dustymom
Topic Starter
Help! I am another searchqu victim. My IE browser is getting redirected.
Thank you in advance.
I ran OTL as directed and here is the output:
OTL logfile created on: 6/17/2011 3:40:04 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Susan Home\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 70.97% Memory free
12.00 Gb Paging File | 9.60 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.50 Gb Total Space | 868.83 Gb Free Space | 94.59% Space Free | Partition Type: NTFS
Drive D: | 12.92 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS
Drive H: | 488.25 Mb Total Space | 39.17 Mb Free Space | 8.02% Space Free | Partition Type: FAT
Drive J: | 981.05 Mb Total Space | 707.49 Mb Free Space | 72.12% Space Free | Partition Type: FAT32
Drive K: | 232.88 Gb Total Space | 176.90 Gb Free Space | 75.96% Space Free | Partition Type: NTFS
Computer Name: SUSANHOME-HP | User Name: Susan Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Susan Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10s_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - c:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
========== Modules (SafeList) ==========
MOD - C:\Users\Susan Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe ()
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (szserver) – C:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (pdfcDispatcher) – C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys (Symantec Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amd_sata) – C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) – C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (netr28x) – C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (ATI Technologies, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie64.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110615.001\IDSviA64.sys (Symantec Corporation)
DRV - (szkg5) – C:\Windows\SySWOW64\DRIVERS\szkg64.sys (iS3 Inc.)
DRV - (is3srv) – C:\Windows\SySWOW64\drivers\is3srv64.sys (iS3 Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110616.003\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110617.003\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110617.003\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/04/02 16:28:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/04/02 16:28:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/04/02 16:28:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011/05/12 22:03:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2011/05/12 18:49:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/18 23:19:39 | 000,000,000 | —D | M]
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files (x86)\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/17 15:37:28 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
[2011/06/17 09:00:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{AF64D656-4A0E-49E4-9DDA-19888B8BBBB7}
[2011/06/16 21:00:12 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{42DE57C3-192C-4112-AE58-A597300282F6}
[2011/06/16 08:39:07 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{186A747C-E236-4368-AAAD-F11887D9134A}
[2011/06/15 13:27:35 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/15 13:27:35 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/15 13:27:34 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/15 13:27:34 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/15 13:27:34 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/15 13:27:34 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/15 13:27:34 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/15 13:27:34 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/15 13:27:34 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/15 13:27:34 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/15 13:27:34 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/15 13:27:34 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/15 13:27:34 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/15 13:27:34 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/15 13:26:41 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/15 13:26:41 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/06/15 13:26:39 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/15 13:12:41 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{68351F83-7604-44C6-83A8-AD08D55BB1E5}
[2011/06/14 22:03:15 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C5132026-0CD4-4895-BF09-6E9E76C7EAAE}
[2011/06/14 09:40:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{50F6AC1F-447C-4118-80AC-47AE538D0988}
[2011/06/14 09:29:50 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{EA359345-F055-4821-90DD-29D1EBF21EB4}
[2011/06/14 09:28:56 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{90C03DE9-DD25-4FDF-AF14-C09236144785}
[2011/06/13 11:57:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{81AFB536-5CCC-4FD7-AEE6-887A1FC17B40}
[2011/06/12 22:39:38 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{61A0F335-0F8F-4AE1-B073-5A8072F1CD5A}
[2011/06/12 10:07:08 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{F1CF7887-F1AC-40FB-8F8C-3EA52EC88F3B}
[2011/06/11 17:38:54 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\HP MediaSmart Video
[2011/06/11 11:39:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\STOPzilla!
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\iS3
[2011/06/11 10:55:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/06/11 10:55:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/06/11 10:28:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{216324AF-36BA-4314-9464-E29ACBC73D60}
[2011/06/10 21:17:55 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E1A68620-4798-4F0E-8E4B-7FD601507EA5}
[2011/06/10 21:14:20 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{4B46B5FB-4FCE-44DC-A74F-265F32FB3D34}
[2011/06/10 18:47:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Malwarebytes
[2011/06/10 18:47:34 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/10 18:47:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/10 18:47:34 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/06/10 18:47:31 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/06/10 18:47:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/10 08:45:47 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C2C66A6F-9183-4FDD-B49B-FB4A6D89E737}
[2011/06/09 20:24:34 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{2F95B3CA-3ADF-4099-BD8B-85D374E3E1CE}
[2011/06/09 13:32:06 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Ilivid Player
[2011/06/09 13:28:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\PackageAware
[2011/06/09 08:23:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D24E0A24-5050-40F8-9FA8-F764D66DD945}
[2011/06/08 21:38:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/06/08 21:38:02 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2011/06/08 21:38:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2011/06/08 21:31:25 | 000,000,000 | —D | C] – C:\Users\Susan Home\Documents\Downloads
[2011/06/08 19:07:24 | 000,132,560 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/06/08 19:07:24 | 000,022,992 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/06/08 19:07:22 | 000,546,256 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/06/08 19:07:22 | 000,456,144 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/06/08 19:07:22 | 000,398,800 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/06/08 19:07:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/06/08 19:07:22 | 000,067,024 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/06/08 19:07:22 | 000,028,624 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/06/08 19:07:20 | 000,738,768 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/06/08 19:07:20 | 000,390,608 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/06/08 19:07:20 | 000,230,864 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/06/08 19:07:20 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/06/08 11:47:54 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{65ED6565-B926-43A3-BE23-C418D13F1146}
