Zephyr_A
Topic Starter
I thought I had the subscription set on my last topic so that I would get an email when there was a response, which is why it took so long for me to give another response.
The thread is: http://forums.whatthetech.com/index.php?showtopic=118867
The following applications that were suggested to be removed could not be found in the programs list to remove:
Antivirus 5 not showing up (cannot uninstall)
SelectRebates
Search Settings
MyWebSearch
funwebproducts
applicationupdater
Here are the OTL Logs:
The aswmbr log:
The thread is: http://forums.whatthetech.com/index.php?showtopic=118867
The following applications that were suggested to be removed could not be found in the programs list to remove:
Antivirus 5 not showing up (cannot uninstall)
SelectRebates
Search Settings
MyWebSearch
funwebproducts
applicationupdater
Here are the OTL Logs:
OTL logfile created on: 6/9/2011 8:43:35 PM - Run 1 OTL by OldTimer - Version 3.2.23.0 Folder = D:\ Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 893.44 Mb Total Physical Memory | 269.01 Mb Available Physical Memory | 30.11% Memory free 1.99 Gb Paging File | 1.16 Gb Available in Paging File | 58.25% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 231.42 Gb Total Space | 155.14 Gb Free Space | 67.04% Space Free | Partition Type: NTFS Drive D: | 7.45 Gb Total Space | 7.45 Gb Free Space | 99.99% Space Free | Partition Type: FAT32 Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - D:\OTL.exe (OldTimer Tools) PRC - C:\Program Files\SelectRebates\SelectRebates.exe () PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe (Authentium, Inc) PRC - C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe (Authentium, Inc) PRC - C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe (Authentium, Inc) PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\Blubster\Blubster.exe (MP2P Technologies.) PRC - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - D:\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.20533_none_4634c4a0218d65c1\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC) SRV - (vseqrts) – C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe (Authentium, Inc) SRV - (vsedsps) – C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe (Authentium, Inc) SRV - (vseamps) – C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe (Authentium, Inc) SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.) SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (TNaviSrv) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION) SRV - (Swupdtmr) – c:\Toshiba\IVP\swupdate\swupdtmr.exe () SRV - (pinger) – C:\Toshiba\IVP\ISM\pinger.exe () SRV - (CFSvcs) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems) SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.) SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) ========== Driver Services (SafeList) ========== DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation) DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.) DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments) DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation) DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems) DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.) DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation) DRV - (netr73) – C:\Windows\System32\drivers\netr73.sys (Ralink Technology Inc.) DRV - (KR3NPXP) – C:\Windows\system32\drivers\kr3npxp.sys (TOSHIBA CORPORATION) DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.) DRV - (KR10I) – C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION) DRV - (KR10N) – C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.msn.com/ [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [2009/07/25 13:11:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions [2009/07/25 13:11:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\[removed] O1 HOSTS File: ([2011/01/27 22:55:15 | 000,000,736 | —- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: ::1 localhost O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - File not found O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [Bar] File not found O4 - HKLM..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe (MP2P Technologies.) O4 - HKLM..\Run: [MyWebSearch Plugin] File not found O4 - HKLM..