dbjb7606
Topic Starter
My Post -
I get a stop error on blue screen 0X00000050
Page_fault_in_nopaged_area
_____________________________________________
Reply
There are a few possibilities here with this error:
Blue Screen- 'STOP 0x00000050 (PAGE FAULT IN NON PAGED AREA)'
http://windows.ittoolbox.com/groups/techni…ed_area-2171868
You may have a malicious driver:
http://support.microsoft.com/?kbid=894278&sd;=RMVP
Possibly a malicious display driver:
http://en.allexperts.com/q/Windows-XP-3282…00050-error.htm
My number 1 suspect is a malicious driver.
Firstly though, before going to any of the above links, go to Device Manager:
1. Go to Start / right click on "my computer" / click on "manage" / click on "Device Manager"
If there are any red, black or yellow warnings, you have a driver problem for sure.
If so, right click on the device and choose "properties" / click on driver / click on un-install driver / re-start
2. Go to MS updates and choose "custom". Download the correct driver which should show up there as "optional downloads".
Cheers,
Lee
______________________________________________________
My Post
No Warnings in Device Manager
_______________________________________________________
Reply
Ok, that's might be good, but just because nothing shows up in the Device Manager, does not mean there is no malicious driver in your PC.
I don't know what security you have installed, but you should run a check with your anti-virus and also an anti-Malware program. If you don't have one
you can download "Malwarebytes" from here: http://www.malwarebytes.org/mbam.php
Download it to your desktop and when installing make sure any added extras like toolbars offered are un-ticked.
If a Virus is found, I would open a thread in the Melware section here. If a malicious driver is found after these checks, I would follow the instruction in the 2nd. link in my original post, or take the problem to the Melware section where the experts there can guide you.
The error you are receiving usually refers to a malicious driver (usually the display driver), but there can be other reasons for that error too and that is why I originally gave you those 3 links, so you could better define your problem.
Cheers,
Lee
___________________________________________________
My Post
Here is my Malware bytes log….I run it regularly and surely haven't seen this many items!!! Before I do a memory test, I will wait for you to look at it and advise. The memory diagnostic you describe is kinda confusing
My system is a Dell Optiplex GX620 Running XP Home SP3 4 GB Ram on 2 sticks Pentium D Processor 2.80 GHz.
Thanks for your help
________________________________________________________________________________
_
Reply
Look in Add and Remove Programs (from Control Panel) and see if you have a program called (or something like) Perfect Optimizer installed. If so, uninstall it.
You had a lot of infected areas of your computer and I suspect MalwareBytes will not have removed it all. I think it would be a good idea for you to go to the Spyware / Malware / Virus Removal forum area, read the info there and follow the posted directions. Once you receive a clean bill of health, come back here if you have any additional questions or concerns or it turns out not to be a malware problem.
Please be patient as that is a very busy area. If you do not receive a response in 3 days, post a message here: http://forums.whatthetech.com/What_Do_If_Y…ays_t78698.html
It would still be a good idea to run the memory test though.
*****Note - I Uninstalled Perfect Optimizer
________________________________________________________________
OTL Posts follow:
OTL logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32
Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
PRC - C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
PRC - C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
PRC - C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
PRC - C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe (WareCentral.com)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\J River\Media Center 15\Plugins\msscript.ocx (Microsoft Corporation)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (Media Center 15 Service) – C:\Program Files\J River\Media Center 15\JRService.exe (J. River, Inc.)
SRV - (QBVSS) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (QuickBooksDB21) – C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (LBTServ) – C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TSP) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) – C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (se3eobex) – C:\WINDOWS\system32\drivers\se3eobex.sys (MCCI Corporation)
DRV - (se3emgmt) Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se3emgmt.sys (MCCI Corporation)
DRV - (se3emdm) – C:\WINDOWS\system32\drivers\se3emdm.sys (MCCI Corporation)
DRV - (se3emdfl) – C:\WINDOWS\system32\drivers\se3emdfl.sys (MCCI Corporation)
DRV - (se3ebus) Sony Ericsson Device 062 (WDM) – C:\WINDOWS\system32\drivers\se3ebus.sys (MCCI Corporation)
DRV - (elagopro) – C:\WINDOWS\system32\drivers\elagopro.sys (Gteko Ltd.)
DRV - (elaunidr) – C:\WINDOWS\system32\drivers\elaunidr.sys (Gteko Ltd.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PfModNT.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=proxy-server:8080;https=proxy-server:8080
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:7.1.5
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.69
FF - prefs.js..network.proxy.http: "proxy-server"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "ams-server*,*.local"
FF - prefs.js..network.proxy.ssl: "proxy-server"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/20 10:34:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/15 22:47:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/13 18:10:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/12 22:58:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.9\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2010/12/07 21:06:07 | 000,000,000 | —D | M]
[2010/10/12 19:02:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions
[2008/05/09 15:54:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2009/06/29 11:18:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2010/06/18 22:27:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2011/01/19 07:30:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions
[2010/11/30 23:03:58 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011/01/16 00:28:54 | 000,000,000 | —D | M] ("LittleFox") – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2010/10/15 18:20:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/10/12 21:19:29 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/01/12 22:50:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/01/19 08:22:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions
[2009/05/31 19:16:40 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2009/05/31 20:07:42 | 000,000,000 | —D | M] (MinimizeToTray–0.9 Compatible) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{31513E58-F253-47ad-86DB-D5F21E901234}
[2009/05/31 16:39:56 | 000,000,000 | —D | M] (FoxClocks) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2011/01/05 22:59:29 | 000,001,820 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\bing.xml
[2010/12/01 07:42:28 | 000,001,196 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\winamp-search.xml
[2010/10/12 19:01:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/20 10:34:29 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/12/15 22:47:09 | 000,000,000 | —D | M] (Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/11/30 09:11:52 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2009/12/07 20:15:44 | 000,360,824 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 12430 more lines…
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (FoxyTunes Toolbar Helper) - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - No CLSID value found.
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O3 - HKLM\..\Toolbar: (FoxyTunes Toolbar) - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DLSService] C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
O4 - HKCU..\Run: [EasyLinkAdvisor] C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [GoodSync] C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
O4 - HKCU..\Run: [MRC] C:\Program Files\PC Tune-Up\PCTuneUp.exe (Large Software)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SoftAuto.exe] C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [SystemExplorer] File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\PrintKey-Pro.lnk = C:\WINDOWS\Installer\{5EFA4EA3-0604-458C-A06D-485F6B2724C9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled [2011/01/18 23:36:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\CNET TechTracker.lnk = C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Mozilla Sunbird.lnk = C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra 'Tools' menuitem : VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
O16 - DPF: {16F67783-7E72-4C39-99C4-4780A8335484} http://www.syncmyride.com/Own/Modules/Uplo…pplets/sync.cab (SyncXfer Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1266388971562 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} http://www.shockwave.com/content/bigcityad…BGamePlayer.cab (Jolly Bear Games Player)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (Reg Error: Key error.)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (Reg Error: Key error.)
