aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-26 20:41:57
—————————–
20:41:57.212 OS Version: Windows 5.1.2600 Service Pack 3
20:41:57.212 Number of processors: 1 586 0x209
20:41:57.222 ComputerName: HELEN-LAPTOPXP UserName: jhitchen
20:41:59.646 Initialize success
20:42:15.649 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
20:42:15.649 Disk 0 Vendor: FUJITSU_MHT2060AH 006C Size: 57231MB BusType: 3
20:42:17.722 Disk 0 MBR read successfully
20:42:17.722 Disk 0 MBR scan
20:42:17.722 Disk 0 Windows XP default MBR code
20:42:19.815 Disk 0 scanning sectors +117194175
20:42:19.845 Disk 0 scanning C:\WINDOWS\system32\drivers
20:42:31.592 Service scanning
20:42:33.234 Disk 0 trace - called modules:
20:42:33.254 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
20:42:33.254 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f7bab8]
20:42:33.254 3 CLASSPNP.SYS[f86b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x82fa1b00]
20:42:33.264 Scan finished successfully
20:42:57.689 Disk 0 MBR has been saved successfully to "E:\MBR.dat"
20:42:57.719 The log file has been saved successfully to "E:\aswMBR.txt"
OTL logfile created on: 5/26/2011 8:45:47 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\jhitchen\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.33 Mb Total Physical Memory | 97.34 Mb Available Physical Memory | 19.07% Memory free
1.22 Gb Paging File | 0.78 Gb Available in Paging File | 64.03% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.34 Gb Total Space | 17.15 Gb Free Space | 32.77% Space Free | Partition Type: NTFS
Drive D: | 2.56 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 7.49 Gb Total Space | 3.25 Gb Free Space | 43.37% Space Free | Partition Type: FAT32
Computer Name: HELEN-LAPTOPXP | User Name: jhitchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\jhitchen\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\jhitchen\Application Data\Microsoft\conhost.exe ()
PRC - C:\Documents and Settings\jhitchen\Local Settings\Temp\csrss.exe ()
PRC - C:\Documents and Settings\jhitchen\Application Data\dwm.exe ()
PRC - C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe ()
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\DriverUpdate\DriverUpdate.exe (SlimWare Utilities, Inc.)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files\IntelliAdmin4\Agent\Agent32.exe ()
PRC - C:\WINDOWS\IntelliAdminRC3\Agent32.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\jhitchen\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\IObit\IObit Security 360\is360mon.dll (IObit)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (MySQL) – C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe ()
SRV - (nlsX86cc) – C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (IntelliAdminRC4) – C:\Program Files\IntelliAdmin4\Agent\Agent32.exe ()
SRV - (IntelliAdminRC3) – C:\WINDOWS\IntelliAdminRC3\Agent32.exe ()
SRV - (CcmExec) – C:\WINDOWS\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SWDUMon) – C:\WINDOWS\system32\drivers\SWDUMon.sys ()
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (RsFx0150) – C:\WINDOWS\system32\drivers\RsFx0150.sys (Microsoft Corporation)
DRV - (NxDrv) – C:\WINDOWS\system32\drivers\NxDrv.sys (SonicWALL Inc.)
DRV - (SSLDrv) – C:\WINDOWS\system32\drivers\SSLDrv.sys (SonicWALL Inc.)