[2011/06/07 22:23:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E3133B87-F876-4495-BBE7-EC7C7C175B2E}
[2011/06/07 08:08:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5A113E50-F28D-48D7-A01E-1787D22A8851}
[2011/06/06 20:08:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{FA642869-986A-48DE-950C-BF00A9B49B8A}
[2011/06/06 08:07:33 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C4695417-4C3C-4A6B-9C9F-A82F4F7C5DF2}
[2011/06/05 19:15:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E5C0D1EE-5C53-4C8C-98AF-0DC487509FEC}
[2011/06/05 06:53:52 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{0FA036EF-AC1D-4172-B6D4-7BF0A3F112E1}
[2011/06/04 22:03:20 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{DBB23C6A-0158-4476-AB2D-20287BC9395F}
[2011/06/04 18:54:40 | 000,000,000 | —D | C] – C:\Users\Susan Home\Tracing
[2011/06/04 07:42:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D1271789-6941-4B56-8644-B8D24F3AFEAE}
[2011/06/03 19:42:10 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{9478B9A8-20E6-4363-9902-31B36AFEF77A}
[2011/06/03 07:41:23 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5D6A2F46-94E7-4A1C-8971-7CCB056FFD5F}
[2011/06/02 12:58:28 | 000,074,768 | R— | C] (iS3 Inc.) – C:\Windows\SysWow64\drivers\SZKG64.sys
[2011/06/02 12:58:28 | 000,074,768 | R— | C] (iS3 Inc.) – C:\Windows\SysWow64\drivers\is3srv64.sys
[2011/06/02 11:14:14 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{208A9177-2693-4522-8BB6-A82FA0E44959}
[2011/06/01 22:10:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{81E5EE83-4015-4ADB-84E0-1D876B3EFDA9}
[2011/06/01 19:01:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2011/06/01 19:00:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/06/01 18:59:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/06/01 18:59:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/06/01 18:57:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Microsoft Help
[2011/06/01 18:56:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/06/01 18:54:38 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/06/01 08:30:05 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{64A73298-E508-4FCF-9563-5171D283AEF5}
[2011/05/31 20:29:18 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{0A1C8C4C-0380-42DB-9B4B-39840BB841C8}
[2011/05/31 08:28:30 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{EA48958C-C413-4C2F-BB18-2D2A3FD728A2}
[2011/05/30 23:03:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{A1656796-31A2-43F2-AF75-6789BAD7D741}
[2011/05/30 11:02:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5CC9E9C5-7109-4585-867D-F7E386269D12}
[2011/05/29 23:01:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{41438937-CD3C-451F-B004-61E57CFF509D}
[2011/05/29 10:23:18 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E69374D7-3634-44DE-9408-BA9E3D9260EE}
[2011/05/28 22:22:48 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{8A2BEDFF-4F01-4E75-A746-8E5DCB6A05D7}
[2011/05/28 12:25:01 | 000,000,000 | —D | C] – C:\Users\Susan Home\Documents\Patterns
[2011/05/28 09:20:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5C610323-471B-433B-866A-0D6AC5D761DB}
[2011/05/27 11:52:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{F82C649C-CC4B-4A9F-8F87-D862FBFDC836}
[2011/05/26 20:50:35 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{A242626C-19B4-4364-9788-E53529CC1A02}
[2011/05/26 18:44:25 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[2011/05/26 08:50:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E0BA1263-4A40-4CE0-806B-716EB27849B4}
[2011/05/25 20:49:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{3F26E9AA-3439-4361-A295-F2D137474489}
[2011/05/25 08:48:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{6A036EE6-7AF2-41C4-A985-B0CA2389882A}
[2011/05/25 08:40:56 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 20:47:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D0C8648B-112A-44BE-B2B6-6D0A502CB002}
[2011/05/24 16:18:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Adobe
[2011/05/24 08:14:49 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/24 08:14:49 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/24 08:14:29 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5E624C92-B6FB-4E17-8EF6-06EE41D1D4FB}
[2011/05/23 20:13:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{1C01C05C-19C5-4E70-8C20-E67E0A045652}
[2011/05/23 08:06:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{354793BA-D8FA-4871-ADB5-08D53BF19931}
[2011/05/22 19:28:12 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{AA94508E-24D2-400F-9BF5-8D2CD3C94641}
[2011/05/21 22:03:10 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E88D9E21-4C62-4D30-971F-2306929599FB}
[2011/05/21 08:15:31 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5C2C4050-F9E8-47AB-930E-069C62D15F44}
[2011/05/20 17:43:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BusinessCardDesigner
[2011/05/20 17:43:53 | 000,000,000 | —D | C] – C:\Windows\SysWow64\gs
[2011/05/20 17:43:31 | 000,000,000 | —D | C] – C:\BusinessCardDesigner
[2011/05/20 17:30:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011/05/20 17:30:16 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Google
[2011/05/20 17:30:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2011/05/20 12:25:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CFE972E1-6D2B-4309-92D0-21C108A5D064}
[2011/05/20 07:49:17 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/19 20:36:29 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CCC8B490-9B48-47FD-A3FF-6F15D7BEDA6A}
[2011/05/19 07:51:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CAFDA3AB-89D5-4544-A782-D03ED3BE760F}
[2011/05/19 07:51:08 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E969AC03-4D9D-43E1-91C2-E0C5651296AE}
[2011/05/18 23:19:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/05/18 23:19:37 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/05/18 23:19:32 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/05/18 23:19:32 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/05/18 23:19:32 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/05/18 23:19:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011/05/18 23:19:30 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/18 23:19:30 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/18 22:49:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2011/05/18 22:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xvid
[2011/05/18 22:46:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/05/18 22:46:44 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/05/18 22:46:43 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Real
[2011/05/18 22:04:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/18 22:04:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/18 22:04:07 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/18 21:57:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\viewsonic
[2011/05/18 21:52:04 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2011/05/18 21:50:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2011/05/18 21:50:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/05/18 21:48:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ATI Technologies