O16 - DPF: PackageCab http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O27 - HKLM IFEO\wupdmgr.exe: Debugger - ntsd– File not found
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/11 17:47:36 | 000,000,000 | —D | M] - E:\autorun – [ FAT32 ]
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\AutoRun\command - "" = M:\slacker.synclauncher.exe
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\slacker\command - "" = M:\slacker.synclauncher.exe
O34 - HKLM BootExecute: ("autocheck autochk *") - File not found
O34 - HKLM BootExecute: (autocheck smrgdf C:\Documents and Settings\Donald Bishop\Application Data\iolo\) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (63908374630105088)
========== Files/Folders - Created Within 30 Days ==========
[2011/01/19 21:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388_files
[2011/01/19 21:31:23 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:10 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 08:13:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Donald Bishop\Recent
[2011/01/18 23:36:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled
[2011/01/15 08:06:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RoboForm
[2011/01/15 08:02:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2011/01/14 17:32:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AD.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AC.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AB.tmp
[2011/01/12 22:52:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/01/08 00:34:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Start Menu\Programs\Revo Uninstaller
[2011/01/07 07:33:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GoodSync
[2011/01/03 20:10:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Intuit_Inc
[2010/12/25 13:11:27 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2010/12/23 15:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2010/12/22 23:32:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\My Documents\BlackBerry
[2010/08/31 17:04:19 | 008,134,344 | —- | C] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2003/12/09 13:16:52 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
[2011/01/19 21:56:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/19 21:35:21 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:35:17 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:34:29 | 000,069,432 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:36 | 000,359,929 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 21:24:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006UA.job
[2011/01/19 20:16:50 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 14:28:11 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\GoodSync - Quicken.job
[2011/01/19 08:56:02 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/19 08:27:10 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/01/19 08:11:44 | 000,002,351 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
[2011/01/19 08:11:34 | 000,000,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:34 | 000,000,204 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,202 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:09:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 08:07:07 | 000,000,802 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\PC Pitstop Disk MD - Daily E.job
[2011/01/18 20:37:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/18 20:35:42 | 000,000,120 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/01/18 20:35:42 | 000,000,044 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/01/18 20:03:43 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/01/18 20:03:11 | 000,000,110 | —- | M] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/01/18 19:38:25 | 000,332,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/17 22:24:08 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006Core.job
[2011/01/17 22:04:28 | 000,041,472 | —- | M] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/17 12:23:09 | 000,002,411 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/17 10:34:15 | 000,009,594 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/15 15:44:24 | 000,069,916 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume E Task.job
[2011/01/13 17:07:50 | 000,566,417 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume C Task.job
[2011/01/08 01:28:04 | 000,001,956 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/07 07:33:54 | 000,001,738 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\GoodSync.lnk
[2011/01/03 17:19:37 | 000,002,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/28 21:08:24 | 000,001,542 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/25 07:43:47 | 000,002,533 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/12/23 20:58:01 | 000,341,123 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/19 21:34:19 | 000,069,432 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:35 | 000,359,929 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 20:16:50 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 08:11:34 | 000,000,204 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:32 | 000,000,202 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:07:58 | 000,196,736 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/19 07:13:59 | 000,000,294 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/14 17:32:40 | 000,002,411 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/13 17:07:50 | 000,566,417 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/08 01:28:04 | 000,001,956 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/02 23:14:26 | 000,002,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/31 10:24:04 | 000,009,594 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2010/12/28 21:08:23 | 000,001,542 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/24 14:37:57 | 000,001,620 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/23 20:58:00 | 000,341,123 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2010/12/20 21:38:06 | 000,002,772 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.Exception.log
[2010/12/20 21:36:29 | 000,003,315 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\PreferencePane
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plugins
[2010/12/03 19:38:54 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2010/12/03 19:36:39 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Pop Flute
[2010/12/03 19:36:38 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plug-In Settings
[2010/12/03 19:36:38 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2010/08/17 22:08:09 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/06 21:53:34 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/10/05 09:43:43 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2009/07/27 21:02:41 | 000,055,809 | —- | C] () – C:\WINDOWS\CP-FPCOS100.dll
[2009/07/06 16:16:35 | 000,008,086 | RHS- | C] () – C:\Program Files\uninstall.log
[2009/05/31 18:06:46 | 000,013,020 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Comma Separated Values (Windows).CAL
[2009/05/08 06:34:43 | 008,673,792 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2008/12/12 14:04:46 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/12/12 14:03:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/10/30 16:03:23 | 000,000,110 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/04/15 21:46:29 | 000,018,790 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2008/04/03 22:32:06 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2008/02/11 08:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 08:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/08 12:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/21 00:40:51 | 000,002,711 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2007/11/17 17:55:09 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/10/07 14:32:50 | 000,000,166 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/08/04 16:26:03 | 000,000,513 | —- | C] () – C:\WINDOWS\pu32i.ini
[2007/07/27 13:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 13:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/04/02 22:43:38 | 000,000,000 | —- | C] () – C:\WINDOWS\Hammerhead.INI
[2007/03/13 17:30:02 | 000,003,102 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/10 15:02:41 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/03/10 14:52:59 | 000,039,790 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/01/27 12:22:29 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\DymoQBInst.dll
[2007/01/27 12:20:45 | 000,000,056 | —- | C] () – C:\WINDOWS\Addrfixr.ini
[2007/01/27 12:20:45 | 000,000,036 | —- | C] () – C:\WINDOWS\iltwain.ini
[2007/01/27 12:20:27 | 000,007,803 | —- | C] () – C:\WINDOWS\System32\dymourl.ini
[2007/01/27 12:18:31 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\DYMOCFG.DLL
[2007/01/27 12:18:31 | 000,002,560 | —- | C] () – C:\WINDOWS\System32\lmmonres.dll
[2007/01/03 10:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 10:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 10:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/15 23:44:07 | 000,000,136 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\fusioncache.dat
[2006/12/15 17:51:18 | 000,000,982 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\.googlewebacchosts
[2006/12/10 19:04:37 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/03 01:34:49 | 000,041,472 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 23:42:47 | 000,000,088 | —- | C] () – C:\WINDOWS\gbsaver.ini
[2006/12/02 22:31:25 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\dfxg14.dll
[2006/12/02 18:06:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\dm.ini
[2006/12/02 18:06:08 | 000,000,676 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\AdobeDLM.log
[2006/12/02 16:50:42 | 000,000,170 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/12/02 16:46:56 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/02 16:15:20 | 000,009,255 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/12/02 15:13:23 | 000,002,582 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/02 13:51:58 | 000,000,549 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2006/12/02 13:37:31 | 000,000,038 | —- | C] () – C:\WINDOWS\System32\w3url.dll
[2006/12/02 13:01:24 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/11/28 15:06:28 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/11/28 14:44:06 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/09/18 13:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006/09/18 13:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2006/05/02 17:38:24 | 000,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2005/12/05 18:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 11:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,481 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:51:10 | 000,025,741 | —- | C] () – C:\WINDOWS\System32\aavr3h.dll
[2004/08/10 12:51:10 | 000,015,365 | —- | C] () – C:\WINDOWS\System32\llbstp.dll
[2004/08/04 05:00:00 | 000,018,705 | —- | C] () – C:\WINDOWS\System32\nusvg7cc.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2010/08/31 16:23:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2008/12/12 13:53:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/12/02 19:13:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/05/17 18:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2009/07/06 16:16:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DYMO
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/03/15 21:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EUFJFLUFYG
[2010/10/10 21:51:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/09/01 06:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2009/07/13 15:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2010/12/03 19:36:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Guides
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hybrid Chords