DRV - (prepdrvr) – C:\WINDOWS\system32\CCM\PrepDrv.sys (Microsoft Corporation)
DRV - (SEM43XX) – C:\WINDOWS\system32\drivers\semwl5.SYS (Broadcom Corporation)
DRV - (SEMWModem) – C:\WINDOWS\system32\drivers\GCXX.sys (Broadcom Corporation)
DRV - (SEMWWNIC) – C:\WINDOWS\system32\drivers\GCXXNet.sys (Broadcom Corporation)
DRV - (Sony_EricssonWWSC) – C:\WINDOWS\system32\drivers\GCXXSC.sys (Broadcom Corporation)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (RT2500) – C:\WINDOWS\system32\drivers\RT2500.sys (Ralink Technology Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.crabtree-evelyn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55515
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://google.ca/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:4.0.0.78
FF - prefs.js..extensions.enabledItems: [removed]:3.3.433
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:7.2.8
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55515
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 14:07:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/26 15:54:47 | 000,000,000 | —D | M]
[2010/12/18 13:39:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jhitchen\Application Data\Mozilla\Extensions
[2011/04/26 13:00:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jhitchen\Application Data\Mozilla\Firefox\Profiles\ewk4c1ve.default\extensions
[2011/01/14 12:15:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\jhitchen\Application Data\Mozilla\Firefox\Profiles\ewk4c1ve.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/20 14:33:25 | 000,000,000 | —D | M] (ActiveGS) – C:\Documents and Settings\jhitchen\Application Data\Mozilla\Firefox\Profiles\ewk4c1ve.default\extensions\[removed]
[2010/12/23 18:55:04 | 000,000,000 | —D | M] (NetExtender Launcher) – C:\Documents and Settings\jhitchen\Application Data\Mozilla\Firefox\Profiles\ewk4c1ve.default\extensions\[removed]
[2010/12/18 13:38:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2010/12/13 19:06:30 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/29 14:07:40 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/26 15:54:34 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2001/08/23 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\jhitchen\Application Data\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [DriverUpdate] C:\Program Files\DriverUpdate\DriverUpdate.exe (SlimWare Utilities, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
F3 - HKCU WinNT: Load - (C:\DOCUME~1\jhitchen\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\jhitchen\Local Settings\Temp\csrss.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - File not found
O15 - HKCU\..Trusted Domains: ceu ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.ca ([retail] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.co.uk ([retail] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.co.uk ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([barracuda] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([emea] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([imagenet] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([otrs] https in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([printers] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([qcglobal] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([retail] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([sharepoint] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: crabtree-evelyn.com.au ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: ctree.net ([ceu] https in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1292274449669 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1292338430639 (MUWebControl Class)
O16 - DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30}
https://ssl-vpn.crabtree-evelyn.com/NELX.cab (NELaunchCtrl Class)
O16 - DPF: {79D6214F-CFCE-480F-9901-27950E78F1E6}
https://ssl-vpn.crabtree-evelyn.com/MLWebCacheCleaner.cab (WebCacheCleaner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {A6A216EB-4F7C-11D5-8438-0000B456BA3D}
https://ssl-vpn.crabtree-evelyn.com/go/http….1/matn5250.cab (Matn5250 Control)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ctree.net
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\jhitchen\Application Data\dwm.exe) - C:\Documents and Settings\jhitchen\Application Data\dwm.exe ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/19 18:55:21 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/10/05 18:36:26 | 000,465,408 | R— | M] (BioWare Corp.) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2005/10/07 13:24:42 | 000,000,547 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{09e00310-6a36-11d9-9307-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{09e00310-6a36-11d9-9307-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{09e00310-6a36-11d9-9307-806d6172696f}\Shell\AutoRun\command - "" = D:\autorun.exe – [2005/10/05 18:36:26 | 000,465,408 | R— | M] (BioWare Corp.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe" -a "%1" %* ()
