer settings that you specified have not
taken effect. Install or reinstall the printer driver. You might need to contact
the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer HP LaserJet 5 (Copy 1) failed to initialize because a suitable
HP LaserJet 5 driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Lexmark X125 because the print
processor LMPriNT could not be found. Please obtain and install a new version of
the driver from the manufacturer (if available), or choose an alternate driver
that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Lexmark X125 failed to initialize because a suitable Lexmark
X125 driver could not be found. The new printer settings that you specified have
not taken effect. Install or reinstall the printer driver. You might need to contact
the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Lexmark X6100 Series because
the print processor Lexmark X6100 Series Print Processor could not be found. Please
obtain and install a new version of the driver from the manufacturer (if available),
or choose an alternate driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Lexmark X6100 Series failed to initialize because a suitable
Lexmark X6100 Series driver could not be found. The new printer settings that you
specified have not taken effect. Install or reinstall the printer driver. You might
need to contact the vendor for an updated driver.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 72
Description = Windows could not initialize printer Microsoft Office Document Image
Writer because the print processor ModiPrint could not be found. Please obtain
and install a new version of the driver from the manufacturer (if available), or
choose an alternate driver that works with this print device.

Error - 11/17/2009 1:44:00 PM | Computer Name = Yvonne-PC | Source = Print | ID = 23
Description = Printer Microsoft Office Document Image Writer failed to initialize
because a suitable Microsoft Office Document Image Writer Driver driver could not
be found. The new printer settings that you specified have not taken effect. Install
or reinstall the printer driver. You might need to contact the vendor for an updated
driver.


< End of report >


DDS text

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:02:02.77 on Sat 12/18/2010
Internet Explorer: 8.0.6001.18999

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.sellit2.us/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=2&o=vb32&d=0209&m=d620
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=2&o=vb32&d=0209&m=d620
uInternet Settings,ProxyServer = http=127.0.0.1:23012
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360 premier edition\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360 premier edition\engine\3.8.0.41\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360 premier edition\engine\3.8.0.41\coIEPlg.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [cdloader] "c:\users\yvonne\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [DW6]
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [eRecoveryService]
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: 401k.com\www
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {01118F00-3E00-11D2-8470-0060089874ED} - hxxp://symantec.atgnow.com/sdccommon/download/ssrc.cab
DPF: {01119400-3E00-11D2-8470-0060089874ED} - hxxp://symantec.atgnow.com/sdccommon/download/sprtctlln.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxp://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D6E0B119-DCF2-4CD6-8DFB-7CFF1B70F7FF} - hxxps://bis.na.blackberry.com/html/web/client_tools/TOImport.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360 premier edition\engine\3.8.0.41\CoIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\yvonne\appdata\roaming\mozilla\firefox\profiles\dyc0h9x4.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2010-12-18 14:58 709,456 a——- c:\windows\isRS-000.tmp
2010-12-18 12:40 –d—– c:\program files\Microsoft Picture It! 7
2010-12-18 11:04 2,037,248 a——- c:\windows\system32\win32k.sys
2010-12-18 11:04 603,648 a——- c:\windows\system32\schedsvc.dll
2010-12-18 11:04 357,376 a——- c:\windows\system32\taskschd.dll
2010-12-18 11:04 345,088 a——- c:\windows\system32\wmicmiplugin.dll
2010-12-18 11:03 270,336 a——- c:\windows\system32\taskcomp.dll
2010-12-18 11:03 171,520 a——- c:\windows\system32\taskeng.exe
2010-12-18 11:03 81,920 a——- c:\windows\system32\consent.exe
2010-12-18 11:03 292,352 a——- c:\windows\system32\atmfd.dll
2010-12-18 11:03 72,704 a——- c:\windows\system32\fontsub.dll
2010-12-18 11:03 34,304 a——- c:\windows\system32\atmlib.dll
2010-11-23 07:15 –d—– C:\b9843d25900296c67329
2010-11-21 19:47 1,130,824 a——- c:\windows\system32\dfshim.dll
2010-11-21 19:47 297,808 a——- c:\windows\system32\mscoree.dll
2010-11-21 19:47 295,264 a——- c:\windows\system32\PresentationHost.exe
2010-11-21 19:47 99,176 a——- c:\windows\system32\PresentationHostProxy.dll
2010-11-21 19:47 49,472 a——- c:\windows\system32\netfxperf.dll