[2008/12/05 18:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software
[2006/12/28 20:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2010/10/31 15:19:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/01/19 00:35:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/11/13 15:59:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/09/07 06:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
[2009/11/05 18:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2007/10/21 12:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/12/01 17:34:40 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2007/08/27 08:36:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MipKukSoft
[2009/04/21 22:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/12/03 19:37:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2009/11/15 11:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/07/06 20:27:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2010/10/10 21:50:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/03/09 17:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/07/26 23:03:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/04/04 22:23:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/01/08 01:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2006/12/02 15:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/12/12 14:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/10/30 16:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2011/01/03 21:55:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2009/07/11 09:59:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2007/12/20 09:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/29 23:03:00 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\System Restore
[2009/06/22 17:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/28 16:38:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/04/27 14:50:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/22 18:49:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VMGJFLUFYG
[2009/06/25 21:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WindSolutions
[2007/10/26 07:21:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/12/10 18:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YoWindow
[2010/05/22 08:08:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 16:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/19 13:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/10/11 18:41:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F29F2260-20C9-49D5-9651-71A8580940BF}
[2009/01/03 17:04:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F40E9D30-5DFC-4B21-BFDB-A5CDEE6440A6}
[2009/01/03 17:03:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2009/10/19 15:07:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2007/06/02 16:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\.purple
[2008/05/20 17:11:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\acccore
[2010/10/30 16:44:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Amazon
[2011/01/16 20:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2008/10/31 06:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Buddi
[2009/01/02 14:37:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Canon
[2010/08/17 22:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive
[2010/06/15 06:49:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CheckPoint
[2009/08/21 17:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/11/14 01:32:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/06/25 21:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CopyTransPhoto
[2009/05/07 06:39:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Dealio
[2010/09/25 21:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\DriverCure
[2010/06/27 16:50:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\eMusic
[2008/12/28 00:42:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Facebook
[2008/07/29 23:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FireShot
[2008/03/24 21:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Flock
[2006/12/02 16:08:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FotoWire
[2010/06/15 20:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FoxyTunes
[2010/06/14 11:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GARMIN
[2011/01/19 00:43:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GoodSync
[2007/06/01 18:19:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\gtk-2.0
[2007/01/08 18:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ICAClient
[2009/06/19 21:42:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iLike
[2007/10/07 13:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Image Zone Express
[2010/10/19 16:54:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iolo
[2010/08/06 21:41:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\J River
[2007/08/27 08:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Kybtec Software
[2007/03/16 06:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Launchy
[2009/06/30 16:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Leadertech
[2009/05/31 15:18:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MailFrontier
[2007/08/27 18:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MipKukSoft
[2007/10/16 21:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MSNInstaller
[2006/12/02 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Musicmatch
[2008/12/12 14:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\NewSoft
[2009/05/30 07:49:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\OfficeUpdate12
[2007/10/12 16:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Opera
[2010/09/25 21:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ParetoLogic
[2009/01/02 16:08:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Pogo Games
[2010/02/05 07:49:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Portalarium
[2007/10/07 12:48:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Printer Info Cache
[2010/12/20 21:39:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Research In Motion
[2007/12/08 17:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoadRunner
[2011/01/15 08:02:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2008/12/12 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ScanSoft
[2009/05/07 06:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Search Settings
[2007/07/17 06:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\SlimBrowser
[2008/05/21 22:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Snapfish
[2010/06/18 22:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Songbird2
[2007/11/17 17:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Teleca
[2007/09/24 15:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\TomTom
[2007/07/19 17:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Uniblue
[2008/07/10 20:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Windows Desktop Search
[2009/06/25 21:30:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WindSolutions
[2010/05/28 06:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WinPatrol
[2010/12/10 18:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\YoWindow
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume C Task.job
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume E Task.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\GoodSync - Quicken.job
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Daily E.job
[2007/07/21 03:26:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Once E.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/29 21:50:17 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/04/28 15:55:01 | 000,031,861 | —- | M] () – C:\ComboFix.txt
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/11/28 14:45:30 | 000,004,478 | RH– | M] () – C:\dell.sdr
[2008/10/31 18:45:10 | 000,000,051 | —- | M] () – C:\EventLOG.txt
[2010/11/12 14:17:29 | 000,000,081 | —- | M] () – C:\FDeClient_Start.log
[2010/02/17 00:38:47 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2010/08/12 06:37:56 | 000,000,255 | —- | M] () – C:\INSTALL.LOG
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/09/07 22:28:44 | 000,001,375 | -H– | M] () – C:\IPH.PH
[2009/04/26 16:10:37 | 000,006,608 | —- | M] () – C:\JavaRa.log
[2006/12/02 16:06:42 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/17 20:00:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/19 08:09:12 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/05/31 14:08:51 | 000,000,805 | —- | M] () – C:\rollback.ini
[2006/12/07 07:26:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2007/03/16 06:16:59 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2007/03/17 18:59:23 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2007/03/23 23:07:35 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2007/04/16 23:02:21 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2007/04/20 16:17:08 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2007/04/21 16:18:54 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2007/04/28 23:51:16 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/03/27 12:21:57 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2006/12/07 07:26:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2007/03/16 06:16:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2007/03/17 18:59:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2007/03/23 23:07:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2007/04/16 23:02:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2007/04/20 16:17:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2007/04/21 16:18:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2007/04/28 23:51:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/03/27 12:21:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2007/07/23 22:03:57 | 000,000,033 | —- | M] () – C:\wizard.txt
[2009/04/20 22:21:36 | 000,000,152 | —- | M] () – C:\YServer.txt
[11 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/02/17 00:54:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/16 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8Z.DLL
[2007/04/16 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8Z.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/07/18 13:34:32 | 000,586,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2007/07/28 15:13:13 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2009/07/06 16:19:54 | 000,008,086 | RHS- | M] () – C:\Program Files\uninstall.log
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/02/16 19:31:05 | 004,194,304 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/16 21:50:47 | 000,262,144 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2010/02/16 19:31:05 | 048,758,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/16 19:31:05 | 006,553,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/06 16:20:01 | 000,000,226 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Create & Print Home.url
[2010/02/17 20:15:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/12/02 12:24:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/06/14 16:37:14 | 000,000,077 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
[2010/08/31 17:04:24 | 008,134,344 | —- | M] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-13 03:14:37
========== Alternate Data Streams ==========
@Alternate Data Stream - 185 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D0C22DC
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A41BE14
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EFDF5FB
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE9A3E83
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
OTL Extras logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32
Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.hta [@ = htafile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 9.0 Data Manager
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service – (Check Point Software Technologies LTD)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb – (Orb Networks, Inc.)