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe" -a "%1" %* ()
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (30412908236111872)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/26 20:41:21 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\jhitchen\Desktop\aswMBR.exe
[2011/05/26 20:41:08 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jhitchen\Desktop\OTL.exe
[2011/05/26 20:40:35 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/05/26 13:14:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\jhitchen\Desktop\HiJackThis.exe
[2011/05/24 11:31:56 | 000,260,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSFLXGRD.OCX
[2011/05/24 11:31:56 | 000,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\RICHTX32.OCX
[2011/05/24 11:31:56 | 000,067,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\SYSINFO.OCX
[2011/05/24 11:27:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HexWar
[2011/05/24 11:27:45 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\Application Data\HexWar Launcher
[2011/05/20 19:03:49 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\BlackBerry
[2011/05/20 19:00:06 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\Local Settings\Application Data\Research In Motion
[2011/05/20 19:00:03 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\Application Data\Research In Motion
[2011/05/20 18:56:16 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsgXP_2k3.dll
[2011/05/20 18:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\BlackBerry
[2011/05/20 18:53:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/05/20 18:52:48 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2011/05/20 18:52:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2011/05/20 18:18:52 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2011/05/16 11:46:27 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Knights of Columbus
[2011/05/16 11:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Cover Letters
[2011/05/14 22:56:33 | 000,188,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WINGDE.DLL
[2011/05/14 22:56:33 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WING.DLL
[2011/05/14 22:56:33 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING32.DLL
[2011/05/14 22:56:33 | 000,006,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WINGDIB.DRV
[2011/05/14 22:56:33 | 000,005,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WINGPAL.WND
[2011/05/04 23:34:59 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Visual Studio 2005
[2011/05/04 22:54:00 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\Local Settings\Application Data\Microsoft_Corporation
[2011/05/04 22:23:03 | 000,047,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\perf-MSSQL10_50.SQLEXPRESS-sqlagtctr.dll
[2011/05/04 22:20:06 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Integration Services Script Component
[2011/05/04 22:19:08 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Integration Services Script Task
[2011/05/04 22:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\SQL Server Management Studio
[2011/05/04 22:16:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RsFx
[2011/05/04 22:10:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft SQL Server 2008
[2011/05/04 22:09:23 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\My Documents\Visual Studio 2008
[2011/05/04 22:06:37 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SDKs
[2011/05/04 22:06:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 9.0
[2011/05/04 22:06:06 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/05/04 22:05:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/05/04 21:43:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft SQL Server 2008 R2
[2011/05/04 21:39:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server
[2011/05/02 23:56:52 | 000,000,000 | —D | C] – C:\I-Magic
[2011/05/02 23:56:29 | 000,283,648 | —- | C] (Stirling Technologies, Inc.) – C:\WINDOWS\uninst.exe
[2011/04/29 12:08:40 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\Application Data\gtk-2.0
[2011/04/29 11:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Game Booster
[2011/04/28 18:32:11 | 000,000,000 | —D | C] – C:\Documents and Settings\jhitchen\.dia
[2011/04/28 18:31:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Dia
[2011/04/28 18:31:16 | 000,000,000 | —D | C] – C:\Program Files\Dia
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/26 20:50:13 | 000,011,252 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/26 20:50:12 | 000,011,252 | -HS- | M] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/26 20:42:46 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/26 20:40:22 | 000,011,232 | —- | M] () – C:\WINDOWS\System32\drivers\SWDUMon.sys