[2011/05/18 21:48:25 | 000,116,240 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\drivers\AtihdW76.sys
[2011/05/18 21:48:07 | 000,450,560 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysNative\ATIDEMGX.dll
[2011/05/18 21:48:07 | 000,057,344 | —- | C] (AMD) – C:\Windows\SysNative\coinst.dll
[2011/05/18 21:46:23 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/17 15:37:32 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
[2011/06/17 14:45:51 | 000,000,352 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForSusan Home.job
[2011/06/17 14:09:01 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/17 14:09:01 | 000,624,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/17 14:09:01 | 000,106,502 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/17 13:59:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/17 08:08:20 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 08:08:20 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 08:03:26 | 000,000,304 | —- | M] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/06/17 08:00:41 | 536,305,663 | -HS- | M] () – C:\hiberfil.sys
[2011/06/16 08:20:19 | 000,355,304 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/11 11:28:49 | 000,850,986 | —- | M] () – C:\Users\Susan Home\Documents\regbackup.reg
[2011/06/11 10:55:49 | 000,002,999 | —- | M] () – C:\Users\Susan Home\Desktop\HiJackThis.lnk
[2011/06/10 18:47:35 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/10 08:46:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/08 21:38:21 | 000,002,249 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2011/06/08 19:07:24 | 000,132,560 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/06/08 19:07:24 | 000,022,992 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/06/08 19:07:22 | 000,546,256 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/06/08 19:07:22 | 000,456,144 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/06/08 19:07:22 | 000,398,800 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/06/08 19:07:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/06/08 19:07:22 | 000,067,024 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/06/08 19:07:22 | 000,028,624 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/06/08 19:07:20 | 000,738,768 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/06/08 19:07:20 | 000,390,608 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/06/08 19:07:20 | 000,230,864 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/06/08 19:07:20 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/06/02 12:58:28 | 000,074,768 | R— | M] (iS3 Inc.) – C:\Windows\SysWow64\drivers\SZKG64.sys
[2011/06/02 12:58:28 | 000,074,768 | R— | M] (iS3 Inc.) – C:\Windows\SysWow64\drivers\is3srv64.sys
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/20 17:43:56 | 000,001,688 | —- | M] () – C:\Users\Public\Desktop\Business Card Designer 4.0.lnk
[2011/05/20 17:30:26 | 000,001,132 | —- | M] () – C:\Users\Susan Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/05/20 17:30:25 | 000,001,108 | —- | M] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2011/05/18 23:19:47 | 000,001,042 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/05/18 23:19:37 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/05/18 23:19:32 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/05/18 23:19:32 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/05/18 23:19:32 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/05/18 23:19:30 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/18 23:19:30 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/18 22:09:43 | 000,000,108 | —- | M] () – C:\Windows\VSWizard.ini
[2011/05/18 22:04:52 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/17 08:03:26 | 000,000,304 | —- | C] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/06/11 11:28:48 | 000,850,986 | —- | C] () – C:\Users\Susan Home\Documents\regbackup.reg
[2011/06/11 10:55:49 | 000,002,999 | —- | C] () – C:\Users\Susan Home\Desktop\HiJackThis.lnk
[2011/06/10 18:47:35 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:38:20 | 000,002,249 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2011/05/20 17:43:55 | 000,001,688 | —- | C] () – C:\Users\Public\Desktop\Business Card Designer 4.0.lnk
[2011/05/20 17:30:26 | 000,001,132 | —- | C] () – C:\Users\Susan Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/05/20 17:30:25 | 000,001,108 | —- | C] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2011/05/20 12:42:17 | 000,000,352 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForSusan Home.job
[2011/05/18 23:21:58 | 000,703,488 | —- | C] () – C:\Windows\SysNative\xvidcore.dll
[2011/05/18 23:21:58 | 000,650,752 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/18 23:21:58 | 000,255,488 | —- | C] () – C:\Windows\SysNative\xvidvfw.dll
[2011/05/18 23:21:58 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/18 23:21:58 | 000,173,056 | —- | C] () – C:\Windows\SysNative\xvid.ax
[2011/05/18 23:21:58 | 000,152,064 | —- | C] () – C:\Windows\SysWow64\xvid.ax
[2011/05/18 23:19:47 | 000,001,042 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/05/18 22:04:51 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/18 22:04:49 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/18 21:55:32 | 000,000,108 | —- | C] () – C:\Windows\VSWizard.ini
[2011/05/18 21:48:07 | 000,076,216 | —- | C] () – C:\Windows\SysNative\atiapfxx.blb
[2011/05/18 21:48:07 | 000,021,866 | —- | C] () – C:\Windows\atiogl.xml
[2011/05/18 21:48:07 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/18 21:48:07 | 000,002,857 | —- | C] () – C:\Windows\SysNative\atipblag.dat
[2011/05/12 21:09:45 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/05/12 18:30:48 | 000,000,178 | —- | C] () – C:\Windows\SysWow64\HPPA.ini
[2011/05/12 15:43:30 | 000,730,638 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/02 16:07:34 | 000,014,051 | —- | C] () – C:\Windows\SysWow64\RaCoInst.dat
[2011/04/02 15:54:12 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/09/21 10:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/12 15:55:00 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\Blio
[2011/05/12 14:22:44 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\PictureMover
[2011/05/14 21:52:29 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\SoftGrid Client
[2011/05/12 15:44:26 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\TP
[2011/05/12 15:50:15 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\WildTangent
[2011/05/12 18:11:44 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\Windows Live Writer
[2009/07/13 22:08:49 | 000,018,354 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/24 12:22:29 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/17 08:00:41 | 536,305,663 | -HS- | M] () – C:\hiberfil.sys
[2011/04/02 17:39:02 | 000,000,000 | RHS- | M] () – C:\OS
[2011/06/17 08:00:42 | 2146,734,079 | -HS- | M] () – C:\pagefile.sys
[2010/08/06 18:26:40 | 000,047,104 | -HS- | M] () – C:\Thumbs.db
< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/12 14:24:06 | 000,000,221 | -HS- | M] () – C:\Users\Susan Home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/17 15:37:32 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >
—–EXTRAS.TXT
OTL Extras logfile created on: 6/17/2011 3:40:05 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Susan Home\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 70.97% Memory free
12.00 Gb Paging File | 9.60 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.50 Gb Total Space | 868.83 Gb Free Space | 94.59% Space Free | Partition Type: NTFS
Drive D: | 12.92 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS
Drive H: | 488.25 Mb Total Space | 39.17 Mb Free Space | 8.02% Space Free | Partition Type: FAT