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray – (Orb Networks)
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – (Orb Networks)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe" = C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe:*:Enabled:Media Player
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 11.0 Data Manager – (Intuit, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03DF638A-D61C-4893-B8B9-845900C03163}" = TurboTax 2010 wnyiper
"{058B32E2-6310-4359-B2D4-1988390C3B83}" = Broadcom Advanced Control Suite
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{061BBC42-C5A9-4F82-AD24-EAE562968D0B}" = QuickBooks
"{0700E22B-A440-40A5-BD20-04BF618CA0F9}" = QuickBooks Enterprise Solutions: Retail Edition 10.0
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX310_series" = Canon MX310 series
"{11E0AC7D-6840-4F67-865F-EE1C13D28C38}" = QuickBooks Enterprise Solutions: Retail Edition 11.0
"{1EFCFB56-B8BB-4834-AE8E-29EE73FF8611}" = QuickBooks
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{321F110F-E26B-4E33-8F13-30A8C79DB687}" = Desk Drive
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}" = MSN Toolbar
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{37C5A56A-00EA-347B-B7A1-5628BED56702}" = Google Talk Plugin
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3AC785C0-EAA2-012B-AE3B-000000000000}" = TurboTax 2009 wneiper
"{3B8186F0-EAA2-012B-AE69-000000000000}" = TurboTax 2009 wnyiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53C398FE-CD56-412E-B3C7-B27F4B8B07D1}" = Microsoft IntelliType Pro 5.3
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{5658CE44-2822-45C9-A5C0-F93AB4682BBF}" = Document eSort Components
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{598420E8-E9F9-4FAE-9B6C-599FDF2F611A}" = BlackBerry App World Browser Plugin
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5EFA4EA3-0604-458C-A06D-485F6B2724C9}" = PrintKey-Pro v1.05
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73006B34-9743-4A39-AC37-38EDFCEB6DCE}" = Adobe Product/Adobe Studio Update 10/2001
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113269180}" = Mahjong Garden Deluxe
"{830C1687-F55F-45C1-AD2B-405824DC65DB}" = Network Recording Player
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9021848E-F315-44C7-8D45-3B16162AA73A}" = TurboTax 2010 wneiper
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91190409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Publisher 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-004E-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector 32-bit
"{95140000-007C-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Facebook 32-bit
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B335897-6FBC-46B4-94B9-C159DF25AD51}" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"{9F9BE2A8-2FA2-438E-934B-6F237B641167}" = Cooliris for Internet Explorer
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}" = Microsoft SQL Server VSS Writer
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}" = U3Launcher
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0904}" = Microsoft Digital Image Pro 9
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}" = ArcSoft Panorama Maker 5
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA0092C2-C0FE-40DA-A79E-E4C0FCA129F9}" = Intuit Entitlement Client
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Add-Remove Manager_is1" = Add-Remove Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AI RoboForm" = RoboForm 7-1-6 (All Users)
"AIM_7" = AIM 7
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"Audit Support Center" = Audit Support Center 1.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Bejeweled Blitz" = Bejeweled Blitz
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"Canon MX310 series User Registration" = Canon MX310 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"Clickster-Pro223" = Clickster-Pro
"Clickster-Pro224" = Clickster-Pro
"Clickster-Pro2241" = Clickster-Pro
"Creative Media Lite" = Creative Media Lite
"Defraggler" = Defraggler
"DYMO Label Software" = DYMO Label Software
"DYMO Label v.8" = DYMO Label v.8
"DYMO QuickBooks Add-In" = DYMO QuickBooks Add-In
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0033)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"EsetOnlineScanner" = ESET Online Scanner
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"FoxyTunesForInternetExplorer" = FoxyTunes for Internet Explorer
"Google Updater" = Google Updater
"Google Video Uploader" = Google Video Uploader
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Logitech Print Service" = Logitech Print Service
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mastering Intuit QuickBooks Enterprise Solutions 11.0" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"Media Center 12" = Media Center 12
"Media Center 15" = Media Center 15
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Sunbird (0.9)" = Mozilla Sunbird (0.9)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MP3 Player Recovery Tool_is1" = MP3 Player Recovery Tool
"MP3 WAV Converter 4.13" = MP3 WAV Converter 4.13
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MuVoT200UG" = Creative MuVo T200 User's Guide
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Orb" = Winamp Remote
"PC Matic_is1" = PC Matic 1.0.0.0
"PC Pitstop Disk MD_is1" = PC Pitstop Disk MD 2.0
"PC Pitstop Optimize2_is1" = PC Pitstop Optimize2 2.0
"PC Tune-Up" = PC Tune-Up
"PictureIt_v9" = Microsoft Digital Image Pro 9
"QcDrv" = Logitech® Camera Driver
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.91
"SearchAssist" = SearchAssist
"Shockwave" = Shockwave
"ShortKeys 2" = ShortKeys 2
"ShortKeys 3" = ShortKeys 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Songbird-release-1800" = Songbird 1.8.0 (Build 1800)
"STANDARDR" = Microsoft Office Standard 2007
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"Unlocker" = Unlocker 1.8.9
"Update Service" = Update Service
"VisualRoute Lite Edition" = VisualRoute Lite Edition
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"Yahoo! Widget Engine" = Yahoo! Widgets
"yowindow" = YoWindow
"ZoneAlarm Security Suite" = ZoneAlarm Security Suite
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
"Zune" = Zune
"Zynga Toolbar" = Zynga Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Chromium" = Chromium
"CNET TechTracker" = CNET TechTracker
"GmailPopTroubleshooter" = Gmail POP Troubleshooter
"LastPass" = LastPass (uninstall only)
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/19/2011 1:45:57 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:21:15 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
Error - 1/19/2011 9:13:55 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:23:34 PM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
[ OSession Events ]
Error - 10/9/2008 3:19:31 PM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6323.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/14/2011 1:52:08 AM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 164
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 1/19/2011 1:41:04 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 1:41:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/19/2011 2:22:37 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.
Error - 1/19/2011 2:22:57 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.
Error - 1/19/2011 2:23:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 2:23:13 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/19/2011 9:10:16 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.
Error - 1/19/2011 9:11:25 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.