==================== Find3M ====================

2010-11-29 17:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 17:42 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-11-02 00:01 916,480 a——- c:\windows\system32\wininet.dll
2010-11-01 23:57 43,520 a——- c:\windows\system32\licmgr10.dll
2010-11-01 23:57 109,056 a——- c:\windows\system32\iesysprep.dll
2010-11-01 23:57 71,680 a——- c:\windows\system32\iesetup.dll
2010-11-01 22:26 133,632 a——- c:\windows\system32\ieUnatt.exe
2010-10-28 06:56 2,048 a——- c:\windows\system32\tzres.dll
2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe
2010-09-20 03:25 231,936 a——- c:\windows\system32\msshsq.dll
2010-03-15 09:11 86,016 a——- c:\windows\inf\infstrng.dat
2010-03-15 09:11 51,200 a——- c:\windows\inf\infpub.dat
2010-03-15 09:11 86,016 a——- c:\windows\inf\infstor.dat
2009-12-01 06:53 0 a——- c:\users\yvonne\appdata\roaming\wklnhst.dat
2009-05-26 21:07 620 a——- c:\program files\Shortcut to TaxEstimator35.lnk
2009-05-19 07:35 3,932 a——- c:\users\yvonne\appdata\roaming\LMLayout.dat
2009-05-19 07:35 268 a——- c:\users\yvonne\appdata\roaming\LMCPaper.dat
2009-03-18 18:54 60,744 a——- c:\users\yvonne\g2mdlhlpx.exe
2008-08-27 16:45 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-20 20:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2010-07-16 07:24 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-07-16 07:24 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-07-16 07:24 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2006-07-26 18:37 56 a–shr– c:\windows\system32\CB5678212A.sys
2006-11-01 09:11 1,786 a–sh— c:\windows\system32\KGyGaAvL.sys

============= FINISH: 16:02:44.82 ===============
Hello Yvonne and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Any underlined text in my posts indicates a clickable link.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • GMER log
ok… tried to use the GMER rootscanner. the 1st time i got this windows error msg after it told me the program has stopped for the following reason
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.768.2
Locale ID: 1033

Additional information about the problem:
BCCode: c2
BCP1: 00000007
BCP2: 0000110B
BCP3: 00000000
BCP4: C00000B5
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\Mini123110-02.dmp
C:\Users\Yvonne\AppData\Local\Temp\WER-70465-0.sysdata.xml
C:\Users\Yvonne\AppData\Local\Temp\WER5F6D.tmp.version.txt

Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=501…mp;clcid=0x0409

then i shut off the norton and unchecked the "file" box and hit scan again immeadiatly the screen went whacky and it auto started in safe mode.

tired loading it from safe mode and the laptop bluescreened on me and started the memory dump on me.
got any other suggestions?
thx yvonne
Yvonne:

Try this one instead:
🖼Click to load external image (Posted Image) Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Please include the following in your next post:
  • RKU log
here is the rku log RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6001 (Service Pack 1) Number of processors #1 ============================================== >Drivers ============================================== 0x8B204000 C:\Windows\system32\DRIVERS\atikmdag.sys 5861376 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver) 0x8261C000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System) 0x8261C000 PnpManager 3903488 bytes 0x8261C000 RAW 3903488 bytes 0x8261C000 WMIxWDM 3903488 bytes 0x8C00E000 C:\Windows\system32\drivers\RTKVHDA.sys 2150400 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x95E90000 Win32k 2109440 bytes 0x95E90000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xA3609000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110101.005\NAVEX15.SYS 1355776 bytes (Symantec Corporation, AV Engine) 0x87A07000 C:\Windows\System32\Drivers\Ntfs.sys 1110016 bytes (Microsoft Corporation, NT File System Driver) 0x87672000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x87803000 C:\Windows\System32\drivers\tcpip.sys 954368 bytes (Microsoft Corporation, TCP/IP Driver) 0x8046C000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0x99A7B000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x8B808000 C:\Windows\system32\DRIVERS\athr.sys 724992 bytes (Atheros Communications, Inc., Atheros Extensible Wireless LAN device driver) 0x99405000 C:\Windows\system32\drivers\spsys.sys 716800 bytes (Microsoft Corporation, security processor) 0x87929000 C:\Windows\System32\drivers\dxgkrnl.sys 651264 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x8054C000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic) 0x8CCF0000 C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys 503808 bytes (Symantec Corporation, Common Client Hash Provider Driver) 0x87601000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x994B4000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x8CC5E000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xA3768000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20101231.001\IDSvix86.sys 372736 bytes (Symantec Corporation, IDS Core Driver) 0x99B87000 C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS 339968 bytes (Symantec Corporation, Symantec AutoProtect) 0x8078A000 C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS 323584 bytes (Symantec Corporation, Symantec Extended File Attributes) 0x99A0E000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0x8B7A8000 C:\Windows\system32\DRIVERS\yk60x86.sys 315392 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.) 0x806AB000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x8C38B000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x80602000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x8CD6B000 C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys 270336 bytes (Symantec Corporation, BASH Driver) 0x8042B000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x8BA01000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8B8EB000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x8BBC3000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x877A8000 C:\Windows\system32\drivers\NETIO.SYS 237568 bytes (Microsoft Corporation, Network I/O Subsystem) 0x995AB000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x87B16000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x8C2FB000 C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS 212992 bytes (Symantec Corporation, Network Dispatch Driver) 0x8BB39000 C:\Windows\system32\DRIVERS\usbhub.sys 212992 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x829D5000 ACPI_HAL 208896 bytes 0x829D5000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x80748000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x8BB7E000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x8B981000 C:\Windows\system32\DRIVERS\SynTP.sys 196608 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0x8B9BC000 C:\Windows\system32\DRIVERS\msiscsi.sys 188416 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x8C21B000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x8777D000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8BAF8000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0x879C8000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0x805D5000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x87B66000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x80659000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x8C248000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x8C32F000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x8BA84000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x87B9E000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0x8C292000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x9956C000 C:\Windows\system32\drivers\mrxdav.sys 131072 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x9958C000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x8072A000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x8CCBC000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0x99521000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x878EC000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x87BD0000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0x9953E000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x8B8BA000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x995E4000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x8CCD9000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x8BA62000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x99B71000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x8C3D3000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x8C2E5000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0x99557000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8BACA000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8C362000 C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS 86016 bytes (Symantec Corporation, Firewall Filter Driver) 0xA3754000 