Drive J: | 981.05 Mb Total Space | 707.49 Mb Free Space | 72.12% Space Free | Partition Type: FAT32
Drive K: | 232.88 Gb Total Space | 176.90 Gb Free Space | 75.96% Space Free | Partition Type: NTFS
Computer Name: SUSANHOME-HP | User Name: Susan Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{67048E0C-29A5-534C-FF67-83C4BF948D48}" = AMD Drag and Drop Transcoding
"{6888C635-E550-4FA4-958E-CE2880B0443B}" = HP Power Assistant
"{70DFF8B2-44A3-2C2C-FB21-783E8291265F}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}" = HP MediaSmart SmartMenu
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{D87047B9-BBC5-9941-00B4-719B9E56CACC}" = ATI AVIVO64 Codecs
"{D9B52C63-4209-7129-BF10-FA5DCD38579E}" = ccc-utility64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06092909-8851-C581-F990-7195076FDAEF}" = CCC Help Czech
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CA04779-346C-30FD-EB9B-8EEA2CE094B3}" = CCC Help Thai
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B3B5C60-70B8-F022-5497-03FD2772586C}" = CCC Help Greek
"{1C160168-BF5B-72FE-BAFA-6DD5F737404C}" = CCC Help Chinese Standard
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1ED3EBF6-A130-4B3B-B01A-C29B067798B3}" = CCC Help Finnish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{264FE20A-757B-492a-B0C3-4009E2997D8A}" = PictureMover
"{278AD90C-D27D-AA89-58DF-AD13852D51CA}" = CCC Help Spanish
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CDBFF1A-6433-E94D-CA25-831FDB9775E9}" = CCC Help Italian
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{31DED885-1124-0E58-97FB-73E4EF692E8D}" = CCC Help Hungarian
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33B670D7-8A06-DA5B-0341-5630D1E12007}" = ccc-core-static
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38D65ABC-A00B-6E13-2EF3-826CFC8CFC14}" = CCC Help French
"{3B4325A0-43CD-10D1-64F6-BD2F90DCB756}" = Catalyst Control Center Graphics Previews Vista
"{3F8B39A4-B7CE-B036-941C-A8DB57676B04}" = CCC Help Norwegian
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{465210C4-595A-BD80-44E8-E0457D9D8432}" = Zinio Reader 4
"{4ACF9BBA-E137-7309-7BF9-567ADAB6B4E6}" = CCC Help Turkish
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{51AD839D-CE11-B9E3-227D-03BC89F227C8}" = CCC Help Danish
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{55043DDE-D718-C7F7-9B4C-2B3D818D8A1F}" = Catalyst Control Center InstallProxy
"{5774B4C1-8579-D5D9-8D38-A0CE32B6736C}" = CCC Help German
"{5D19BB0D-9B04-5B85-9295-4E11BCB1C2C3}" = CCC Help Polish
"{60341104-FC8E-EF26-12CB-93B17DF55976}" = CCC Help Japanese
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{62161867-51F1-9FB8-0E6E-FE49D89CBB71}" = CCC Help Dutch
"{65589581-920C-CAE1-58C2-2149D3AA3F39}" = HydraVision
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A7E9B60-4698-F505-CAD3-05F8AB22FB61}" = CCC Help Russian
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75794DD1-5D69-4E33-A141-C3D4B0724C71}" = Catalyst Control Center Graphics Previews Common
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{795A3A1E-E06A-4214-A2EF-3DDF3BA05C2B}" = STOPzilla
"{7CE47764-9A8F-380D-FB9E-FCFC37B9F727}" = CCC Help Korean
"{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}" = HP Support Information
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D3903E2-4B1B-4A69-B8F6-A3D1BE075BDB}" = Blio
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT2860 Wireless LAN Card
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{912CED74-88D3-4C5B-ACB0-13231864975E}" = PressReader
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9ED77550-AF66-2B7E-97E1-34B3BFDEAC6D}" = CCC Help Swedish
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B1A4A13D-4665-4ED3-9DFE-F845725FBBD8}" = HP Support Assistant
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E8454B5F-4122-864C-002D-31F878D2CBF4}" = CCC Help English
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E6252F-8DC2-B508-D412-1C427CDB3448}" = CCC Help Portuguese
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FCB6F9DC-A0FF-621E-DE53-877E63864DD1}" = CCC Help Chinese Traditional
"{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}" = LightScribe System Software
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE4466A3-76B3-A9F4-9B22-150D6F8B4647}" = Catalyst Control Center Localization All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Business Card Designer 4.0" = Business Card Designer 4.0
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Kobo" = Kobo
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"My HP Game Console" = HP Game Console
"NIS" = Norton Internet Security
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PDF Complete" = PDF Complete Special Edition
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1" = Zinio Reader 4
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HuluDesktop" = Hulu Desktop
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/28/2011 4:28:29 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/30/2011 4:50:47 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/31/2011 7:12:54 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/31/2011 11:13:47 PM | Computer Name = SusanHome-HP | Source = Application Error | ID = 1000
Description = Faulting application name: BusinessCardDesigner.exe, version: 4.0.0.0,
time stamp: 0x4cfdd484 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x00000000 Faulting process id:
0xf78 Faulting application start time: 0x01cc2009e523aa64 Faulting application path:
C:\BusinessCardDesigner\dep\BusinessCardDesigner.exe Faulting module path: unknown
Report
Id: 2a003cf6-8bfd-11e0-ae8b-78acc0c0d628
Error - 6/1/2011 12:34:02 AM | Computer Name = SusanHome-HP | Source = Application Error | ID = 1000
Description = Faulting application name: WINWORD.EXE, version: 10.0.2627.0, time
stamp: 0x3a9cdbe7 Faulting module name: WINWORD.EXE, version: 10.0.2627.0, time
stamp: 0x3a9cdbe7 Exception code: 0xc0000005 Fault offset: 0x0001d5e7 Faulting process
id: 0x10fc Faulting application start time: 0x01cc200a775fbd6e Faulting application
path: C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE Faulting module
path: C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE Report Id: 5f777105-8c08-11e0-ae8b-78acc0c0d628
Error - 6/1/2011 1:03:34 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/2/2011 5:23:40 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/3/2011 9:50:46 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/4/2011 8:55:14 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/5/2011 11:48:37 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
[ System Events ]
Error - 5/31/2011 11:02:01 PM | Computer Name = SusanHome-HP | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:30:54 PM on ?5/?31/?2011 was unexpected.
Error - 6/1/2011 11:58:34 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the lmhosts service.
Error - 6/9/2011 4:32:07 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7030
Description = The Bandoo Coordinator service is marked as an interactive service.
However, the system is configured to not allow interactive services. This service
may not function properly.
Error - 6/12/2011 1:05:25 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 12:34:42 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 2:34:16 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 6:38:33 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/13/2011 11:58:02 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/13/2011 11:14:26 PM | Computer Name = SusanHome-HP | Source = DCOM | ID = 10010
Description =
Error - 6/14/2011 12:28:10 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
< End of report >
Thank you in advance.