Error - 1/19/2011 9:11:40 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 9:11:52 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
< End of report >
Thanks for your help
I get a stop error on blue screen 0X00000050
Page_fault_in_nopaged_area
_____________________________________________
Reply
There are a few possibilities here with this error:
Blue Screen- 'STOP 0x00000050 (PAGE FAULT IN NON PAGED AREA)'
http://windows.ittoolbox.com/groups/techni…ed_area-2171868
You may have a malicious driver:
http://support.microsoft.com/?kbid=894278&sd;=RMVP
Possibly a malicious display driver:
http://en.allexperts.com/q/Windows-XP-3282…00050-error.htm
My number 1 suspect is a malicious driver.
Firstly though, before going to any of the above links, go to Device Manager:
1. Go to Start / right click on "my computer" / click on "manage" / click on "Device Manager"
If there are any red, black or yellow warnings, you have a driver problem for sure.
If so, right click on the device and choose "properties" / click on driver / click on un-install driver / re-start
2. Go to MS updates and choose "custom". Download the correct driver which should show up there as "optional downloads".
Cheers,
Lee
______________________________________________________
My Post
No Warnings in Device Manager
_______________________________________________________
Reply
Ok, that's might be good, but just because nothing shows up in the Device Manager, does not mean there is no malicious driver in your PC.
I don't know what security you have installed, but you should run a check with your anti-virus and also an anti-Malware program. If you don't have one
you can download "Malwarebytes" from here: http://www.malwarebytes.org/mbam.php
Download it to your desktop and when installing make sure any added extras like toolbars offered are un-ticked.
If a Virus is found, I would open a thread in the Melware section here. If a malicious driver is found after these checks, I would follow the instruction in the 2nd. link in my original post, or take the problem to the Melware section where the experts there can guide you.
The error you are receiving usually refers to a malicious driver (usually the display driver), but there can be other reasons for that error too and that is why I originally gave you those 3 links, so you could better define your problem.
Cheers,
Lee
___________________________________________________
My Post
Here is my Malware bytes log….I run it regularly and surely haven't seen this many items!!! Before I do a memory test, I will wait for you to look at it and advise. The memory diagnostic you describe is kinda confusing
My system is a Dell Optiplex GX620 Running XP Home SP3 4 GB Ram on 2 sticks Pentium D Processor 2.80 GHz.
Thanks for your help
________________________________________________________________________________
_
Reply
Look in Add and Remove Programs (from Control Panel) and see if you have a program called (or something like) Perfect Optimizer installed. If so, uninstall it.
You had a lot of infected areas of your computer and I suspect MalwareBytes will not have removed it all. I think it would be a good idea for you to go to the Spyware / Malware / Virus Removal forum area, read the info there and follow the posted directions. Once you receive a clean bill of health, come back here if you have any additional questions or concerns or it turns out not to be a malware problem.
Please be patient as that is a very busy area. If you do not receive a response in 3 days, post a message here: http://forums.whatthetech.com/What_Do_If_Y…ays_t78698.html
It would still be a good idea to run the memory test though.
*****Note - I Uninstalled Perfect Optimizer
________________________________________________________________
OTL Posts follow:
OTL logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32
Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
PRC - C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
PRC - C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
PRC - C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
PRC - C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe (WareCentral.com)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\J River\Media Center 15\Plugins\msscript.ocx (Microsoft Corporation)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (Media Center 15 Service) – C:\Program Files\J River\Media Center 15\JRService.exe (J. River, Inc.)
SRV - (QBVSS) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (QuickBooksDB21) – C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (LBTServ) – C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TSP) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) – C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (se3eobex) – C:\WINDOWS\system32\drivers\se3eobex.sys (MCCI Corporation)
DRV - (se3emgmt) Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se3emgmt.sys (MCCI Corporation)
DRV - (se3emdm) – C:\WINDOWS\system32\drivers\se3emdm.sys (MCCI Corporation)
DRV - (se3emdfl) – C:\WINDOWS\system32\drivers\se3emdfl.sys (MCCI Corporation)
DRV - (se3ebus) Sony Ericsson Device 062 (WDM) – C:\WINDOWS\system32\drivers\se3ebus.sys (MCCI Corporation)
DRV - (elagopro) – C:\WINDOWS\system32\drivers\elagopro.sys (Gteko Ltd.)
DRV - (elaunidr) – C:\WINDOWS\system32\drivers\elaunidr.sys (Gteko Ltd.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PfModNT.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=proxy-server:8080;https=proxy-server:8080
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:7.1.5
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.69
FF - prefs.js..network.proxy.http: "proxy-server"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "ams-server*,*.local"
FF - prefs.js..network.proxy.ssl: "proxy-server"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/20 10:34:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/15 22:47:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/13 18:10:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/12 22:58:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.9\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2010/12/07 21:06:07 | 000,000,000 | —D | M]
[2010/10/12 19:02:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions
[2008/05/09 15:54:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2009/06/29 11:18:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2010/06/18 22:27:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2011/01/19 07:30:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions
[2010/11/30 23:03:58 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011/01/16 00:28:54 | 000,000,000 | —D | M] ("LittleFox") – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2010/10/15 18:20:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/10/12 21:19:29 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/01/12 22:50:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/01/19 08:22:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions
[2009/05/31 19:16:40 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2009/05/31 20:07:42 | 000,000,000 | —D | M] (MinimizeToTray–0.9 Compatible) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{31513E58-F253-47ad-86DB-D5F21E901234}
[2009/05/31 16:39:56 | 000,000,000 | —D | M] (FoxClocks) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2011/01/05 22:59:29 | 000,001,820 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\bing.xml
[2010/12/01 07:42:28 | 000,001,196 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\winamp-search.xml
[2010/10/12 19:01:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/20 10:34:29 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/12/15 22:47:09 | 000,000,000 | —D | M] (Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/11/30 09:11:52 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2009/12/07 20:15:44 | 000,360,824 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 12430 more lines…
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (FoxyTunes Toolbar Helper) - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - No CLSID value found.
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O3 - HKLM\..\Toolbar: (FoxyTunes Toolbar) - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DLSService] C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
O4 - HKCU..\Run: [EasyLinkAdvisor] C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [GoodSync] C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
O4 - HKCU..\Run: [MRC] C:\Program Files\PC Tune-Up\PCTuneUp.exe (Large Software)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SoftAuto.exe] C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [SystemExplorer] File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\PrintKey-Pro.lnk = C:\WINDOWS\Installer\{5EFA4EA3-0604-458C-A06D-485F6B2724C9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled [2011/01/18 23:36:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\CNET TechTracker.lnk = C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Mozilla Sunbird.lnk = C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra 'Tools' menuitem : VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
O16 - DPF: {16F67783-7E72-4C39-99C4-4780A8335484} http://www.syncmyride.com/Own/Modules/Uplo…pplets/sync.cab (SyncXfer Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1266388971562 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} http://www.shockwave.com/content/bigcityad…BGamePlayer.cab (Jolly Bear Games Player)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (Reg Error: Key error.)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (Reg Error: Key error.)