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110101.005\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0x8BAB6000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x8C377000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x8B959000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver) 0x877E2000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x8BBB0000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8B943000 C:\Windows\system32\DRIVERS\HDAudBus.sys 73728 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x87B8D000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8BB6D000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x80412000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x87910000 C:\Windows\system32\DRIVERS\amdk8.sys 65536 bytes (Microsoft Corporation, Processor Device Driver) 0x8077A000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x8CDE6000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x8070A000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8BAE6000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x8CDD7000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x87B57000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x80680000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8BAA7000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8B934000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x8069C000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x960D0000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x8C3F2000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x8C2CE000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x806FC000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x8C354000 C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS 57344 bytes (Symantec Corporation, NDIS Filter Driver) 0x8CDAD000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x8BA55000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0x8BB2C000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x8B79B000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver) 0x805C8000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0x99B65000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x8C286000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x8CDBA000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes 0x8B976000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x8B9B1000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x8C2C3000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8BA79000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8BA42000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x87BF0000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x80692000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0x8B96C000 C:\Windows\system32\DRIVERS\DKbFltr.sys 40960 bytes (Dritek System Inc., Dritek PS2 Keyboard Filter Driver) 0x8CDCD000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8BB22000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0x8CDF6000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x8B9EA000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0x99B5B000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x8C000000 C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0x8B8E1000 C:\Windows\system32\DRIVERS\usbohci.sys 40960 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0x87BC7000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x8C26F000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0xA37C3000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x807D9000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0x8C2DC000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0x8C3E9000 C:\Windows\system32\DRIVERS\SymIMv.sys 36864 bytes (Symantec Corporation, NDIS 6.0 Filter Driver for Windows Vista) 0x960B0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x87907000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x8B929000 C:\Windows\system32\DRIVERS\usbfilter.sys 36864 bytes (Advanced Micro Devices Inc., AMD USB Filter Driver) 0x87920000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0x80648000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x80722000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x87BBF000 C:\Windows\system32\DRIVERS\AtiPcie.sys 32768 bytes (ATI Technologies Inc., ATI PCIE Driver for ATI PCIE chipset) 0x80423000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x8CDC5000 C:\Windows\System32\Drivers\dump_atapi.sys 32768 bytes 0x8040A000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x80651000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x8B8D3000 C:\Windows\system32\DRIVERS\NTIDrvr.sys 32768 bytes (NewTech Infosystems, Inc., NTI CD-ROM Filter Driver) 0x8C2B3000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8C2BB000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8BA4D000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver) 0x87B4F000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x8071A000 C:\Windows\System32\Drivers\UBHelper.sys 32768 bytes (NewTech Infosystems Corporation, NTI CDROM Filter Driver) 0x8C27F000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x99A74000 C:\Windows\system32\drivers\int15.sys 28672 bytes (Acer, Inc., int15) 0x8C278000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x806F5000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0x8BADF000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver) 0x8B8DB000 C:\Windows\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0x8B955000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0x8068F000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0x99B59000 C:\Windows\system32\drivers\regi.sys 8192 bytes (InterVideo, regi driver) 0x8BAF6000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x8B932000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0x8C26D000 C:\Windows\System32\Drivers\Cdr4_xp.SYS 4096 bytes (Sonic Solutions, CDR4 CD and DVD Place Holder Driver (see PxHelp)) 0x8C26E000 C:\Windows\System32\Drivers\Cdralw2k.SYS 4096 bytes (Sonic Solutions, CDRAL Place Holder Driver (see PxHelp)) ============================================== >Stealth ============================================== 0x09580000 Hidden Image–>CLI.Component.