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe () O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [RunSpySweeperScheduleAtStartup] C:\Windows\System32\msfeedssync.exe (Microsoft Corporation) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk = File not found O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control) O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} http://zone.msn.com/bingame/feed/default/SproutLauncher.cab (SproutLauncherCtrl Class) O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://hishouse.jvbc.org/activex/AMC.cab (Reg Error: Key error.) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-us.cab (Windows Live Hotmail Photo Upload Tool) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Toshiba-1.JPG O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Toshiba-1.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ] O33 - MountPoints2\{37d6c7cd-1b8d-11dd-8d85-001b381d69d5}\Shell\Auto\command - "" = Cn911.exe O33 - MountPoints2\{37d6c7cd-1b8d-11dd-8d85-001b381d69d5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] – "%1" %* O35 - HKLM\..exefile [open] – "%1" %* O37 - HKLM\…com [@ = comfile] – "%1" %* O37 - HKLM\…exe [@ = exefile] – "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/06/09 20:32:05 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\backups [2011/06/09 20:21:35 | 000,000,000 | -HSD | C] – C:\Config.Msi [2011/06/08 14:07:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\AVG8 [2011/06/02 21:05:20 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Owner\Desktop\HiJackThis.exe [2011/05/26 07:55:17 | 000,000,000 | —D | C] – C:\c30a754d759a91bcf832498f [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/06/09 20:48:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{3CD0C571-27B0-4C4B-879B-8F074F4961EC}.job [2011/06/09 20:36:12 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/06/09 20:35:30 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/06/09 20:34:44 | 000,003,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/06/09 20:34:44 | 000,003,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/06/09 20:34:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat [2011/06/09 20:34:18 | 937,476,096 | -HS- | M] () – C:\hiberfil.sys [2011/06/09 20:24:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4109366116-2483938743-85732800-1000UA.job [2011/06/09 20:18:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4109366116-2483938743-85732800-1001UA.job [2011/06/09 17:18:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4109366116-2483938743-85732800-1001Core.job [2011/06/05 22:24:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4109366116-2483938743-85732800-1000Core.job [2011/06/02 22:17:55 | 000,006,040 | —- | M] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat [2011/06/02 20:25:56 | 000,618,648 | —- | M] () – C:\Windows\System32\perfh009.dat [2011/06/02 20:25:56 | 000,104,024 | —- | M] () – C:\Windows\System32\perfc009.dat [2011/06/02 20:22:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Owner\Desktop\HiJackThis.exe [2011/06/01 23:31:27 | 000,020,992 | —- | M] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/06/01 10:17:38 | 076,657,738 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm [2011/05/29 21:40:15 | 000,001,356 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/06/01 10:10:23 | 937,476,096 | -HS- | C] () – C:\hiberfil.sys [2011/05/01 08:55:15 | 000,000,085 | —- | C] () – C:\Windows\AuthentiumException.ini [2011/02/01 09:21:19 | 000,000,067 | —- | C] () – C:\Windows\st_affiliate.ini [2011/01/12 23:02:59 | 000,000,286 | —- | C] () – C:\Windows\reimage.ini [2010/03/22 14:56:52 | 000,000,054 | —- | C] () – C:\Windows\System32\tav.ini [2009/11/28 20:57:34 | 000,001,356 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat [2009/03/16 15:20:39 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol [2008/05/29 17:23:04 | 000,020,992 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/05/07 18:53:47 | 000,006,040 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat [2007/05/16 21:40:56 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll [2007/05/16 21:40:55 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll [2007/05/16 21:40:55 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll [2007/05/16 21:40:55 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll [2007/05/16 21:40:55 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll [2007/05/16 21:40:55 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll [2007/05/16 20:46:42 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI [2007/05/16 20:30:13 | 000,036,864 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll [2007/05/16 20:15:16 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini [2007/05/16 20:15:16 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll [2007/05/16 20:15:16 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini [2007/05/16 20:15:16 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini [2007/05/16 20:13:14 | 000,000,291 | —- | C] () – C:\Windows\RtDefLvl.ini [2007/05/16 20:13:14 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat [2007/05/16 20:13:14 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ0.dat [2007/05/16 20:13:14 | 000,000,008 | —- | C] () – C:\Windows\System32\drivers\RtkHDAud.dat [2007/04/25 00:57:36 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll [2007/04/25 00:32:44 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat [2007/04/02 17:49:54 | 000,145,050 | —- | C] () – C:\Windows\System32\atiicdxx.dat [2006/12/05 16:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll [2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat [2006/11/02 08:47:37 | 000,457,040 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT [2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll [2006/11/02 06:33:01 | 000,618,648 | —- | C] () – C:\Windows\System32\perfh009.dat [2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat [2006/11/02 06:33:01 | 000,104,024 | —- | C] () – C:\Windows\System32\perfc009.dat [2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat [2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat [2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin [2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT [2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini [2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat [2006/11/02 03:22:43 | 000,099,999 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin [2006/11/02 03:22:43 | 000,018,271 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2005/11/23 17:55:42 | 000,024,576 | —- | C] () – C:\Windows\System32\SPCtl.dll [2005/07/23 00:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll ========== LOP Check ========== [2009/12/28 22:45:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Barnes & Noble [2009/10/01 17:21:49 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\BNeReader [2009/08/16 13:51:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Canon [2009/10/07 18:39:27 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2009/01/04 15:15:45 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\DataCast [2008/07/11 22:40:33 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\GetRightToGo [2010/04/30 19:43:36 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\LimeWire [2008/05/07 18:54:03 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Template [2008/10/11 22:24:17 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\TOSHIBA [2008/07/11 07:29:59 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Ulead Systems [2008/07/01 21:02:35 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WeatherDPA [2008/05/12 19:45:10 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WildTangent [2008/05/27 20:25:29 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WinBatch [2011/06/09 20:33:11 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT [2011/06/09 20:48:00 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{3CD0C571-27B0-4C4B-879B-8F074F4961EC}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:8FDE078B < End of report >
OTL Extras logfile created on: 6/9/2011 8:43:35 PM - Run 1 OTL by OldTimer - Version 3.2.23.0 Folder = D:\ Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 893.44 Mb Total Physical Memory | 269.01 Mb Available Physical Memory | 30.11% Memory free 1.99 Gb Paging File | 1.16 Gb Available in Paging File | 58.25% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 231.42 Gb Total Space | 155.14 Gb Free Space | 67.04% Space Free | Partition Type: NTFS Drive D: | 7.45 Gb Total Space | 7.45 Gb Free Space | 99.99% Space Free | Partition Type: FAT32 Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] – "%1" %* cmdfile [open] – "%1" %* comfile [open] – "%1" %* cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] – "%1" %* helpfile [open] – Reg Error: Key error. hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] – "%1" %* regfile [merge] – Reg Error: Key error. scrfile [config] – "%1" scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] – "%1" /S txtfile [edit] – Reg Error: Key error. Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine – (TOSHIBA Corporation) "C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – () ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{11570781-8AD5-4690-BB4E-E30CC0271D92}" = lport=139 | protocol=6 | dir=in | app=system | "{18199539-32CA-4F73-A9CF-6ACDB41A6191}" = rport=137 | protocol=17 | dir=out | app=system | "{2A4E78A3-DA31-41F2-BF42-DF4843A35829}" = rport=139 | protocol=6 | dir=out | app=system | "{45BBBE1A-C16F-4409-BD16-BFA9276D1082}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{463A2536-097E-4E8E-9457-77876F154227}" = rport=138 | protocol=17 | dir=out | app=system | "{62DD0B51-0C0D-4AA6-BE7B-6FC841751810}" = lport=137 | protocol=17 | dir=in | app=system | "{878B8783-C655-48C5-A0AC-8C1320786708}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{8C0888ED-A67D-4166-B8F5-AA0FB5FE836C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{8F3E36D6-0740-4924-990F-7FBC3AD39BC1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A6915D7A-E91C-46E9-B766-27594A7C0653}" = lport=445 | protocol=6 | dir=in | app=system | "{A7231524-1BF2-418C-B608-04EF9D6C109D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{C3FE852D-B320-481D-8442-143FCBB46747}" = rport=445 | protocol=6 | dir=out | app=system | "{C962DB7C-3AE0-4C7A-89B8-9F4EFEE2AC26}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D465FC23-A035-43D0-8E52-8CE720873CC0}" = lport=138 | protocol=17 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00E2479A-0EDA-4936-8D6E-D3E41A2452B2}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{060C12CC-804D-4433-B87B-EA3F9725B205}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{0AACDF05-E968-4937-99C6-73908EAB6741}" = protocol=17 | dir=in | app=c:\program files\blubster\blubster.exe | "{1A2A0CCC-4A1A-4B1A-87D9-FD29475B5F5E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{2E4A8D82-37E3-4C66-813F-98030189F680}" = protocol=6 | dir=in | app=c:\program files\blubster\blubster.exe | "{2FD54F10-3F17-4F1E-866A-FA8B2FD5EE86}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe | "{34D08E99-F724-4DF8-922C-51AEB3E9D2E1}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe | "{35AFC45F-2813-4163-B772-9F3C90677EA5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3D305539-4393-4AAA-84E1-30A1FCD11E96}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3E901296-5156-4B85-B590-CA5C16CA906B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5CFBAFE2-802A-4AF0-A46D-71CB223B0327}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{6C2B5B24-E172-41FD-8353-DB064C9E8520}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe | "{6E695218-B6EE-4B5C-A69E-A02C4CF7CF51}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{7F3441C5-2BD3-4689-AC0C-F6C1961D4F39}" = protocol=17 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe | "{8A9228E5-10D8-4BB5-9469-AF0B15038AB4}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe | "{8B3CBA70-0D86-49BC-8921-2BBA6F133D70}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{95338725-7F19-4026-83D2-C761D273A730}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe | "{A181D985-50CC-4E51-8A3E-9A9523E3BEBD}" = dir=in | app=c:\program files\myspace\im\myspaceim.exe | "{A3A1DA4D-46BC-4179-8498-C6A460A02D55}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe | "{A81550E0-1505-42F9-9C59-55D552AE81B5}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{B6DD566F-AFFD-43B1-BF9F-B08EA12BAFD6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{BDB5A838-4BDB-41F8-A27B-3F1148DC815B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{BE85C98B-EA6B-4CCC-AC5D-635FA09F874C}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe | "{CE513C88-9A21-418B-AB73-04BFB2459BC3}" = protocol=6 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe | "{F5198437-7755-4449-AAF2-94F32B1EBE6A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "TCP Query User{2966D263-C69F-48F4-970E-8DF4368156FC}C:\users\haze\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=6 | dir=in | app=c:\users\haze\appdata\roaming\myspace\im\bin\myspaceim.exe | "TCP Query User{396AA642-C7E6-4302-A753-473815AB89C0}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "TCP Query User{95477519-48BB-44EB-A985-D4DEB95DCCE1}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{E4D34F4A-7DD9-42F8-9113-7BFB28C0C2B0}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{2CD2E5D0-F4EF-48FB-AF36-125601CC2F51}C:\users\haze\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=17 | dir=in | app=c:\users\haze\appdata\roaming\myspace\im\bin\myspaceim.exe | "UDP Query