O16 - DPF: PackageCab http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O27 - HKLM IFEO\wupdmgr.exe: Debugger - ntsd– File not found
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/11 17:47:36 | 000,000,000 | —D | M] - E:\autorun – [ FAT32 ]
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\AutoRun\command - "" = M:\slacker.synclauncher.exe
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\slacker\command - "" = M:\slacker.synclauncher.exe
O34 - HKLM BootExecute: ("autocheck autochk *") - File not found
O34 - HKLM BootExecute: (autocheck smrgdf C:\Documents and Settings\Donald Bishop\Application Data\iolo\) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (63908374630105088)
========== Files/Folders - Created Within 30 Days ==========
[2011/01/19 21:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388_files
[2011/01/19 21:31:23 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:10 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 08:13:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Donald Bishop\Recent
[2011/01/18 23:36:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled
[2011/01/15 08:06:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RoboForm
[2011/01/15 08:02:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2011/01/14 17:32:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AD.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AC.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AB.tmp
[2011/01/12 22:52:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/01/08 00:34:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Start Menu\Programs\Revo Uninstaller
[2011/01/07 07:33:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GoodSync
[2011/01/03 20:10:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Intuit_Inc
[2010/12/25 13:11:27 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2010/12/23 15:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2010/12/22 23:32:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\My Documents\BlackBerry
[2010/08/31 17:04:19 | 008,134,344 | —- | C] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2003/12/09 13:16:52 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
[2011/01/19 21:56:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/19 21:35:21 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:35:17 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:34:29 | 000,069,432 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:36 | 000,359,929 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 21:24:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006UA.job
[2011/01/19 20:16:50 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 14:28:11 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\GoodSync - Quicken.job
[2011/01/19 08:56:02 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/19 08:27:10 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/01/19 08:11:44 | 000,002,351 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
[2011/01/19 08:11:34 | 000,000,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:34 | 000,000,204 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,202 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:09:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 08:07:07 | 000,000,802 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\PC Pitstop Disk MD - Daily E.job
[2011/01/18 20:37:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/18 20:35:42 | 000,000,120 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/01/18 20:35:42 | 000,000,044 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/01/18 20:03:43 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/01/18 20:03:11 | 000,000,110 | —- | M] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/01/18 19:38:25 | 000,332,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/17 22:24:08 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006Core.job
[2011/01/17 22:04:28 | 000,041,472 | —- | M] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/17 12:23:09 | 000,002,411 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/17 10:34:15 | 000,009,594 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/15 15:44:24 | 000,069,916 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume E Task.job
[2011/01/13 17:07:50 | 000,566,417 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume C Task.job
[2011/01/08 01:28:04 | 000,001,956 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/07 07:33:54 | 000,001,738 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\GoodSync.lnk
[2011/01/03 17:19:37 | 000,002,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/28 21:08:24 | 000,001,542 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/25 07:43:47 | 000,002,533 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/12/23 20:58:01 | 000,341,123 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/19 21:34:19 | 000,069,432 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:35 | 000,359,929 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 20:16:50 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 08:11:34 | 000,000,204 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:32 | 000,000,202 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:07:58 | 000,196,736 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/19 07:13:59 | 000,000,294 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/14 17:32:40 | 000,002,411 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/13 17:07:50 | 000,566,417 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/08 01:28:04 | 000,001,956 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/02 23:14:26 | 000,002,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/31 10:24:04 | 000,009,594 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2010/12/28 21:08:23 | 000,001,542 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/24 14:37:57 | 000,001,620 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/23 20:58:00 | 000,341,123 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2010/12/20 21:38:06 | 000,002,772 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.Exception.log
[2010/12/20 21:36:29 | 000,003,315 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\PreferencePane
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plugins
[2010/12/03 19:38:54 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2010/12/03 19:36:39 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Pop Flute
[2010/12/03 19:36:38 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plug-In Settings
[2010/12/03 19:36:38 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2010/08/17 22:08:09 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/06 21:53:34 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/10/05 09:43:43 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2009/07/27 21:02:41 | 000,055,809 | —- | C] () – C:\WINDOWS\CP-FPCOS100.dll
[2009/07/06 16:16:35 | 000,008,086 | RHS- | C] () – C:\Program Files\uninstall.log
[2009/05/31 18:06:46 | 000,013,020 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Comma Separated Values (Windows).CAL
[2009/05/08 06:34:43 | 008,673,792 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2008/12/12 14:04:46 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/12/12 14:03:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/10/30 16:03:23 | 000,000,110 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/04/15 21:46:29 | 000,018,790 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2008/04/03 22:32:06 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2008/02/11 08:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 08:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/08 12:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/21 00:40:51 | 000,002,711 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2007/11/17 17:55:09 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/10/07 14:32:50 | 000,000,166 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/08/04 16:26:03 | 000,000,513 | —- | C] () – C:\WINDOWS\pu32i.ini
[2007/07/27 13:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 13:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/04/02 22:43:38 | 000,000,000 | —- | C] () – C:\WINDOWS\Hammerhead.INI
[2007/03/13 17:30:02 | 000,003,102 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/10 15:02:41 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/03/10 14:52:59 | 000,039,790 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/01/27 12:22:29 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\DymoQBInst.dll
[2007/01/27 12:20:45 | 000,000,056 | —- | C] () – C:\WINDOWS\Addrfixr.ini
[2007/01/27 12:20:45 | 000,000,036 | —- | C] () – C:\WINDOWS\iltwain.ini
[2007/01/27 12:20:27 | 000,007,803 | —- | C] () – C:\WINDOWS\System32\dymourl.ini
[2007/01/27 12:18:31 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\DYMOCFG.DLL
[2007/01/27 12:18:31 | 000,002,560 | —- | C] () – C:\WINDOWS\System32\lmmonres.dll
[2007/01/03 10:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 10:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 10:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/15 23:44:07 | 000,000,136 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\fusioncache.dat
[2006/12/15 17:51:18 | 000,000,982 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\.googlewebacchosts
[2006/12/10 19:04:37 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/03 01:34:49 | 000,041,472 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 23:42:47 | 000,000,088 | —- | C] () – C:\WINDOWS\gbsaver.ini
[2006/12/02 22:31:25 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\dfxg14.dll
[2006/12/02 18:06:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\dm.ini
[2006/12/02 18:06:08 | 000,000,676 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\AdobeDLM.log
[2006/12/02 16:50:42 | 000,000,170 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/12/02 16:46:56 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/02 16:15:20 | 000,009,255 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/12/02 15:13:23 | 000,002,582 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/02 13:51:58 | 000,000,549 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2006/12/02 13:37:31 | 000,000,038 | —- | C] () – C:\WINDOWS\System32\w3url.dll
[2006/12/02 13:01:24 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/11/28 15:06:28 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/11/28 14:44:06 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/09/18 13:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006/09/18 13:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2006/05/02 17:38:24 | 000,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2005/12/05 18:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 11:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,481 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:51:10 | 000,025,741 | —- | C] () – C:\WINDOWS\System32\aavr3h.dll
[2004/08/10 12:51:10 | 000,015,365 | —- | C] () – C:\WINDOWS\System32\llbstp.dll
[2004/08/04 05:00:00 | 000,018,705 | —- | C] () – C:\WINDOWS\System32\nusvg7cc.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2010/08/31 16:23:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2008/12/12 13:53:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/12/02 19:13:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/05/17 18:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2009/07/06 16:16:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DYMO
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/03/15 21:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EUFJFLUFYG
[2010/10/10 21:51:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/09/01 06:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2009/07/13 15:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2010/12/03 19:36:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Guides
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hybrid Chords