[2011/05/26 20:40:15 | 000,000,453 | —- | M] () – C:\WINDOWS\SMSCFG.ini
[2011/05/26 20:39:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/26 20:39:40 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/05/26 20:39:39 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/05/26 20:39:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/26 20:34:50 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jhitchen\Desktop\OTL.exe
[2011/05/26 20:34:38 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\jhitchen\Desktop\aswMBR.exe
[2011/05/26 17:46:29 | 000,003,132 | —- | M] () – C:\Documents and Settings\jhitchen\Application Data\69C2.47C
[2011/05/26 12:48:49 | 000,186,880 | —- | M] () – C:\Documents and Settings\jhitchen\Application Data\dwm.exe
[2011/05/26 12:48:22 | 000,339,968 | -HS- | M] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe
[2011/05/24 13:15:53 | 000,573,942 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/24 13:15:53 | 000,115,184 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/24 11:31:59 | 000,001,208 | —- | M] () – C:\WINDOWS\unins000.dat
[2011/05/24 11:31:50 | 000,695,578 | —- | M] () – C:\WINDOWS\unins000.exe
[2011/05/24 11:27:48 | 000,000,888 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HexWar Game Launcher.lnk
[2011/05/20 19:35:23 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/20 19:11:08 | 000,012,800 | —- | M] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 18:56:48 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/05/20 18:56:41 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/05/20 18:53:46 | 000,001,956 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2011/05/20 07:45:47 | 000,474,300 | —- | M] () – C:\Documents and Settings\jhitchen\Desktop\Knightly News 05-2011.pdf
[2011/05/17 07:43:49 | 000,000,088 | —- | M] () – C:\WINDOWS\CwbRmDir.bat
[2011/05/14 22:56:22 | 000,000,224 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2011/05/04 15:11:21 | 000,006,231 | —- | M] () – C:\Documents and Settings\jhitchen\Desktop\Apr 2011 CCHMPA Accounts.pdf
[2011/04/29 12:11:33 | 000,000,218 | —- | M] () – C:\Documents and Settings\jhitchen\.recently-used.xbel
[2011/04/29 12:07:51 | 000,000,751 | —- | M] () – C:\Documents and Settings\jhitchen\Desktop\Dia.lnk
[2011/04/29 11:30:00 | 000,000,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Switch to Gaming Mode.lnk
[2011/04/29 11:30:00 | 000,000,809 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Game Booster.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/26 12:48:49 | 000,186,880 | —- | C] () – C:\Documents and Settings\jhitchen\Application Data\dwm.exe
[2011/05/26 12:48:25 | 000,011,262 | -HS- | C] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/26 12:48:25 | 000,011,262 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4256o56y1a8o6x33021iv38cljbeoo2456lvgt
[2011/05/26 12:48:22 | 000,339,968 | -HS- | C] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe
[2011/05/26 12:48:21 | 000,003,132 | —- | C] () – C:\Documents and Settings\jhitchen\Application Data\69C2.47C
[2011/05/24 11:31:56 | 000,695,578 | —- | C] () – C:\WINDOWS\unins000.exe
[2011/05/24 11:31:56 | 000,001,208 | —- | C] () – C:\WINDOWS\unins000.dat
[2011/05/24 11:27:48 | 000,000,888 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HexWar Game Launcher.lnk
[2011/05/21 00:22:58 | 000,168,176 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/05/20 18:56:48 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/05/20 18:56:41 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/05/20 18:53:46 | 000,001,956 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2011/05/20 07:45:36 | 000,474,300 | —- | C] () – C:\Documents and Settings\jhitchen\Desktop\Knightly News 05-2011.pdf
[2011/05/17 07:43:49 | 000,000,088 | —- | C] () – C:\WINDOWS\CwbRmDir.bat
[2011/05/14 22:56:07 | 000,000,224 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2011/05/04 15:11:17 | 000,006,231 | —- | C] () – C:\Documents and Settings\jhitchen\Desktop\Apr 2011 CCHMPA Accounts.pdf
[2011/04/29 12:11:33 | 000,000,218 | —- | C] () – C:\Documents and Settings\jhitchen\.recently-used.xbel
[2011/04/29 12:07:51 | 000,000,751 | —- | C] () – C:\Documents and Settings\jhitchen\Desktop\Dia.lnk
[2011/04/29 11:30:00 | 000,000,821 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Switch to Gaming Mode.lnk
[2011/04/29 11:30:00 | 000,000,809 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Game Booster.lnk
[2011/04/26 13:09:47 | 000,011,232 | —- | C] () – C:\WINDOWS\System32\drivers\SWDUMon.sys
[2011/04/25 16:42:33 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/04/25 16:42:32 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/04/10 18:59:01 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/06 12:04:52 | 000,000,407 | —- | C] () – C:\WINDOWS\MORDOR.INI
[2011/04/06 12:04:43 | 000,002,573 | —- | C] () – C:\WINDOWS\WAVEMIX.INI
[2011/04/06 12:04:26 | 000,090,702 | —- | C] () – C:\WINDOWS\SETUP1.EXE