I ran OTL as directed and here is the output:
OTL logfile created on: 6/17/2011 3:40:04 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Susan Home\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 70.97% Memory free
12.00 Gb Paging File | 9.60 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.50 Gb Total Space | 868.83 Gb Free Space | 94.59% Space Free | Partition Type: NTFS
Drive D: | 12.92 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS
Drive H: | 488.25 Mb Total Space | 39.17 Mb Free Space | 8.02% Space Free | Partition Type: FAT
Drive J: | 981.05 Mb Total Space | 707.49 Mb Free Space | 72.12% Space Free | Partition Type: FAT32
Drive K: | 232.88 Gb Total Space | 176.90 Gb Free Space | 75.96% Space Free | Partition Type: NTFS
Computer Name: SUSANHOME-HP | User Name: Susan Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Susan Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10s_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - c:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
========== Modules (SafeList) ==========
MOD - C:\Users\Susan Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe ()
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (szserver) – C:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (pdfcDispatcher) – C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys (Symantec Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amd_sata) – C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) – C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (netr28x) – C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (ATI Technologies, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie64.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110615.001\IDSviA64.sys (Symantec Corporation)
DRV - (szkg5) – C:\Windows\SySWOW64\DRIVERS\szkg64.sys (iS3 Inc.)
DRV - (is3srv) – C:\Windows\SySWOW64\drivers\is3srv64.sys (iS3 Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110616.003\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110617.003\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110617.003\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/04/02 16:28:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/04/02 16:28:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/04/02 16:28:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011/05/12 22:03:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\ [2011/05/12 18:49:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/18 23:19:39 | 000,000,000 | —D | M]
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files (x86)\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/17 15:37:28 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
[2011/06/17 09:00:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{AF64D656-4A0E-49E4-9DDA-19888B8BBBB7}
[2011/06/16 21:00:12 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{42DE57C3-192C-4112-AE58-A597300282F6}
[2011/06/16 08:39:07 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{186A747C-E236-4368-AAAD-F11887D9134A}
[2011/06/15 13:27:35 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/15 13:27:35 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/15 13:27:34 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/15 13:27:34 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/15 13:27:34 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/15 13:27:34 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/15 13:27:34 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/15 13:27:34 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/15 13:27:34 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/15 13:27:34 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/15 13:27:34 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/15 13:27:34 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/15 13:27:34 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/15 13:27:34 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/15 13:26:41 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/15 13:26:41 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/06/15 13:26:39 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/15 13:12:41 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{68351F83-7604-44C6-83A8-AD08D55BB1E5}
[2011/06/14 22:03:15 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C5132026-0CD4-4895-BF09-6E9E76C7EAAE}
[2011/06/14 09:40:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{50F6AC1F-447C-4118-80AC-47AE538D0988}
[2011/06/14 09:29:50 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{EA359345-F055-4821-90DD-29D1EBF21EB4}
[2011/06/14 09:28:56 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{90C03DE9-DD25-4FDF-AF14-C09236144785}
[2011/06/13 11:57:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{81AFB536-5CCC-4FD7-AEE6-887A1FC17B40}
[2011/06/12 22:39:38 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{61A0F335-0F8F-4AE1-B073-5A8072F1CD5A}
[2011/06/12 10:07:08 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{F1CF7887-F1AC-40FB-8F8C-3EA52EC88F3B}
[2011/06/11 17:38:54 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\HP MediaSmart Video
[2011/06/11 11:39:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\STOPzilla!
[2011/06/11 11:39:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\iS3
[2011/06/11 10:55:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/06/11 10:55:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/06/11 10:28:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{216324AF-36BA-4314-9464-E29ACBC73D60}
[2011/06/10 21:17:55 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E1A68620-4798-4F0E-8E4B-7FD601507EA5}
[2011/06/10 21:14:20 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{4B46B5FB-4FCE-44DC-A74F-265F32FB3D34}
[2011/06/10 18:47:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Malwarebytes
[2011/06/10 18:47:34 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/10 18:47:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/10 18:47:34 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/06/10 18:47:31 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/06/10 18:47:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/10 08:45:47 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C2C66A6F-9183-4FDD-B49B-FB4A6D89E737}
[2011/06/09 20:24:34 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{2F95B3CA-3ADF-4099-BD8B-85D374E3E1CE}
[2011/06/09 13:32:06 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Ilivid Player
[2011/06/09 13:28:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\PackageAware
[2011/06/09 08:23:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D24E0A24-5050-40F8-9FA8-F764D66DD945}
[2011/06/08 21:38:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/06/08 21:38:02 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2011/06/08 21:38:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2011/06/08 21:31:25 | 000,000,000 | —D | C] – C:\Users\Susan Home\Documents\Downloads
[2011/06/08 19:07:24 | 000,132,560 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/06/08 19:07:24 | 000,022,992 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/06/08 19:07:22 | 000,546,256 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/06/08 19:07:22 | 000,456,144 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/06/08 19:07:22 | 000,398,800 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/06/08 19:07:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/06/08 19:07:22 | 000,067,024 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/06/08 19:07:22 | 000,028,624 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/06/08 19:07:20 | 000,738,768 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/06/08 19:07:20 | 000,390,608 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/06/08 19:07:20 | 000,230,864 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/06/08 19:07:20 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/06/08 11:47:54 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{65ED6565-B926-43A3-BE23-C418D13F1146}