[2008/12/05 18:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software
[2006/12/28 20:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2010/10/31 15:19:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/01/19 00:35:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/11/13 15:59:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/09/07 06:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
[2009/11/05 18:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2007/10/21 12:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/12/01 17:34:40 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2007/08/27 08:36:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MipKukSoft
[2009/04/21 22:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/12/03 19:37:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2009/11/15 11:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/07/06 20:27:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2010/10/10 21:50:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/03/09 17:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/07/26 23:03:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/04/04 22:23:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/01/08 01:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2006/12/02 15:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/12/12 14:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/10/30 16:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2011/01/03 21:55:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2009/07/11 09:59:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2007/12/20 09:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/29 23:03:00 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\System Restore
[2009/06/22 17:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/28 16:38:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/04/27 14:50:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/22 18:49:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VMGJFLUFYG
[2009/06/25 21:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WindSolutions
[2007/10/26 07:21:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/12/10 18:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YoWindow
[2010/05/22 08:08:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 16:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/19 13:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/10/11 18:41:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F29F2260-20C9-49D5-9651-71A8580940BF}
[2009/01/03 17:04:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F40E9D30-5DFC-4B21-BFDB-A5CDEE6440A6}
[2009/01/03 17:03:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2009/10/19 15:07:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2007/06/02 16:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\.purple
[2008/05/20 17:11:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\acccore
[2010/10/30 16:44:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Amazon
[2011/01/16 20:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2008/10/31 06:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Buddi
[2009/01/02 14:37:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Canon
[2010/08/17 22:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive
[2010/06/15 06:49:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CheckPoint
[2009/08/21 17:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/11/14 01:32:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/06/25 21:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CopyTransPhoto
[2009/05/07 06:39:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Dealio
[2010/09/25 21:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\DriverCure
[2010/06/27 16:50:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\eMusic
[2008/12/28 00:42:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Facebook
[2008/07/29 23:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FireShot
[2008/03/24 21:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Flock
[2006/12/02 16:08:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FotoWire
[2010/06/15 20:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FoxyTunes
[2010/06/14 11:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GARMIN
[2011/01/19 00:43:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GoodSync
[2007/06/01 18:19:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\gtk-2.0
[2007/01/08 18:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ICAClient
[2009/06/19 21:42:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iLike
[2007/10/07 13:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Image Zone Express
[2010/10/19 16:54:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iolo
[2010/08/06 21:41:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\J River
[2007/08/27 08:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Kybtec Software
[2007/03/16 06:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Launchy
[2009/06/30 16:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Leadertech
[2009/05/31 15:18:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MailFrontier
[2007/08/27 18:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MipKukSoft
[2007/10/16 21:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MSNInstaller
[2006/12/02 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Musicmatch
[2008/12/12 14:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\NewSoft
[2009/05/30 07:49:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\OfficeUpdate12
[2007/10/12 16:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Opera
[2010/09/25 21:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ParetoLogic
[2009/01/02 16:08:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Pogo Games
[2010/02/05 07:49:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Portalarium
[2007/10/07 12:48:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Printer Info Cache
[2010/12/20 21:39:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Research In Motion
[2007/12/08 17:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoadRunner
[2011/01/15 08:02:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2008/12/12 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ScanSoft
[2009/05/07 06:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Search Settings
[2007/07/17 06:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\SlimBrowser
[2008/05/21 22:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Snapfish
[2010/06/18 22:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Songbird2
[2007/11/17 17:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Teleca
[2007/09/24 15:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\TomTom
[2007/07/19 17:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Uniblue
[2008/07/10 20:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Windows Desktop Search
[2009/06/25 21:30:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WindSolutions
[2010/05/28 06:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WinPatrol
[2010/12/10 18:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\YoWindow
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume C Task.job
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume E Task.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\GoodSync - Quicken.job
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Daily E.job
[2007/07/21 03:26:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Once E.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/29 21:50:17 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/04/28 15:55:01 | 000,031,861 | —- | M] () – C:\ComboFix.txt
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/11/28 14:45:30 | 000,004,478 | RH– | M] () – C:\dell.sdr
[2008/10/31 18:45:10 | 000,000,051 | —- | M] () – C:\EventLOG.txt
[2010/11/12 14:17:29 | 000,000,081 | —- | M] () – C:\FDeClient_Start.log
[2010/02/17 00:38:47 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2010/08/12 06:37:56 | 000,000,255 | —- | M] () – C:\INSTALL.LOG
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/09/07 22:28:44 | 000,001,375 | -H– | M] () – C:\IPH.PH
[2009/04/26 16:10:37 | 000,006,608 | —- | M] () – C:\JavaRa.log
[2006/12/02 16:06:42 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/17 20:00:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/19 08:09:12 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/05/31 14:08:51 | 000,000,805 | —- | M] () – C:\rollback.ini
[2006/12/07 07:26:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2007/03/16 06:16:59 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2007/03/17 18:59:23 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2007/03/23 23:07:35 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2007/04/16 23:02:21 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2007/04/20 16:17:08 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2007/04/21 16:18:54 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2007/04/28 23:51:16 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/03/27 12:21:57 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2006/12/07 07:26:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2007/03/16 06:16:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2007/03/17 18:59:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2007/03/23 23:07:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2007/04/16 23:02:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2007/04/20 16:17:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2007/04/21 16:18:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2007/04/28 23:51:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/03/27 12:21:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2007/07/23 22:03:57 | 000,000,033 | —- | M] () – C:\wizard.txt
[2009/04/20 22:21:36 | 000,000,152 | —- | M] () – C:\YServer.txt
[11 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/02/17 00:54:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/16 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8Z.DLL
[2007/04/16 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8Z.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/07/18 13:34:32 | 000,586,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2007/07/28 15:13:13 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2009/07/06 16:19:54 | 000,008,086 | RHS- | M] () – C:\Program Files\uninstall.log
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/02/16 19:31:05 | 004,194,304 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/16 21:50:47 | 000,262,144 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2010/02/16 19:31:05 | 048,758,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/16 19:31:05 | 006,553,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/06 16:20:01 | 000,000,226 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Create & Print Home.url
[2010/02/17 20:15:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/12/02 12:24:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/06/14 16:37:14 | 000,000,077 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
[2010/08/31 17:04:24 | 008,134,344 | —- | M] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-13 03:14:37
========== Alternate Data Streams ==========
@Alternate Data Stream - 185 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D0C22DC
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A41BE14
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EFDF5FB
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE9A3E83
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
OTL Extras logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32
Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.hta [@ = htafile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 9.0 Data Manager
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service – (Check Point Software Technologies LTD)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb – (Orb Networks, Inc.)
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray – (Orb Networks)
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – (Orb Networks)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe" = C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe:*:Enabled:Media Player
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 11.0 Data Manager – (Intuit, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03DF638A-D61C-4893-B8B9-845900C03163}" = TurboTax 2010 wnyiper
"{058B32E2-6310-4359-B2D4-1988390C3B83}" = Broadcom Advanced Control Suite
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{061BBC42-C5A9-4F82-AD24-EAE562968D0B}" = QuickBooks
"{0700E22B-A440-40A5-BD20-04BF618CA0F9}" = QuickBooks Enterprise Solutions: Retail Edition 10.0
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX310_series" = Canon MX310 series
"{11E0AC7D-6840-4F67-865F-EE1C13D28C38}" = QuickBooks Enterprise Solutions: Retail Edition 11.0
"{1EFCFB56-B8BB-4834-AE8E-29EE73FF8611}" = QuickBooks
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{321F110F-E26B-4E33-8F13-30A8C79DB687}" = Desk Drive
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}" = MSN Toolbar
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{37C5A56A-00EA-347B-B7A1-5628BED56702}" = Google Talk Plugin
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3AC785C0-EAA2-012B-AE3B-000000000000}" = TurboTax 2009 wneiper
"{3B8186F0-EAA2-012B-AE69-000000000000}" = TurboTax 2009 wnyiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53C398FE-CD56-412E-B3C7-B27F4B8B07D1}" = Microsoft IntelliType Pro 5.3
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{5658CE44-2822-45C9-A5C0-F93AB4682BBF}" = Document eSort Components
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{598420E8-E9F9-4FAE-9B6C-599FDF2F611A}" = BlackBerry App World Browser Plugin
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5EFA4EA3-0604-458C-A06D-485F6B2724C9}" = PrintKey-Pro v1.05
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73006B34-9743-4A39-AC37-38EDFCEB6DCE}" = Adobe Product/Adobe Studio Update 10/2001
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113269180}" = Mahjong Garden Deluxe
"{830C1687-F55F-45C1-AD2B-405824DC65DB}" = Network Recording Player
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9021848E-F315-44C7-8D45-3B16162AA73A}" = TurboTax 2010 wneiper
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91190409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Publisher 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-004E-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector 32-bit
"{95140000-007C-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Facebook 32-bit
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B335897-6FBC-46B4-94B9-C159DF25AD51}" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"{9F9BE2A8-2FA2-438E-934B-6F237B641167}" = Cooliris for Internet Explorer
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}" = Microsoft SQL Server VSS Writer
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}" = U3Launcher
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0904}" = Microsoft Digital Image Pro 9
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}" = ArcSoft Panorama Maker 5
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA0092C2-C0FE-40DA-A79E-E4C0FCA129F9}" = Intuit Entitlement Client
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Add-Remove Manager_is1" = Add-Remove Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AI RoboForm" = RoboForm 7-1-6 (All Users)
"AIM_7" = AIM 7
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"Audit Support Center" = Audit Support Center 1.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Bejeweled Blitz" = Bejeweled Blitz
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"Canon MX310 series User Registration" = Canon MX310 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"Clickster-Pro223" = Clickster-Pro
"Clickster-Pro224" = Clickster-Pro
"Clickster-Pro2241" = Clickster-Pro
"Creative Media Lite" = Creative Media Lite
"Defraggler" = Defraggler
"DYMO Label Software" = DYMO Label Software
"DYMO Label v.8" = DYMO Label v.8
"DYMO QuickBooks Add-In" = DYMO QuickBooks Add-In
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0033)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"EsetOnlineScanner" = ESET Online Scanner
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"FoxyTunesForInternetExplorer" = FoxyTunes for Internet Explorer
"Google Updater" = Google Updater
"Google Video Uploader" = Google Video Uploader
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Logitech Print Service" = Logitech Print Service
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mastering Intuit QuickBooks Enterprise Solutions 11.0" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"Media Center 12" = Media Center 12
"Media Center 15" = Media Center 15
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Sunbird (0.9)" = Mozilla Sunbird (0.9)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MP3 Player Recovery Tool_is1" = MP3 Player Recovery Tool
"MP3 WAV Converter 4.13" = MP3 WAV Converter 4.13
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MuVoT200UG" = Creative MuVo T200 User's Guide
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Orb" = Winamp Remote
"PC Matic_is1" = PC Matic 1.0.0.0
"PC Pitstop Disk MD_is1" = PC Pitstop Disk MD 2.0
"PC Pitstop Optimize2_is1" = PC Pitstop Optimize2 2.0
"PC Tune-Up" = PC Tune-Up
"PictureIt_v9" = Microsoft Digital Image Pro 9
"QcDrv" = Logitech® Camera Driver
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.91
"SearchAssist" = SearchAssist
"Shockwave" = Shockwave
"ShortKeys 2" = ShortKeys 2
"ShortKeys 3" = ShortKeys 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Songbird-release-1800" = Songbird 1.8.0 (Build 1800)
"STANDARDR" = Microsoft Office Standard 2007
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"Unlocker" = Unlocker 1.8.9
"Update Service" = Update Service
"VisualRoute Lite Edition" = VisualRoute Lite Edition
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"Yahoo! Widget Engine" = Yahoo! Widgets
"yowindow" = YoWindow
"ZoneAlarm Security Suite" = ZoneAlarm Security Suite
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
"Zune" = Zune
"Zynga Toolbar" = Zynga Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Chromium" = Chromium
"CNET TechTracker" = CNET TechTracker
"GmailPopTroubleshooter" = Gmail POP Troubleshooter
"LastPass" = LastPass (uninstall only)
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/19/2011 1:45:57 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 8:21:15 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
Error - 1/19/2011 9:13:55 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand
Error - 1/19/2011 9:23:34 PM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog
[ OSession Events ]
Error - 10/9/2008 3:19:31 PM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6323.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/14/2011 1:52:08 AM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 164
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 1/19/2011 1:41:04 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 1:41:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/19/2011 2:22:37 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.
Error - 1/19/2011 2:22:57 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.
Error - 1/19/2011 2:23:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 2:23:13 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/19/2011 9:10:16 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.
Error - 1/19/2011 9:11:25 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.
Error - 1/19/2011 9:11:40 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008
Error - 1/19/2011 9:11:52 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
< End of report >
Thanks for your help