[2011/04/02 22:03:50 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2011/02/22 20:13:08 | 000,012,800 | —- | C] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/02 14:48:35 | 000,000,131 | —- | C] () – C:\Documents and Settings\jhitchen\Local Settings\Application Data\fusioncache.dat
[2010/12/18 13:38:55 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/16 19:27:58 | 000,508,224 | —- | C] () – C:\WINDOWS\System32\ICCProfiles.dll
[2008/03/18 16:52:33 | 000,000,453 | —- | C] () – C:\WINDOWS\SMSCFG.ini
[2006/07/14 15:35:46 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\WBCustomizer.dll
[2005/01/21 13:05:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/01/19 18:57:45 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/01/19 18:52:25 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/01/19 12:29:05 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/01/19 12:28:08 | 000,281,336 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 08:00:00 | 000,573,942 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 08:00:00 | 000,115,184 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 08:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/04/29 11:29:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/04/08 21:47:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MySQL
[2010/12/28 02:29:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2011/01/02 13:45:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/05/20 18:53:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/04/21 21:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/12/28 02:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\Downloaded Installations
[2010/12/28 02:17:21 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\Foxit Software
[2011/04/29 12:08:59 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\gtk-2.0
[2011/05/24 12:46:10 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\HexWar Launcher
[2011/04/29 11:57:42 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\IObit
[2010/12/14 21:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\Leadertech
[2010/12/28 16:57:02 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\Nitro PDF
[2011/05/20 19:02:58 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\Research In Motion
[2011/04/21 21:23:43 | 000,000,000 | —D | M] – C:\Documents and Settings\jhitchen\Application Data\RoboForm
[2011/05/26 20:39:40 | 000,000,276 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/05/26 20:42:46 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/05/26 20:39:39 | 000,000,286 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/01/19 18:55:21 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/01/19 19:19:25 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2005/01/19 18:55:21 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2005/01/19 18:55:21 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/01/19 18:55:21 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2005/01/19 19:12:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/14 09:46:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/26 20:39:25 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2008/12/22 13:08:27 | 000,000,557 | —- | M] () – C:\Pltfrm2.ini
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/01/19 18:54:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/05/26 13:11:27 | 000,176,128 | —- | M] () – C:\Documents and Settings\jhitchen\Application Data\Microsoft\conhost.exe
[2008/11/21 10:14:00 | 000,001,538 | -H– | M] () – C:\Documents and Settings\jhitchen\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/01/19 12:27:10 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/01/19 12:27:10 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/01/19 12:27:10 | 000,397,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/14 10:00:32 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/05 12:34:56 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\jhitchen\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/11/05 12:34:54 | 000,000,079 | —- | M] () – C:\Documents and Settings\jhitchen\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/05/26 20:34:38 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\jhitchen\Desktop\aswMBR.exe
[2011/02/23 22:26:30 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jhitchen\Desktop\HiJackThis.exe
[2011/05/26 20:34:50 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jhitchen\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008/11/05 12:34:54 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\jhitchen\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/12/13 17:08:34 | 000,021,439 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/05/26 20:44:19 | 000,049,152 | —- | M] () – C:\Documents and Settings\jhitchen\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
"AUOptions" = 3
"ScheduledInstallDay" = 7