User{31350C38-8357-4B95-A753-5CA4FCC128A6}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{EBDA8D71-2430-4A34-B144-1C9334CD8D8B}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{FC3F4A7B-020B-47E0-9160-9F31267ABD7D}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{003B5184-F3DF-AF76-CB17-D35B7BB46B81}" = CCC Help Japanese "{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0 "{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update "{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar "{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime "{0E9C4531-58C4-4349-AD2F-A4D999E451EC}" = TOSHIBA Music "{0F6932CF-E642-5A7A-8194-3F7443188287}" = CCC Help Turkish "{103A43D9-9ED8-E78D-7BF1-E536DFE6FC9F}" = Catalyst Control Center Localization Greek "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{12887AF2-AE16-34CC-E85C-637DF6911C8C}" = Catalyst Control Center Localization Turkish "{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist "{13614186-B0A0-AA21-F75A-2097F9167DB8}" = CCC Help Portuguese "{177B615E-47B1-C1C4-6F3B-7D6FEB8D4564}" = CCC Help Thai "{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player "{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26210745-925C-8AE4-F3B9-5FA737A1F6F2}" = CCC Help Russian "{2768CDA5-57DA-59D4-884F-A0F8A5B36D3E}" = CCC Help Finnish "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program "{29DC966A-DA3E-3ED4-68E7-6D3D9A055B42}" = Catalyst Control Center Localization Korean "{2E7A9DDC-E062-0074-08AB-DE7D1B431F75}" = Catalyst Control Center Localization Chinese Traditional "{2FAE3800-CC47-C556-C57F-A91851BF7854}" = CCC Help French "{30DBAD4A-BA6D-4F9D-8AB0-2F6C7B0612A4}" = AVSDK5 "{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6 "{32821558-2C36-4FD0-A891-CA65360B0EC7}" = DesignPro 5 "{335B1821-D274-4EFD-9EFE-3C0FD38EBE65}" = BN eReader "{33824DAC-3F98-0BB6-56D5-7DE1A3CCC068}" = Catalyst Control Center Localization German "{3621A2DF-0870-FE7E-674F-1DBCB18C5D22}" = ccc-utility "{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba "{3F11CE8A-388B-0D3A-DF6F-061F23A13D26}" = CCC Help Korean "{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0 "{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager "{41DD15BE-811D-7DEF-19A9-30AF18F75EFF}" = Catalyst Control Center Localization Thai "{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support "{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour "{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password "{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup "{52F368DE-06BD-E116-9233-D1DE207BDFE6}" = CCC Help Dutch "{53BABC75-1DC1-479B-224B-1EB9E18A799B}" = CCC Help German "{56797214-1A4C-052E-1ECE-B00308BF3362}" = CCC Help Chinese Standard "{572D71E9-5102-74B3-5D22-DEDF911F7FE5}" = CCC Help Italian "{5BA0C9F0-3B01-91A3-6922-4DCF943D9CBE}" = CCC Help English "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{6080CE3C-2CB3-2FA3-1CE2-3350B06664BC}" = CCC Help Swedish "{611E35B8-7F46-DDBB-CC4F-FAAED6C054FF}" = Catalyst Control Center Localization Spanish "{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{678F1F2D-F214-08D4-67FB-AC04316C4940}" = ccc-core-static "{6A0B868C-89BE-ACF1-8C0A-CC88878A9E46}" = Catalyst Control Center Localization Russian "{6C4734CF-A10C-DFF4-5565-457F33849862}" = Catalyst Control Center Localization Swedish "{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{6DECCD60-782D-7B14-22DE-FB8D6EA46433}" = CCC Help Polish "{715044AC-B95E-4CD0-9B0C-CEDDB422F93B}" = CCC Help Czech "{724A8BEC-B350-1C76-C580-959AEA487108}" = Catalyst Control Center Localization Japanese "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree "{7994AA46-4BA6-4349-1606-1DF4148CE05B}" = CCC Help Hungarian "{7AFBAC39-F6A8-9F8D-6A6D-F134F7E34B6E}" = Catalyst Control Center Localization Danish "{845D19A7-0BBF-12DF-87CF-F5D468930EA6}" = Catalyst Control Center Localization Czech "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90BF970B-3335-CFD5-711C-9FE0310A97C0}" = CCC Help Greek "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{926593ED-3962-4630-7CE3-34FF1B4ACCF3}" = Catalyst Control Center Localization Finnish "{9EB0D4D4-87A5-52F5-C59C-159F81BED0E6}" = Catalyst Control Center Graphics Previews Vista "{9F70BF98-003C-491D-81FC-FF9792206AF0}" = iTunes "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver "{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer "{A91383E9-0311-DB40-6AF6-3F9E80F83E84}" = Catalyst Control Center Localization Portuguese "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9 "{B1211E68-4DA2-7942-BE75-14272A8C1EA9}" = Catalyst Control Center Localization Dutch "{B1F8FA80-EFA5-EC12-AD36-F5266EF90B61}" = CCC Help Danish "{B4369E44-8703-E769-A711-40EE5000AC2C}" = Catalyst Control Center Core Implementation "{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser "{B7DE7B5E-4A2B-B709-E133-EC74C81E654A}" = Catalyst Control Center Graphics Full New "{B87A3B9F-7632-E053-2148-8EDD1A787B78}" = Catalyst Control Center Localization Chinese Standard "{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster "{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration "{C7EA6173-A2B8-D45E-A0EE-74F8D2C58D30}" = Catalyst Control Center Localization Hungarian "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba "{D1C3920F-1DC3-A2FA-BF5E-7497B5EF072E}" = Catalyst Control Center Localization Norwegian "{D593C72C-435B-4171-8106-9CA8AA34D716}" = Belkin Wireless Driver "{D95AAA04-9BEF-54B3-CD70-348AC1155DAB}" = Catalyst Control Center Graphics Full Existing "{D9C7C58C-AC51-EDBF-CF22-E4E1B93ED50D}" = Skins "{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI "{DDC4619D-1DC8-C2A7-4968-45586F237131}" = CCC Help Norwegian "{E015B7D9-01AD-FE29-052A-489F4F29ED7F}" = Catalyst Control Center Graphics Light "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{E5E96D69-F0FC-4CAC-AF66-E9770B46440D}" = Belkin Wireless G Plus MIMO USB Network Adapter "{E7511B20-2857-3F50-1B84-F0F32C519FE1}" = CCC Help Chinese Traditional "{EB5BE9DE-6025-6227-0C25-AE5C852EC479}" = Catalyst Control Center Localization Polish "{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities "{EC28331A-FF2B-6D66-D8A0-32C706AEA120}" = CCC Help Spanish "{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox "{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin "{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA "{F2B27034-6059-0549-F01A-4BD9865521B1}" = Catalyst Control Center Localization French "{FBE6B550-A93E-AA46-1DBB-421EC319E2DA}" = Catalyst Control Center Localization Italian "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player "ATI Uninstaller" = ATI Uninstaller "AVG8Uninstall" = AVG Free 8.5 "BFGC" = Big Fish Games: Game Manager "BN_DesktopReader" = Barnes & Noble Desktop Reader "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows "Desktop Dialer" = Desktop Dialer "Google Desktop" = Google Desktop "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password "InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup "InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers. "InstallShield_{E5E96D69-F0FC-4CAC-AF66-E9770B46440D}" = Belkin Wireless G Plus MIMO USB Network Adapter "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "oggcodecs" = oggcodecs 0.71.0946 "PC Matic_is1" = PC Matic [removed] "Picasa 3" = Picasa 3 "PlayMP3" = PlayMP3z "SelectRebatesUninstall" = ShopAtHome SelectRebates "TOSHIBA Game Console" = TOSHIBA Game Console "TOSHIBA Media Center Game Console" = TOSHIBA Media Center Game Console "TOSHIBA Software Modem" = TOSHIBA Software Modem "Windows Media Encoder 9" = Windows Media Encoder 9 Series "WT022084" = Bejeweled 2 Deluxe "WT022091" = Penguins! "WT022092" = Polar Bowler ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report >
The aswmbr log:
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-06-09 20:51:29 —————————– 20:51:29.004 OS Version: Windows 6.0.6000 20:51:29.004 Number of processors: 2 586 0x6801 20:51:29.004 ComputerName: OWNER-PC UserName: Owner 20:51:34.090 Initialize success 20:51:46.492 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 20:51:46.507 Disk 0 Vendor: WDC_WD2500BEVS-22UST0 01.01A01 Size: 238475MB BusType: 3 20:51:48.535 Disk 0 MBR read successfully 20:51:48.535 Disk 0 MBR scan 20:51:48.535 Disk 0 unknown MBR code 20:51:50.563 Disk 0 scanning sectors +488396800 20:51:50.610 Disk 0 scanning C:\Windows\system32\drivers 20:51:56.413 Service scanning 20:51:58.285 Disk 0 trace - called modules: 20:51:58.332 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys atikmdag.sys 20:51:58.348 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84dc58f0] 20:51:58.363 3 ntkrnlpa.exe[824b07e2] -> nt!IofCallDriver -> [0x84649928] 20:51:58.363 5 acpi.sys[8023232a] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84633bb0] 20:51:58.379 Scan finished successfully 20:52:39.464 Disk 0 MBR has been saved successfully to "D:\MBR.dat" 20:52:39.542 The log file has been saved successfully to "D:\aswMBR.txt"