[2011/06/07 22:23:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E3133B87-F876-4495-BBE7-EC7C7C175B2E}
[2011/06/07 08:08:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5A113E50-F28D-48D7-A01E-1787D22A8851}
[2011/06/06 20:08:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{FA642869-986A-48DE-950C-BF00A9B49B8A}
[2011/06/06 08:07:33 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{C4695417-4C3C-4A6B-9C9F-A82F4F7C5DF2}
[2011/06/05 19:15:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E5C0D1EE-5C53-4C8C-98AF-0DC487509FEC}
[2011/06/05 06:53:52 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{0FA036EF-AC1D-4172-B6D4-7BF0A3F112E1}
[2011/06/04 22:03:20 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{DBB23C6A-0158-4476-AB2D-20287BC9395F}
[2011/06/04 18:54:40 | 000,000,000 | —D | C] – C:\Users\Susan Home\Tracing
[2011/06/04 07:42:57 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D1271789-6941-4B56-8644-B8D24F3AFEAE}
[2011/06/03 19:42:10 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{9478B9A8-20E6-4363-9902-31B36AFEF77A}
[2011/06/03 07:41:23 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5D6A2F46-94E7-4A1C-8971-7CCB056FFD5F}
[2011/06/02 12:58:28 | 000,074,768 | R— | C] (iS3 Inc.) – C:\Windows\SysWow64\drivers\SZKG64.sys
[2011/06/02 12:58:28 | 000,074,768 | R— | C] (iS3 Inc.) – C:\Windows\SysWow64\drivers\is3srv64.sys
[2011/06/02 11:14:14 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{208A9177-2693-4522-8BB6-A82FA0E44959}
[2011/06/01 22:10:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{81E5EE83-4015-4ADB-84E0-1D876B3EFDA9}
[2011/06/01 19:01:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2011/06/01 19:00:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/06/01 18:59:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/06/01 18:59:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/06/01 18:57:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Microsoft Help
[2011/06/01 18:56:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/06/01 18:54:38 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/06/01 08:30:05 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{64A73298-E508-4FCF-9563-5171D283AEF5}
[2011/05/31 20:29:18 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{0A1C8C4C-0380-42DB-9B4B-39840BB841C8}
[2011/05/31 08:28:30 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{EA48958C-C413-4C2F-BB18-2D2A3FD728A2}
[2011/05/30 23:03:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{A1656796-31A2-43F2-AF75-6789BAD7D741}
[2011/05/30 11:02:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5CC9E9C5-7109-4585-867D-F7E386269D12}
[2011/05/29 23:01:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{41438937-CD3C-451F-B004-61E57CFF509D}
[2011/05/29 10:23:18 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E69374D7-3634-44DE-9408-BA9E3D9260EE}
[2011/05/28 22:22:48 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{8A2BEDFF-4F01-4E75-A746-8E5DCB6A05D7}
[2011/05/28 12:25:01 | 000,000,000 | —D | C] – C:\Users\Susan Home\Documents\Patterns
[2011/05/28 09:20:59 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5C610323-471B-433B-866A-0D6AC5D761DB}
[2011/05/27 11:52:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{F82C649C-CC4B-4A9F-8F87-D862FBFDC836}
[2011/05/26 20:50:35 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{A242626C-19B4-4364-9788-E53529CC1A02}
[2011/05/26 18:44:25 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[2011/05/26 08:50:00 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E0BA1263-4A40-4CE0-806B-716EB27849B4}
[2011/05/25 20:49:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{3F26E9AA-3439-4361-A295-F2D137474489}
[2011/05/25 08:48:26 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{6A036EE6-7AF2-41C4-A985-B0CA2389882A}
[2011/05/25 08:40:56 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 20:47:39 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{D0C8648B-112A-44BE-B2B6-6D0A502CB002}
[2011/05/24 16:18:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Adobe
[2011/05/24 08:14:49 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/24 08:14:49 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/24 08:14:29 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5E624C92-B6FB-4E17-8EF6-06EE41D1D4FB}
[2011/05/23 20:13:42 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{1C01C05C-19C5-4E70-8C20-E67E0A045652}
[2011/05/23 08:06:13 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{354793BA-D8FA-4871-ADB5-08D53BF19931}
[2011/05/22 19:28:12 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{AA94508E-24D2-400F-9BF5-8D2CD3C94641}
[2011/05/21 22:03:10 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E88D9E21-4C62-4D30-971F-2306929599FB}
[2011/05/21 08:15:31 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{5C2C4050-F9E8-47AB-930E-069C62D15F44}
[2011/05/20 17:43:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BusinessCardDesigner
[2011/05/20 17:43:53 | 000,000,000 | —D | C] – C:\Windows\SysWow64\gs
[2011/05/20 17:43:31 | 000,000,000 | —D | C] – C:\BusinessCardDesigner
[2011/05/20 17:30:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011/05/20 17:30:16 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\Google
[2011/05/20 17:30:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2011/05/20 12:25:49 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CFE972E1-6D2B-4309-92D0-21C108A5D064}
[2011/05/20 07:49:17 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/05/19 20:36:29 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CCC8B490-9B48-47FD-A3FF-6F15D7BEDA6A}
[2011/05/19 07:51:09 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{CAFDA3AB-89D5-4544-A782-D03ED3BE760F}
[2011/05/19 07:51:08 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Local\{E969AC03-4D9D-43E1-91C2-E0C5651296AE}
[2011/05/18 23:19:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/05/18 23:19:37 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/05/18 23:19:32 | 000,272,896 | —- | C] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/05/18 23:19:32 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/05/18 23:19:32 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/05/18 23:19:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011/05/18 23:19:30 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/18 23:19:30 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/18 22:49:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2011/05/18 22:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xvid
[2011/05/18 22:46:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/05/18 22:46:44 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/05/18 22:46:43 | 000,000,000 | —D | C] – C:\Users\Susan Home\AppData\Roaming\Real
[2011/05/18 22:04:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/18 22:04:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/18 22:04:07 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/18 21:57:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\viewsonic
[2011/05/18 21:52:04 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2011/05/18 21:50:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2011/05/18 21:50:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/05/18 21:48:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ATI Technologies
[2011/05/18 21:48:25 | 000,116,240 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\drivers\AtihdW76.sys
[2011/05/18 21:48:07 | 000,450,560 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\SysNative\ATIDEMGX.dll
[2011/05/18 21:48:07 | 000,057,344 | —- | C] (AMD) – C:\Windows\SysNative\coinst.dll
[2011/05/18 21:46:23 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/17 15:37:32 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
[2011/06/17 14:45:51 | 000,000,352 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForSusan Home.job
[2011/06/17 14:09:01 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/17 14:09:01 | 000,624,384 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/17 14:09:01 | 000,106,502 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/17 13:59:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/17 08:08:20 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 08:08:20 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 08:03:26 | 000,000,304 | —- | M] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/06/17 08:00:41 | 536,305,663 | -HS- | M] () – C:\hiberfil.sys
[2011/06/16 08:20:19 | 000,355,304 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/11 11:28:49 | 000,850,986 | —- | M] () – C:\Users\Susan Home\Documents\regbackup.reg
[2011/06/11 10:55:49 | 000,002,999 | —- | M] () – C:\Users\Susan Home\Desktop\HiJackThis.lnk
[2011/06/10 18:47:35 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/10 08:46:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/08 21:38:21 | 000,002,249 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2011/06/08 19:07:24 | 000,132,560 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/06/08 19:07:24 | 000,022,992 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/06/08 19:07:22 | 000,546,256 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/06/08 19:07:22 | 000,456,144 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/06/08 19:07:22 | 000,398,800 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/06/08 19:07:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/06/08 19:07:22 | 000,067,024 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/06/08 19:07:22 | 000,028,624 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/06/08 19:07:20 | 000,738,768 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/06/08 19:07:20 | 000,390,608 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/06/08 19:07:20 | 000,230,864 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/06/08 19:07:20 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/06/02 12:58:28 | 000,074,768 | R— | M] (iS3 Inc.) – C:\Windows\SysWow64\drivers\SZKG64.sys
[2011/06/02 12:58:28 | 000,074,768 | R— | M] (iS3 Inc.) – C:\Windows\SysWow64\drivers\is3srv64.sys
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/20 17:43:56 | 000,001,688 | —- | M] () – C:\Users\Public\Desktop\Business Card Designer 4.0.lnk
[2011/05/20 17:30:26 | 000,001,132 | —- | M] () – C:\Users\Susan Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/05/20 17:30:25 | 000,001,108 | —- | M] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2011/05/18 23:19:47 | 000,001,042 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/05/18 23:19:37 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/05/18 23:19:32 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/05/18 23:19:32 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/05/18 23:19:32 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/05/18 23:19:30 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/18 23:19:30 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/18 22:09:43 | 000,000,108 | —- | M] () – C:\Windows\VSWizard.ini
[2011/05/18 22:04:52 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/17 08:03:26 | 000,000,304 | —- | C] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/06/11 11:28:48 | 000,850,986 | —- | C] () – C:\Users\Susan Home\Documents\regbackup.reg
[2011/06/11 10:55:49 | 000,002,999 | —- | C] () – C:\Users\Susan Home\Desktop\HiJackThis.lnk
[2011/06/10 18:47:35 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/08 21:38:20 | 000,002,249 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2011/05/20 17:43:55 | 000,001,688 | —- | C] () – C:\Users\Public\Desktop\Business Card Designer 4.0.lnk
[2011/05/20 17:30:26 | 000,001,132 | —- | C] () – C:\Users\Susan Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/05/20 17:30:25 | 000,001,108 | —- | C] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2011/05/20 12:42:17 | 000,000,352 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForSusan Home.job
[2011/05/18 23:21:58 | 000,703,488 | —- | C] () – C:\Windows\SysNative\xvidcore.dll
[2011/05/18 23:21:58 | 000,650,752 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/18 23:21:58 | 000,255,488 | —- | C] () – C:\Windows\SysNative\xvidvfw.dll
[2011/05/18 23:21:58 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/18 23:21:58 | 000,173,056 | —- | C] () – C:\Windows\SysNative\xvid.ax
[2011/05/18 23:21:58 | 000,152,064 | —- | C] () – C:\Windows\SysWow64\xvid.ax
[2011/05/18 23:19:47 | 000,001,042 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/05/18 22:04:51 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/05/18 22:04:49 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/18 21:55:32 | 000,000,108 | —- | C] () – C:\Windows\VSWizard.ini
[2011/05/18 21:48:07 | 000,076,216 | —- | C] () – C:\Windows\SysNative\atiapfxx.blb
[2011/05/18 21:48:07 | 000,021,866 | —- | C] () – C:\Windows\atiogl.xml
[2011/05/18 21:48:07 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/18 21:48:07 | 000,002,857 | —- | C] () – C:\Windows\SysNative\atipblag.dat
[2011/05/12 21:09:45 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/05/12 18:30:48 | 000,000,178 | —- | C] () – C:\Windows\SysWow64\HPPA.ini
[2011/05/12 15:43:30 | 000,730,638 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/02 16:07:34 | 000,014,051 | —- | C] () – C:\Windows\SysWow64\RaCoInst.dat
[2011/04/02 15:54:12 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/09/21 10:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/12 15:55:00 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\Blio
[2011/05/12 14:22:44 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\PictureMover
[2011/05/14 21:52:29 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\SoftGrid Client
[2011/05/12 15:44:26 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\TP
[2011/05/12 15:50:15 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\WildTangent
[2011/05/12 18:11:44 | 000,000,000 | —D | M] – C:\Users\Susan Home\AppData\Roaming\Windows Live Writer
[2009/07/13 22:08:49 | 000,018,354 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/24 12:22:29 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/17 08:00:41 | 536,305,663 | -HS- | M] () – C:\hiberfil.sys
[2011/04/02 17:39:02 | 000,000,000 | RHS- | M] () – C:\OS
[2011/06/17 08:00:42 | 2146,734,079 | -HS- | M] () – C:\pagefile.sys
[2010/08/06 18:26:40 | 000,047,104 | -HS- | M] () – C:\Thumbs.db
< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/12 14:24:06 | 000,000,221 | -HS- | M] () – C:\Users\Susan Home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/17 15:37:32 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Susan Home\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >
—–EXTRAS.TXT
OTL Extras logfile created on: 6/17/2011 3:40:05 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Susan Home\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 70.97% Memory free
12.00 Gb Paging File | 9.60 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.50 Gb Total Space | 868.83 Gb Free Space | 94.59% Space Free | Partition Type: NTFS
Drive D: | 12.92 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS
Drive H: | 488.25 Mb Total Space | 39.17 Mb Free Space | 8.02% Space Free | Partition Type: FAT