"ScheduledInstallTime" = 16
"NoAutoRebootWithLoggedOnUsers" = 1
"UseWUServer" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-14 17:04:14
< End of report >
OTL Extras logfile created on: 5/26/2011 8:45:47 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\jhitchen\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.33 Mb Total Physical Memory | 97.34 Mb Available Physical Memory | 19.07% Memory free
1.22 Gb Paging File | 0.78 Gb Available in Paging File | 64.03% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.34 Gb Total Space | 17.15 Gb Free Space | 32.77% Space Free | Partition Type: NTFS
Drive D: | 2.56 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 7.49 Gb Total Space | 3.25 Gb Free Space | 43.37% Space Free | Partition Type: FAT32
Computer Name: HELEN-LAPTOPXP | User Name: jhitchen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Documents and Settings\jhitchen\Local Settings\Application Data\njq.exe ()
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1
"Enabled" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\IntelliAdmin\iadmin.exe:172.16.7.0/24,172.16.5.0/24,172.16.10.0/24,172.16.11.0/24,172.16.13.0/24,172.16.0.0/22:enabled:IntelliAdmin Remote Control Server" = C:\WINDOWS\IntelliAdmin\iadmin.exe:172.16.7.0/24,172.16.5.0/24,172.16.10.0/24,172.16.11.0/24,172.16.13.0/24,172.16.0.0/22:enabled:IntelliAdmin Remote Control Server
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1
"Enabled" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"425508:UDP:172.16.7.0/24,172.16.5.0/24,172.16.10.0/24,172.16.11.0/24,172.16.13.0/24,172.16.0.0/22:enabled:Etrust Discovery" = 425508:UDP:172.16.7.0/24,172.16.5.0/24,172.16.10.0/24,172.16.11.0/24,172.16.13.0/24,172.16.0.0/22:enabled:Etrust Discovery
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings]
"AllowOutboundDestinationUnreachable" = 0
"AllowOutboundSourceQuench" = 0
"AllowRedirect" = 0
"AllowInboundEchoRequest" = 1
"AllowInboundRouterRequest" = 0
"AllowOutboundTimeExceeded" = 0
"AllowOutboundParameterProblem" = 0
"AllowInboundTimestampRequest" = 0
"AllowInboundMaskRequest" = 0
"AllowOutboundPacketTooBig" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
"Enabled" = 1
"RemoteAddresses" = localsubnet,172.16.7.0/24,localsubnet,172.16.5.0/24,localsubnet,172.16.10.0/24,localsubnet,172.16.11.0/24,localsubnet,172.16.13.0/24,localsubnet,172.16.7.20/24,localsubnet,172.16.0.0/22
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = localsubnet,172.16.7.0/24,localsubnet,172.16.5.0/24,localsubnet,172.16.10.0/24,localsubnet,172.16.11.0/24,localsubnet,172.16.13.0/24,localsubnet,172.16.7.20/24,localsubnet,172.16.0.0/22
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = localsubnet,172.16.7.0/24,localsubnet,172.16.5.0/24,localsubnet,172.16.10.0/24,localsubnet,172.16.11.0/24,localsubnet,172.16.13.0/24,localsubnet,172.16.7.20/24,localsubnet,172.16.0.0/22
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"57302:TCP" = 57302:TCP:*:Enabled:Pando Media Booster
"57302:UDP" = 57302:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"57302:TCP" = 57302:TCP:*:Enabled:Pando Media Booster
"57302:UDP" = 57302:UDP:*:Enabled:Pando Media Booster
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\IntelliAdminRC3\Agent32.exe" = C:\WINDOWS\IntelliAdminRC3\Agent32.exe:*:Enabled:IntelliAdmin Remote Control Agent – ()
"C:\Program Files\IntelliAdmin4\Agent\Agent32.exe" = C:\Program Files\IntelliAdmin4\Agent\Agent32.exe:*:Enabled:IntelliAdmin Remote Control 4 – ()
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe" = C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe:*:Enabled:lotroclient – (Turbine, Inc.)
"C:\WINDOWS\IntelliAdminRC3\Agent32.exe" = C:\WINDOWS\IntelliAdminRC3\Agent32.exe:*:Enabled:IntelliAdmin Remote Control Agent – ()
"C:\Program Files\IntelliAdmin4\Agent\Agent32.exe" = C:\Program Files\IntelliAdmin4\Agent\Agent32.exe:*:Enabled:IntelliAdmin Remote Control 4 – ()
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{020617D7-2F72-4D02-BF59-A5CBC1761177}" = SQL Server 2008 R2 Management Studio
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121475F5-2598-4574-8801-8F6B3D6A99BB}" = SQL Server 2008 R2 Management Studio
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{286033D3-C1C2-458A-B42B-0AC9C4E62B90}" = Scid
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{47BE41E6-2F0F-4D17-9C2D-3850FFD9D405}" = Microsoft SQL Server VSS Writer
"{4A39A27F-005B-407E-8CF5-F4D8065658E4}" = SMS Advanced Client
"{4A6A9534-25BD-490D-AFFD-58270214FB6C}" = IntelliAdmin Remote Control Server
"{4AB6A079-178B-4144-B21F-4D1AE71666A2}" = Microsoft SQL Server 2008 R2 Native Client
"{4C9D82EB-9001-4E59-8F64-0BEEE5F4A30A}" = SQL Server 2008 R2 Database Engine Shared
"{4E621E54-0E24-42B5-B80D-E0026C2153EC}_is1" = HexWar Components 1.0.0
"{4ECF4BDC-8387-329A-ABE9-CF5798F84BB2}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = SQL Server 2008 R2 Database Engine Services
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DE3C67-FB48-450E-8BEA-4EB1B3B5355D}" = Microsoft SQL Server 2008 R2 Setup (English)
"{75B6EAA7-773D-4FD9-B3C3-EAE3C4F77313}_is1" = HexWar Game Launcher Version 6.4.0
"{7C8EAD2B-A954-4F73-AAFC-C3EC60D49ADA}" = Microsoft SQL Server 2008 R2 RsFx Driver
"{87DF5956-A327-4304-8338-8E2B0AAB843E}" = BlackBerry Desktop Software 6.0.2
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8AF09748-FCC1-48AB-9A81-21D76903F5C9}" = MySQL Server 5.5
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{93998800-1608-403F-9A51-420A77D23C25}" = Sql Server Customer Experience Improvement Program
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.7
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = SQL Server 2008 R2 Database Engine Services
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1583439-B034-4881-819C-D52A0587662B}" = Neverwinter Nights
"{C5E8249E-93E2-4745-8543-01C9885BE454}" = DriverUpdate
"{CA706D05-B655-4F31-AA68-03BB2441F8EC}" = Barracuda Message Archiver Outlook Add-In 2.2.1
"{CACEA8C8-3D38-4F51-953D-1E6FC3346FEF}" = SQL Server 2008 R2 Common Files
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D21BC5B2-CBAC-48FA-A701-B5A63C1CA7B8}" = Microsoft SQL Server 2008 R2 Policies
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{DDFD8348-058C-4F4B-85E5-6D740D4AB3FE}" = Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU
"{E8A0BF78-AEC5-449A-A391-1B20535009D6}" = TableSmith
"{F021CC0C-21C3-4038-AA4A-6E3CBC669CE8}" = SQL Server 2008 R2 Database Engine Shared
"{FC835376-FF3B-4CAA-83E0-2148B3FB7C98}" = SQL Server 2008 R2 Common Files
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFB768E4-E427-4553-BC36-A11F5E62A94D}" = Adobe Flash Player 10 ActiveX
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.02.05.8032
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.2
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.9x Modem
"Dia" = Dia (remove only)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Finale NotePad 2006" = Finale NotePad 2006
"Foxit Reader" = Foxit Reader
"Game Booster_is1" = Game Booster
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"IntelliAdminRC3" = IntelliAdmin 3.0 - Remove Agent
"IObit Security 360_is1" = IObit Security 360
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Report Viewer Redistributable 2008 (KB971119)" = Microsoft Report Viewer Redistributable 2008 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2
"Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neverwinter Nights™ Kingmaker" = BioWare Premium Module: Neverwinter Nights™ Kingmaker
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Smart Defrag 2_is1" = Smart Defrag 2
"Update Manager" = Update Manager (remove only)
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"YInstHelper" = Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/26/2011 12:14:38 AM | Computer Name = HELEN-LAPTOPXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 5/26/2011 12:08:14 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 5/26/2011 12:08:14 PM | Computer Name = HELEN-LAPTOPXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 5/26/2011 12:08:54 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 5/26/2011 1:04:51 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 5/26/2011 1:04:51 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 5/26/2011 1:04:52 PM | Computer Name = HELEN-LAPTOPXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 5/26/2011 8:39:30 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 5/26/2011 8:39:31 PM | Computer Name = HELEN-LAPTOPXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 5/26/2011 8:39:39 PM | Computer Name = HELEN-LAPTOPXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
[ System Events ]
Error - 5/26/2011 12:08:15 PM | Computer Name = HELEN-LAPTOPXP | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CTREE due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 5/26/2011 12:08:16 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 12:08:16 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 12:23:26 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 12:53:29 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 1:04:51 PM | Computer Name = HELEN-LAPTOPXP | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CTREE due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 5/26/2011 1:04:53 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 1:04:53 PM | Computer Name = HELEN-LAPTOPXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 5/26/2011 5:04:51 PM | Computer Name = HELEN-LAPTOPXP | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CTREE due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 5/26/2011 8:39:30 PM | Computer Name = HELEN-LAPTOPXP | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CTREE due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
< End of report >