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 1003520 bytes 0x08C80000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 102400 bytes 0x00BF0000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 118784 bytes 0x045B0000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 118784 bytes 0x09710000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 126976 bytes 0x096A0000 Hidden Image–>CLI.Aspect.Welcome.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 143360 bytes 0x0A110000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 159744 bytes 0x098D0000 Hidden Image–>CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 1699840 bytes 0x08CB0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 217088 bytes 0x096D0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 233472 bytes 0x04500000 Hidden Image–>log4net.dll [ EPROCESS 0x872DE818 ] PID: 2108, 282624 bytes 0x07A50000 Hidden Image–>CLI.Caste.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 282624 bytes 0x00F50000 Hidden Image–>Framework.Model.ControllerInterface.dll [ EPROCESS 0x872DE818 ] PID: 2108, 28672 bytes 0x031D0000 Hidden Image–>Framework.PluginInterface.dll [ EPROCESS 0x872DE818 ] PID: 2108, 28672 bytes 0x043E0000 Hidden Image–>eRecovery.RemoteServerInterface.dll [ EPROCESS 0x872DE818 ] PID: 2108, 28672 bytes 0x04360000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 28672 bytes 0x04390000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 28672 bytes 0x03CE0000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x03D10000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x05880000 Hidden Image–>LOCALIZATION.Foundation.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x05DA0000 Hidden Image–>CLI.Component.Runtime.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x06190000 Hidden Image–>AEM.Server.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x061C0000 Hidden Image–>AEM.Plugin.DPPE.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x06600000 Hidden Image–>AEM.Plugin.WinMessages.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x065F0000 Hidden Image–>AEM.Plugin.Hotkeys.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x06D50000 Hidden Image–>DEM.Graphics.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x06D40000 Hidden Image–>DEM.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07680000 Hidden Image–>CLI.Caste.Graphics.Runtime.Shared.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x076E0000 Hidden Image–>DEM.Graphics.I0706.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x076D0000 Hidden Image–>DEM.Graphics.I0805.dll [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07850000 Hidden Image–>DEM.Graphics.I0712.dll [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07AA0000 Hidden Image–>DEM.OS.I0602.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07AD0000 Hidden Image–>DEM.Graphics.I0709.dll [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07AC0000 Hidden Image–>DEM.OS.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07B70000 Hidden Image–>AEM.Plugin.GD.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07DD0000 Hidden Image–>DEM.Graphics.I0804.dll [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x07DB0000 Hidden Image–>AEM.Actions.CCAA.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x087A0000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x087B0000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x087C0000 Hidden Image–>APM.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08A30000 Hidden Image–>CLI.Component.Runtime.Extension.EEU.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08B50000 Hidden Image–>AEM.Plugin.EEU.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08C70000 Hidden Image–>CLI.Component.Wizard.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08D00000 Hidden Image–>atixclib.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08DB0000 Hidden Image–>CLI.Caste.Graphics.Wizard.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08ED0000 Hidden Image–>CLI.Component.Client.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08F00000 Hidden Image–>CLI.Component.Dashboard.Shared.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08EF0000 Hidden Image–>CLI.Component.Dashboard.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08F10000 Hidden Image–>CLI.Caste.Graphics.Dashboard.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 28672 bytes 0x08D20000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 315392 bytes 0x09E70000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 356352 bytes 0x00F80000 Hidden Image–>Framework.Host.dll [ EPROCESS 0x872DE818 ] PID: 2108, 36864 bytes 0x03BF0000 Hidden Image–>eRecovery.ServicePlugin.dll [ EPROCESS 0x872DE818 ] PID: 2108, 36864 bytes 0x05D60000 Hidden Image–>CCC.Implementation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 36864 bytes 0x05EB0000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 36864 bytes 0x01B60000 Hidden Image–>CCC.Implementation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x04510000 Hidden Image–>CLI.Foundation.XManifest.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x059A0000 Hidden Image–>AxInterop.WBOCXLib.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x06130000 Hidden Image–>Interop.WBOCXLib.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x06120000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x07450000 Hidden Image–>ACE.Graphics.DisplaysManager.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x076A0000 Hidden Image–>CLI.Aspect.CustomFormats.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x07780000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x077B0000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x07800000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x07930000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x07AB0000 Hidden Image–>LOCALIZATION.Foundation.Implementation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x08D90000 Hidden Image–>CLI.Component.Wizard.Shared.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 36864 bytes 0x09020000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 372736 bytes 0x09AE0000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 389120 bytes 0x08BF0000 Hidden Image–>CLI.Component.