Drive J: | 981.05 Mb Total Space | 707.49 Mb Free Space | 72.12% Space Free | Partition Type: FAT32
Drive K: | 232.88 Gb Total Space | 176.90 Gb Free Space | 75.96% Space Free | Partition Type: NTFS
Computer Name: SUSANHOME-HP | User Name: Susan Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{67048E0C-29A5-534C-FF67-83C4BF948D48}" = AMD Drag and Drop Transcoding
"{6888C635-E550-4FA4-958E-CE2880B0443B}" = HP Power Assistant
"{70DFF8B2-44A3-2C2C-FB21-783E8291265F}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}" = HP MediaSmart SmartMenu
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{D87047B9-BBC5-9941-00B4-719B9E56CACC}" = ATI AVIVO64 Codecs
"{D9B52C63-4209-7129-BF10-FA5DCD38579E}" = ccc-utility64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06092909-8851-C581-F990-7195076FDAEF}" = CCC Help Czech
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CA04779-346C-30FD-EB9B-8EEA2CE094B3}" = CCC Help Thai
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B3B5C60-70B8-F022-5497-03FD2772586C}" = CCC Help Greek
"{1C160168-BF5B-72FE-BAFA-6DD5F737404C}" = CCC Help Chinese Standard
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1ED3EBF6-A130-4B3B-B01A-C29B067798B3}" = CCC Help Finnish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{264FE20A-757B-492a-B0C3-4009E2997D8A}" = PictureMover
"{278AD90C-D27D-AA89-58DF-AD13852D51CA}" = CCC Help Spanish
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CDBFF1A-6433-E94D-CA25-831FDB9775E9}" = CCC Help Italian
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{31DED885-1124-0E58-97FB-73E4EF692E8D}" = CCC Help Hungarian
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33B670D7-8A06-DA5B-0341-5630D1E12007}" = ccc-core-static
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38D65ABC-A00B-6E13-2EF3-826CFC8CFC14}" = CCC Help French
"{3B4325A0-43CD-10D1-64F6-BD2F90DCB756}" = Catalyst Control Center Graphics Previews Vista
"{3F8B39A4-B7CE-B036-941C-A8DB57676B04}" = CCC Help Norwegian
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{465210C4-595A-BD80-44E8-E0457D9D8432}" = Zinio Reader 4
"{4ACF9BBA-E137-7309-7BF9-567ADAB6B4E6}" = CCC Help Turkish
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{51AD839D-CE11-B9E3-227D-03BC89F227C8}" = CCC Help Danish
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{55043DDE-D718-C7F7-9B4C-2B3D818D8A1F}" = Catalyst Control Center InstallProxy
"{5774B4C1-8579-D5D9-8D38-A0CE32B6736C}" = CCC Help German
"{5D19BB0D-9B04-5B85-9295-4E11BCB1C2C3}" = CCC Help Polish
"{60341104-FC8E-EF26-12CB-93B17DF55976}" = CCC Help Japanese
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{62161867-51F1-9FB8-0E6E-FE49D89CBB71}" = CCC Help Dutch
"{65589581-920C-CAE1-58C2-2149D3AA3F39}" = HydraVision
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A7E9B60-4698-F505-CAD3-05F8AB22FB61}" = CCC Help Russian
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75794DD1-5D69-4E33-A141-C3D4B0724C71}" = Catalyst Control Center Graphics Previews Common
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{795A3A1E-E06A-4214-A2EF-3DDF3BA05C2B}" = STOPzilla
"{7CE47764-9A8F-380D-FB9E-FCFC37B9F727}" = CCC Help Korean
"{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}" = HP Support Information
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D3903E2-4B1B-4A69-B8F6-A3D1BE075BDB}" = Blio
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT2860 Wireless LAN Card
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{912CED74-88D3-4C5B-ACB0-13231864975E}" = PressReader
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9ED77550-AF66-2B7E-97E1-34B3BFDEAC6D}" = CCC Help Swedish
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B1A4A13D-4665-4ED3-9DFE-F845725FBBD8}" = HP Support Assistant
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E8454B5F-4122-864C-002D-31F878D2CBF4}" = CCC Help English
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E6252F-8DC2-B508-D412-1C427CDB3448}" = CCC Help Portuguese
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FCB6F9DC-A0FF-621E-DE53-877E63864DD1}" = CCC Help Chinese Traditional
"{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}" = LightScribe System Software
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE4466A3-76B3-A9F4-9B22-150D6F8B4647}" = Catalyst Control Center Localization All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Business Card Designer 4.0" = Business Card Designer 4.0
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Kobo" = Kobo
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"My HP Game Console" = HP Game Console
"NIS" = Norton Internet Security
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PDF Complete" = PDF Complete Special Edition
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1" = Zinio Reader 4
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HuluDesktop" = Hulu Desktop
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/28/2011 4:28:29 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/30/2011 4:50:47 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/31/2011 7:12:54 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 5/31/2011 11:13:47 PM | Computer Name = SusanHome-HP | Source = Application Error | ID = 1000
Description = Faulting application name: BusinessCardDesigner.exe, version: 4.0.0.0,
time stamp: 0x4cfdd484 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x00000000 Faulting process id:
0xf78 Faulting application start time: 0x01cc2009e523aa64 Faulting application path:
C:\BusinessCardDesigner\dep\BusinessCardDesigner.exe Faulting module path: unknown
Report
Id: 2a003cf6-8bfd-11e0-ae8b-78acc0c0d628
Error - 6/1/2011 12:34:02 AM | Computer Name = SusanHome-HP | Source = Application Error | ID = 1000
Description = Faulting application name: WINWORD.EXE, version: 10.0.2627.0, time
stamp: 0x3a9cdbe7 Faulting module name: WINWORD.EXE, version: 10.0.2627.0, time
stamp: 0x3a9cdbe7 Exception code: 0xc0000005 Fault offset: 0x0001d5e7 Faulting process
id: 0x10fc Faulting application start time: 0x01cc200a775fbd6e Faulting application
path: C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE Faulting module
path: C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE Report Id: 5f777105-8c08-11e0-ae8b-78acc0c0d628
Error - 6/1/2011 1:03:34 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/2/2011 5:23:40 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/3/2011 9:50:46 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/4/2011 8:55:14 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 6/5/2011 11:48:37 PM | Computer Name = SusanHome-HP | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
[ System Events ]
Error - 5/31/2011 11:02:01 PM | Computer Name = SusanHome-HP | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:30:54 PM on ?5/?31/?2011 was unexpected.
Error - 6/1/2011 11:58:34 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the lmhosts service.
Error - 6/9/2011 4:32:07 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7030
Description = The Bandoo Coordinator service is marked as an interactive service.
However, the system is configured to not allow interactive services. This service
may not function properly.
Error - 6/12/2011 1:05:25 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 12:34:42 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 2:34:16 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/12/2011 6:38:33 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/13/2011 11:58:02 AM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
Error - 6/13/2011 11:14:26 PM | Computer Name = SusanHome-HP | Source = DCOM | ID = 10010
Description =
Error - 6/14/2011 12:28:10 PM | Computer Name = SusanHome-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
is3srv
< End of report >