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 405504 bytes 0x09200000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 413696 bytes 0x09B40000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 413696 bytes 0x08B60000 Hidden Image–>CLI.Component.Systemtray.DLL [ EPROCESS 0x84648020 ] PID: 4280, 430080 bytes 0x09A70000 Hidden Image–>CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 446464 bytes 0x00B40000 Hidden Image–>Framework.Model.Controller.dll [ EPROCESS 0x872DE818 ] PID: 2108, 45056 bytes 0x01060000 Hidden Image–>Framework.Utility.CommonFunctions.dll [ EPROCESS 0x872DE818 ] PID: 2108, 45056 bytes 0x043B0000 Hidden Image–>Framework.Utility.dll [ EPROCESS 0x872DE818 ] PID: 2108, 45056 bytes 0x00C80000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 45056 bytes 0x00CA0000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 45056 bytes 0x03CC0000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x042F0000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x05DB0000 Hidden Image–>ATICCCom.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x076C0000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x076F0000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x077A0000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x077F0000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 45056 bytes 0x09180000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 495616 bytes 0x05B20000 Hidden Image–>CLI.Component.Runtime.Shared.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x05C50000 Hidden Image–>CLI.Foundation.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x06040000 Hidden Image–>AEM.Server.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x061B0000 Hidden Image–>AEM.Plugin.Source.Kit.Server.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x06D30000 Hidden Image–>DEM.Graphics.I0601.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x07690000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x07770000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x077D0000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x07920000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x08BE0000 Hidden Image–>CLI.Component.Client.Shared.Private.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x08CF0000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x08EC0000 Hidden Image–>CLI.Caste.Graphics.Wizard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 53248 bytes 0x09ED0000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 593920 bytes 0x03CF0000 Hidden Image–>CLI.Foundation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x04590000 Hidden Image–>CLI.Component.SkinFactory.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x05B10000 Hidden Image–>CLI.Component.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x07440000 Hidden Image–>CLI.Caste.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x077E0000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x07840000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x07860000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x078F0000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 61440 bytes 0x00F60000 Hidden Image–>Framework.Library.dll [ EPROCESS 0x872DE818 ] PID: 2108, 69632 bytes 0x043C0000 Hidden Image–>eRecovery.RemoteServer.dll [ EPROCESS 0x872DE818 ] PID: 2108, 69632 bytes 0x03DA0000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0x973B8D90 ] PID: 3404, 69632 bytes 0x042B0000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0x84648020 ] PID: 4280, 69632 bytes 0x07820000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 69632 bytes 0x07880000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 69632 bytes 0x088D0000 Hidden Image–>APM.Server.DLL [ EPROCESS 0x84648020 ] PID: 4280, 69632 bytes 0x07720000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Shared.DLL [ EPROCESS 0x84648020 ] PID: 4280, 77824 bytes 0x07660000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 77824 bytes 0x07B50000 Hidden Image–>ATIDEMOS.DLL [ EPROCESS 0x84648020 ] PID: 4280, 77824 bytes 0x09DA0000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 806912 bytes 0x0A040000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 815104 bytes 0x07700000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 86016 bytes 0x078D0000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Runtime.DLL [ EPROCESS 0x84648020 ] PID: 4280, 86016 bytes 0x09680000 Hidden Image–>CLI.Caste.Graphics.Dashboard.DLL [ EPROCESS 0x84648020 ] PID: 4280, 86016 bytes ============================================== >Hooks ============================================== ntkrnlpa.exe+0x000B4EEA, Type: Inline - RelativeJump 0x826D0EEA–>826D0EF1 [ntkrnlpa.exe] ntkrnlpa.exe+0x000B8E48, Type: Inline - RelativeJump 0x826D4E48–>826D4E39 [ntkrnlpa.exe] ntkrnlpa.exe+0x000B8EA4, Type: Inline - RelativeJump 0x826D4EA4–>826D4ECB [ntkrnlpa.exe] ntkrnlpa.exe+0x000B8FD8, Type: Inline - RelativeJump 0x826D4FD8–>826D4FFD [ntkrnlpa.exe] [3000]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x778F7933–>00000000 [unknown_code_page] thanx vonne
Yvonne:

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:23012
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [eRecoveryService] File not found
    O4 - HKCU..\Run: [DW6] File not found
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab (Reg Error: Key error.)
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (Reg Error: Key error.)
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
    O18 - Protocol\Handler\mso-offdap - No CLSID value found
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    O33 - MountPoints2\{5b931d25-b99f-11de-b36c-001d72f4c07c}\Shell - "" = AutoRun
    O33 - MountPoints2\{5b931d25-b99f-11de-b36c-001d72f4c07c}\Shell\AutoRun\command - "" = F:\HPLauncher.exe – File not found
    O33 - MountPoints2\{8741a25d-5051-11de-9b34-001d72f4c07c}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\{8741a25d-5051-11de-9b34-001d72f4c07c}\Shell\phone\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
    O33 - MountPoints2\F\Shell\phone\command - "" = F:\autorun.exe – File not found
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information or C:\Qoobox
  • Make sure that everything else is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Please include the following in your next post:
  • OTL Fix log
  • MBAM log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI