This is a read-only archive. No new posts or registrations. Privacy Page
Hardware

Windows XP Recovery & Network Conntections

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

A month ago I caught XP recovery, I did not start a post, but rather followed the instructions from one by myself. Now my PC has no network connections and in the device manager even the PORTS option is missing. I will next copy and paste the OTL results as directed.

I have also posted my issue in the Hardware> Networking forum. They directed me here first.

Thank you in advance.




OTL logfile created on: 6/19/2011 5:47:23 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Eliza Robinson\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.36% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.80 Gb Total Space | 27.17 Gb Free Space | 38.92% Space Free | Partition Type: NTFS
Drive K: | 1863.01 Gb Total Space | 1701.47 Gb Free Space | 91.33% Space Free | Partition Type: NTFS
Drive V: | 1.92 Gb Total Space | 1.90 Gb Free Space | 99.16% Space Free | Partition Type: FAT32

Computer Name: INKBALL | User Name: Eliza Robinson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Eliza Robinson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcupdate.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Eliza Robinson\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SupportSoft RemoteAssist) – File not found
SRV - (HidServ) – File not found
SRV - (Acuamvcmicer) – File not found
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (Intel® PROSet Monitoring Service) Intel® – C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MOBKbackup) – C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
SRV - (PinnacleSys.MediaServer) – c:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe (Pinnacle Systems)
SRV - (MSSQL$PINNACLESYS) – C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$PINNACLESYS) – C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – C:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (ohci1394) – C:\WINDOWS\system32\DRIVERS\ohci1394.sy@ (Microsoft Corporation)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ElbyDelay) – C:\WINDOWS\system32\drivers\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (WD_FireWire_HID) – C:\WINDOWS\system32\drivers\wdfwhid.sys (Western Digital Technologies)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (ASAPIW2K) – C:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://www.bing.com/?pc=ZUGO&form=ZGAPHP"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=ZUGO&form=ZGAADF&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/05/25 02:59:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/24 03:09:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/04 11:51:06 | 000,000,000 | —D | M]

[2008/09/03 21:17:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Eliza Robinson\Application Data\Mozilla\Extensions
[2011/06/18 07:14:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Eliza Robinson\Application Data\Mozilla\Firefox\Profiles\d9bhrmf5.default\extensions
[2010/08/14 21:02:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Eliza Robinson\Application Data\Mozilla\Firefox\Profiles\d9bhrmf5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/28 10:40:26 | 000,000,000 | —D | M] (Search Toolbar) – C:\Documents and Settings\Eliza Robinson\Application Data\Mozilla\Firefox\Profiles\d9bhrmf5.default\extensions\[removed]
[2011/05/28 10:40:28 | 000,001,919 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Application Data\Mozilla\Firefox\Profiles\d9bhrmf5.default\searchplugins\bing-zugo.xml
[2011/06/18 07:14:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/14 04:18:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/02/01 20:46:03 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/25 02:59:23 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/06/18 16:18:23 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110524030947.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Eliza Robinson\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: hackerwatch.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: mcafee.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: siteadvisor.com ([]* in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://sslvpn.asu.edu/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: Web-Based Email Tools http://email.secureserver.net/Download.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/03 21:20:17 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/05/28 23:09:26 | 000,000,000 | R–D | M] - K:\autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.PIM1 - C:\WINDOWS\System32\pclepim1.dll (Pinnacle Systems)
Drivers32: vidc.wmv3 - C:\Program Files\Combined Community Codec Pack\Filters\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2011/06/19 05:41:00 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Eliza Robinson\Desktop\OTL.exe
[2011/06/19 05:38:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/06/18 19:28:00 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\simptcp.dll
[2011/06/18 19:12:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Eliza Robinson\Desktop\INPENUXP
[2011/06/18 19:12:24 | 008,745,368 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Eliza Robinson\Desktop\R105788.EXE
[2011/06/18 16:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Intel Network Adapters
[2011/06/18 15:59:16 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/06/18 15:59:16 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/06/18 15:59:16 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/06/18 15:59:16 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/06/18 15:59:11 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/06/18 15:57:44 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/18 15:56:58 | 004,130,419 | R— | C] (Swearware) – C:\Documents and Settings\Eliza Robinson\Desktop\ComboFix.exe
[2011/06/18 15:33:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Eliza Robinson\Desktop\ssdkt
[2011/06/18 08:40:49 | 000,112,800 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\IPROSetMonitor.exe
[2011/06/18 08:40:30 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2011/06/18 08:32:01 | 028,137,600 | —- | C] (Intel ) – C:\Documents and Settings\Eliza Robinson\Desktop\PROWin32.exe
[2011/05/28 15:41:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/28 15:27:44 | 000,000,000 | R–D | C] – C:\Documents and Settings\Eliza Robinson\Recent
[2011/05/28 13:02:13 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\GroupPolicy
[2004/11/24 12:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Eliza Robinson\*.tmp files -> C:\Documents and Settings\Eliza Robinson\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/19 05:39:10 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/19 05:38:36 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/19 05:38:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/19 05:37:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/19 05:37:45 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2011/06/19 05:35:58 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Eliza Robinson\Desktop\OTL.exe
[2011/06/18 19:50:50 | 000,071,260 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\oldSUBKEY_NETWORK.reg
[2011/06/18 19:48:37 | 000,000,440 | RHS- | M] () – C:\Documents and Settings\Eliza Robinson\ntuser.pol
[2011/06/18 19:07:04 | 008,745,368 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Eliza Robinson\Desktop\R105788.EXE
[2011/06/18 19:03:26 | 000,156,676 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\INPENUXP.cab
[2011/06/18 18:56:19 | 000,002,415 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2011/06/18 16:58:51 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2011/06/18 16:18:23 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/18 15:54:56 | 004,130,419 | R— | M] (Swearware) – C:\Documents and Settings\Eliza Robinson\Desktop\ComboFix.exe
[2011/06/18 15:22:38 | 000,139,264 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\RKUnhookerLE.EXE
[2011/06/18 15:15:38 | 001,007,120 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\WiNlOgOn.exe
[2011/06/18 15:14:56 | 001,007,120 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\iExplore.exe
[2011/06/18 15:10:22 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/06/18 15:10:21 | 000,000,349 | —- | M] () – C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2011/06/18 15:06:44 | 000,000,209 | -HS- | M] () – C:\boot.ini
[2011/06/18 10:38:04 | 001,309,375 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\ssdkt.zip
[2011/06/18 08:36:44 | 000,198,144 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/18 08:25:26 | 028,137,600 | —- | M] (Intel ) – C:\Documents and Settings\Eliza Robinson\Desktop\PROWin32.exe
[2011/06/18 03:15:45 | 000,463,622 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/18 03:15:45 | 000,080,614 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/18 03:12:50 | 000,000,127 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2011/06/18 03:06:55 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/06/06 22:27:50 | 000,001,742 | —- | M] () – C:\Documents and Settings\Eliza Robinson\My Documents\Default.rdp
[2011/06/06 20:43:06 | 000,000,571 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\Shortcut to mstsc.lnk
[2011/06/06 07:36:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/31 23:16:58 | 000,001,057 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\Dropbox.lnk
[2011/05/28 22:59:37 | 000,002,351 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/28 15:41:34 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/24 08:23:39 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Eliza Robinson\*.tmp files -> C:\Documents and Settings\Eliza Robinson\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/18 19:50:50 | 000,071,260 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\oldSUBKEY_NETWORK.reg
[2011/06/18 19:12:24 | 000,156,676 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\INPENUXP.cab
[2011/06/18 16:58:51 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/06/18 16:09:59 | 000,000,493 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2011/06/18 16:09:34 | 000,001,868 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows 7 Upgrade Advisor.lnk
[2011/06/18 16:09:34 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2011/06/18 16:09:34 | 000,000,609 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/06/18 16:09:33 | 000,002,245 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Illustrator CS2.lnk
[2011/06/18 16:09:33 | 000,001,934 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Plus! Photo Story 2 LE.lnk
[2011/06/18 16:09:33 | 000,001,890 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2011/06/18 16:09:33 | 000,001,866 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 6.0.lnk
[2011/06/18 16:09:33 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/06/18 16:09:33 | 000,001,774 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Stock Photos.lnk
[2011/06/18 16:09:33 | 000,001,744 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Help Center.lnk
[2011/06/18 16:09:33 | 000,001,466 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Media Center.lnk
[2011/06/18 16:09:33 | 000,001,100 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2011/06/18 16:09:33 | 000,000,942 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2011/06/18 16:09:33 | 000,000,721 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\RealPlayer.lnk
[2011/06/18 16:09:32 | 000,001,800 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge.lnk
[2011/06/18 16:09:32 | 000,000,911 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Device Central CS3.lnk
[2011/06/18 16:09:32 | 000,000,818 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS3.lnk
[2011/06/18 15:59:16 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/06/18 15:59:16 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/06/18 15:59:16 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/06/18 15:59:16 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/06/18 15:59:16 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/06/18 15:24:53 | 001,309,375 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\ssdkt.zip
[2011/06/18 15:24:52 | 001,007,120 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\WiNlOgOn.exe
[2011/06/18 15:24:49 | 000,139,264 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\RKUnhookerLE.EXE
[2011/06/18 15:24:48 | 001,007,120 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\iExplore.exe
[2011/06/18 10:02:17 | 000,024,362 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\nettcpip.inf
[2011/06/18 08:40:08 | 000,001,904 | —- | C] () – C:\WINDOWS\System32\SetupBD.din
[2011/06/06 20:43:06 | 000,000,571 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Desktop\Shortcut to mstsc.lnk
[2011/05/28 23:03:24 | 000,001,862 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows 7 Upgrade Advisor.lnk
[2011/05/28 23:03:24 | 000,001,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Studio Launcher.lnk
[2011/05/28 23:03:24 | 000,001,620 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/28 23:03:24 | 000,001,478 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2011/05/28 23:03:24 | 000,000,923 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2011/05/28 23:03:24 | 000,000,818 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/05/28 23:03:24 | 000,000,815 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/28 23:03:24 | 000,000,800 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/05/28 23:03:24 | 000,000,792 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/05/28 23:03:24 | 000,000,079 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/05/28 23:03:23 | 000,002,415 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2011/05/28 23:03:23 | 000,002,361 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk
[2011/05/28 23:03:23 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/28 23:03:23 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/05/28 23:03:23 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/28 23:03:23 | 000,000,852 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CloneDVD2.lnk
[2011/05/28 23:03:23 | 000,000,797 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2011/05/28 23:03:23 | 000,000,762 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2011/05/28 23:03:23 | 000,000,754 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AnyDVD.lnk
[2011/05/28 23:03:23 | 000,000,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2011/05/28 22:59:37 | 000,002,351 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/28 15:41:34 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/28 13:03:44 | 000,000,440 | RHS- | C] () – C:\Documents and Settings\Eliza Robinson\ntuser.pol
[2010/09/25 01:39:51 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/08/21 02:04:14 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\2QX88WVb.dat
[2010/07/24 14:08:46 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/12/14 16:33:07 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2009/09/14 22:08:05 | 000,072,692 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2007/09/18 20:27:09 | 000,061,678 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\PFP120JPR.{PB
[2007/09/18 20:27:09 | 000,012,358 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\PFP120JCM.{PB
[2007/06/25 17:40:55 | 000,000,083 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/04/24 22:51:27 | 000,000,017 | —- | C] () – C:\WINDOWS\MovingPicture.ini
[2007/03/20 21:17:25 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/12/03 21:33:58 | 000,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2006/12/03 21:20:17 | 000,001,289 | —- | C] () – C:\WINDOWS\VFO.INI
[2006/12/03 21:20:16 | 000,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2006/12/03 21:20:16 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2006/12/03 21:20:16 | 000,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2006/12/03 21:20:16 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2006/12/03 21:20:13 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/11/26 21:04:44 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2006/11/02 09:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2006/10/28 11:10:44 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2006/08/22 21:06:56 | 000,000,145 | —- | C] () – C:\WINDOWS\System32\EBPPORT.DAT
[2006/07/16 17:38:29 | 000,000,592 | —- | C] () – C:\WINDOWS\eReg.dat
[2006/07/16 14:39:08 | 000,005,632 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Application Data\dvd.bmk
[2006/07/11 18:40:24 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\76527FB35D.sys
[2006/07/05 22:28:29 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/07/03 23:56:03 | 000,001,783 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/06/29 18:07:30 | 000,198,144 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/28 20:12:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/28 19:21:42 | 000,000,137 | —- | C] () – C:\Documents and Settings\Eliza Robinson\Local Settings\Application Data\fusioncache.dat
[2006/06/22 23:34:48 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/22 23:30:38 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/06/22 23:26:52 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/06/22 23:22:55 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/22 22:57:44 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/22 22:57:42 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/06/22 22:57:10 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 06:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 02:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 02:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 02:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 02:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 02:27:59 | 001,628,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 02:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 02:18:33 | 000,463,622 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 02:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 02:18:33 | 000,080,614 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 02:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 02:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 02:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 02:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 02:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 02:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 02:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 02:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 12:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/29 11:38:24 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/10/08 23:40:16 | 000,454,144 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2004/10/03 10:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/04/05 07:41:02 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/04/05 07:36:48 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/03/11 00:26:10 | 000,406,016 | —- | C] () – C:\WINDOWS\System32\PSDrvCheck.exe
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/05/21 22:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2010/07/28 21:18:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2007/06/25 17:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2007/04/24 22:50:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2007/04/24 22:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2006/12/03 21:22:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/07/13 20:11:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/03/28 03:50:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/01/20 00:13:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visix
[2009/03/17 00:46:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/05/17 17:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 23:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/27 22:12:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/03/19 20:30:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Alien Skin
[2006/07/29 20:18:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\allTunes
[2007/01/18 23:06:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\bang
[2009/11/15 17:17:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Cisco
[2009/07/29 21:41:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Costco Photo Viewer US
[2011/06/18 02:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Dropbox
[2006/08/03 20:04:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Leadertech
[2007/02/01 18:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Opera
[2006/06/29 21:22:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Publish Providers
[2011/06/18 16:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Reno 911 Paintball
[2006/11/26 20:42:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Simple Star
[2007/06/25 17:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\SlySoft
[2006/12/04 18:06:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Snapfish
[2006/09/01 17:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Sony
[2011/06/02 18:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\uTorrent
[2007/03/24 23:01:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Viewpoint
[2011/01/20 00:13:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Eliza Robinson\Application Data\Visix

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/12/03 21:20:17 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2011/06/18 15:06:44 | 000,000,209 | -HS- | M] () – C:\boot.ini
[2011/06/18 16:29:37 | 000,020,465 | —- | M] () – C:\ComboFix.txt
[2005/08/16 02:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/06/22 23:01:50 | 000,006,804 | R— | M] () – C:\dell.sdr
[2007/04/06 17:34:16 | 000,021,230 | —- | M] () – C:\EyeCandyLog.txt
[2011/06/19 05:37:45 | 2145,538,048 | -HS- | M] () – C:\hiberfil.sys
[2006/06/28 20:27:47 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 02:43:04 | 000,000,000 | —- | M] () – C:\IO.SYS
[2007/03/20 21:21:30 | 000,002,321 | —- | M] () – C:\IPH.PH
[2005/08/16 02:43:04 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/10 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/11 21:58:03 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/19 05:37:26 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/06/18 15:27:52 | 000,000,359 | —- | M] () – C:\rkill.log
[2006/06/22 23:24:06 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/05/28 15:40:41 | 000,058,108 | —- | M] () – C:\TDSSKiller.2.5.3.0_28.05.2011_15.39.10_log.txt
[2011/06/18 15:33:57 | 000,057,870 | —- | M] () – C:\TDSSKiller.2.5.5.0_18.06.2011_15.33.13_log.txt
[2007/01/20 16:06:17 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 02:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2004/03/22 15:17:06 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2005/01/30 09:50:26 | 000,012,151 | —- | M] () – C:\WINDOWS\system32\logoxp.jpg
[10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2006/05/18 12:20:35 | 000,319,488 | —- | M] (Nero AG / Nero Inc.) – C:\WINDOWS\Nero PhotoShow.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 02:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 02:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 02:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/08/16 02:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/06/18 15:54:56 | 004,130,419 | R— | M] (Swearware) – C:\Documents and Settings\Eliza Robinson\Desktop\ComboFix.exe
[2011/06/18 15:14:56 | 001,007,120 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\iExplore.exe
[2011/06/19 05:35:58 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Eliza Robinson\Desktop\OTL.exe
[2011/06/18 08:25:26 | 028,137,600 | —- | M] (Intel ) – C:\Documents and Settings\Eliza Robinson\Desktop\PROWin32.exe
[2011/06/18 19:07:04 | 008,745,368 | —- | M] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\Documents and Settings\Eliza Robinson\Desktop\R105788.EXE
[2011/06/18 15:22:38 | 000,139,264 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\RKUnhookerLE.EXE
[2011/06/18 15:15:38 | 001,007,120 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\WiNlOgOn.exe
[2006/11/03 19:08:20 | 006,261,916 | —- | M] () – C:\Documents and Settings\Eliza Robinson\Desktop\XP Codec Pack 2.0.6.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-18 10:16:03

< End of report >
Here is the Extras report from OTL as well:


OTL Extras logfile created on: 6/19/2011 5:47:23 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Eliza Robinson\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.36% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.80 Gb Total Space | 27.17 Gb Free Space | 38.92% Space Free | Partition Type: NTFS
Drive K: | 1863.01 Gb Total Space | 1701.47 Gb Free Space | 91.33% Space Free | Partition Type: NTFS
Drive V: | 1.92 Gb Total Space | 1.90 Gb Free Space | 99.16% Space Free | Partition Type: FAT32

Computer Name: INKBALL | User Name: Eliza Robinson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"28066:TCP" = 28066:TCP:*:Enabled:spport
"21921:TCP" = 21921:TCP:*:Enabled:spport
"28496:TCP" = 28496:TCP:*:Enabled:spport

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
"C:\Program Files\utorrent\utorrent.exe" = C:\Program Files\utorrent\utorrent.exe:*:Enabled:µTorrent – ()
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems, Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi – (Pinnacle Systems, Inc.)
"C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe:*:Enabled:Dreamweaver MX 2004 – (Macromedia, Inc.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Documents and Settings\Eliza Robinson\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Eliza Robinson\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 24
"{27C467F8-F8EF-4f68-BD72-D63632B2096C}" = McAfee Online Backup
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A6355EB-273D-4368-9DB6-FB99EBA9FABD}" = Cisco AnyConnect VPN Client
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150070}" = J2SE Runtime Environment 5.0 Update 7
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{44663264-E108-4938-BF9E-A767315072C9}" = Intel® Network Connections [removed]
"{460CE8B9-6EC2-458A-90D4-691631ECE9D9}" = Pinnacle MediaServer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4C643986-DE3C-4737-8472-CCEC36CCC267}" = Studio Content CD
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{53EF6570-21A4-47ED-A40A-E6470A5677A3}" = Studio 8
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5636E517-8100-4E2A-B69E-2B16AFFA2360}" = Sony Sound Forge 8.0d
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A012D9C-2E2E-405A-B87C-E909F5297C3F}" = Studio 10 Bonus DVD
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6D10C4BE-0C36-4F4E-8C3A-E5E867A5F01D}" = QuickConnect
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F512339-216D-4FBE-8A83-3EDCC3F03F51}" = WD Win98 SE USB Disk Driver, v1.00.09
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8F1A20DC-251D-47B0-91B7-DCA2523EE6C9}" = McAfee Virtual Technician
"{8F20D3F3-0B75-482D-8395-CF4530AE8874}" = AxisTV Display Layout Editor
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}" = DiscAPI (Studio 10)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFF4500E-C5D6-695D-A027-B3D4DDED2CC3}" = McAfee Online Backup
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (PINNACLESYS)
"{E2B4553B-D1A9-438B-8B39-55EDAD611033}" = Nero 7 Ultra Edition
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}" = Adobe Stock Photos 1.0
"{EEECE229-49F6-4851-A73A-99B058221F8C}" = RAPID (Studio 10)
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"AnyDVD" = AnyDVD
"ATI Display Driver" = ATI Display Driver
"BookSmart® 2.5.1 2.5.1" = BookSmart® 2.5.1 2.5.1
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CloneDVD2" = CloneDVD2
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Combined Community Codec Pack" = Combined Community Codec Pack 2006-07-28 (Remove Only)
"CSCLIB" = Canon Camera Support Core Library
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DPP" = Canon Utilities Digital Photo Professional 3.4
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EOS Utility" = Canon Utilities EOS Utility
"FileZilla" = FileZilla (remove only)
"Google Desktop" = Google Desktop
"Hollywood FX 4.6" = Pinnacle Hollywood FX 4.6
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"Macromedia Director MX 2004" = Macromedia Director MX 2004
"Magic ISO Maker v5.4 (build 0251)" = Magic ISO Maker v5.4 (build 0251)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MSC" = McAfee Internet Security
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyCamera" = Canon Utilities MyCamera
"Nero PhotoShow Express 4" = Nero PhotoShow Express 4
"Nero Sipps!UninstallKey" = Nero Sipps
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"RADVideo" = RAD Video Tools
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Viewpoint Toolbar" = Viewpoint Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.3
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"WinAce Archiver" = WinAce Archiver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XP Codec Pack" = XP Codec Pack
"XviD_is1" = XviD MPEG-4 Video Codec
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/18/2011 10:32:48 PM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service start on port 26000 failed: System.Net.Sockets.SocketException:
A socket operation encountered a dead network at System.Net.Sockets.Socket..ctor(AddressFamily
addressFamily, SocketType socketType, ProtocolType protocolType) at Belikov.GenuineChannels.GenuineTcp.TcpConnectionManager.StartListening(Object
endPointAsObject) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel.StartListening(Object
data) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel..ctor(IDictionary
properties, IClientChannelSinkProvider iClientChannelSinkProvider, IServerChannelSinkProvider
iServerChannelSinkProvider) at PinnacleSys.MediaServer.MediaServerService.Start()

Error - 6/18/2011 10:32:48 PM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service cannot be started. System.Net.Sockets.SocketException: A socket
operation encountered a dead network at PinnacleSys.MediaServer.MediaServerService.Start()

at PinnacleSys.MediaServer.MediaServerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)

Error - 6/18/2011 10:58:39 PM | Computer Name = INKBALL | Source = JavaQuickStarterService | ID = 1
Description =

Error - 6/18/2011 10:58:47 PM | Computer Name = INKBALL | Source = MSSQL$PINNACLESYS | ID = 19011
Description =

Error - 6/18/2011 10:59:01 PM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service start on port 26000 failed: System.Net.Sockets.SocketException:
A socket operation encountered a dead network at System.Net.Sockets.Socket..ctor(AddressFamily
addressFamily, SocketType socketType, ProtocolType protocolType) at Belikov.GenuineChannels.GenuineTcp.TcpConnectionManager.StartListening(Object
endPointAsObject) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel.StartListening(Object
data) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel..ctor(IDictionary
properties, IClientChannelSinkProvider iClientChannelSinkProvider, IServerChannelSinkProvider
iServerChannelSinkProvider) at PinnacleSys.MediaServer.MediaServerService.Start()

Error - 6/18/2011 10:59:02 PM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service cannot be started. System.Net.Sockets.SocketException: A socket
operation encountered a dead network at PinnacleSys.MediaServer.MediaServerService.Start()

at PinnacleSys.MediaServer.MediaServerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)

Error - 6/19/2011 8:38:02 AM | Computer Name = INKBALL | Source = JavaQuickStarterService | ID = 1
Description =

Error - 6/19/2011 8:38:15 AM | Computer Name = INKBALL | Source = MSSQL$PINNACLESYS | ID = 19011
Description =

Error - 6/19/2011 8:38:22 AM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service start on port 26000 failed: System.Net.Sockets.SocketException:
A socket operation encountered a dead network at System.Net.Sockets.Socket..ctor(AddressFamily
addressFamily, SocketType socketType, ProtocolType protocolType) at Belikov.GenuineChannels.GenuineTcp.TcpConnectionManager.StartListening(Object
endPointAsObject) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel.StartListening(Object
data) at Belikov.GenuineChannels.GenuineTcp.GenuineTcpChannel..ctor(IDictionary
properties, IClientChannelSinkProvider iClientChannelSinkProvider, IServerChannelSinkProvider
iServerChannelSinkProvider) at PinnacleSys.MediaServer.MediaServerService.Start()

Error - 6/19/2011 8:38:22 AM | Computer Name = INKBALL | Source = PinnacleSys.MediaServer | ID = 0
Description = Service cannot be started. System.Net.Sockets.SocketException: A socket
operation encountered a dead network at PinnacleSys.MediaServer.MediaServerService.Start()

at PinnacleSys.MediaServer.MediaServerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)

[ Cisco AnyConnect VPN Client Events ]
Error - 6/6/2011 10:48:44 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: RestoreProxySettingsToBrowser File: .\BrowserProxy.cpp Line:
1040 Invoked Function: DeleteFile Return Code: 2 (0x00000002) Description: The system
cannot find the file specified.

Error - 6/6/2011 11:40:47 PM | Computer Name = INKBALL | Source = vpnui | ID = 67108866
Description = Function: MsgCatalog::msgFormat File: .\i18n\MsgCatalog.cpp Line: 323
Invoked
Function: FormatMessage Return Code: 3 (0x00000003) Description: The system cannot
find the path specified.

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CSocketTransport::callbackHandler File: .\IPC\SocketTransport.cpp
Line:
1257 Invoked Function: WSAGetOverlappedResult Return Code: 10054 (0x00002746) Description:
An existing connection was forcibly closed by the remote host.

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CSocketTransport::callbackHandler File: .\IPC\SocketTransport.cpp
Line:
1258 Invoked Function: WSARecv/WSARecvFrom Return Code: 997 (0x000003E5) Description:
Overlapped I/O operation is in progress.

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CIpcTransport::OnSocketReadComplete File: .\IPC\IPCTransport.cpp
Line:
823 Invoked Function: CSocketTransport::readSocket Return Code: -31522801 (0xFE1F000F)
Description:
SOCKETTRANSPORT_ERROR_TRANSPORT_FAILURE

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CIpcDepot::OnIpcMessageReceived File: .\IPC\IPCDepot.cpp Line:
811 Invoked Function: CIpcTransport::OnSocketReadComplete Return Code: -31522801
(0xFE1F000F) Description: SOCKETTRANSPORT_ERROR_TRANSPORT_FAILURE

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CTcpTransport::writeSocketBlocking File: .\IPC\SocketTransport.cpp
Line:
1644 Invoked Function: WSASend Return Code: 10054 (0x00002746) Description: An existing
connection was forcibly closed by the remote host.

Error - 6/7/2011 4:51:54 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: CIpcTransport::terminateIpcConnection File: .\IPC\IPCTransport.cpp
Line:
385 Invoked Function: CSocketTransport::writeSocketBlocking Return Code: -31522805
(0xFE1F000B) Description: SOCKETTRANSPORT_ERROR_WRITE

Error - 6/7/2011 4:52:07 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67110873
Description = Termination reason code 5: The user is logging off the system.

Error - 6/7/2011 4:52:07 AM | Computer Name = INKBALL | Source = vpnagent | ID = 67108866
Description = Function: RestoreProxySettingsToBrowser File: .\BrowserProxy.cpp Line:
1040 Invoked Function: DeleteFile Return Code: 2 (0x00000002) Description: The system
cannot find the file specified.

[ System Events ]
Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7001
Description = The Cisco AnyConnect VPN Agent service depends on the TCP/IP Protocol
Driver service which failed to start because of the following error: %%31

Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%2

Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7024
Description = The Workstation service terminated with service-specific error 2250
(0x8CA).

Error - 6/18/2011 9:28:27 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7000
Description = The WebDav Client Redirector service failed to start due to the following
error: %%2

Error - 6/18/2011 9:42:11 PM | Computer Name = INKBALL | Source = Workstation | ID = 5727
Description = Could not load MRxSmb device driver.

Error - 6/18/2011 9:42:11 PM | Computer Name = INKBALL | Source = Workstation | ID = 5727
Description = Could not load RDR device driver.

Error - 6/18/2011 9:57:52 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7000
Description = The IPSEC driver service failed to start due to the following error:
%%2

Error - 6/18/2011 9:57:52 PM | Computer Name = INKBALL | Source = Service Control Manager | ID = 7000
Description = The AFD service failed to start due to the following error: %%2


< End of report >
Hello and welcome to the forum.

Lets see if we can get the PC back on the internet. This file will fit on a floppy or thumb drive.

Get a copy of winsockxpfix.exe and copy it to the infected computer.
You just run it and things should work OK after it reboots your system.

http://www.snapfiles.com/get/winsockxpfix.html
===================================================
Hi LDTate - I ran winsockxpfix.exe and rebooted the machine. But it didn't fix the issue the problem - yellow cautions are still listed for all items under network adapters in the device manager and no network connection is showing. It did repair registry errors however.
This is a hardware issue but lets see if this will work. In Device Manager, uninstall the network adaptors, reboot and let windows install them. If that doesn't work, my suggestion is to look for your cd with the drivers on it that came with the pc.
No go. Uninstall and re install with same effect. I do not have the original CDs, but downloaded the drivers from DELL - issue remains.
I've had stubborn cases where corrupt hardware drivers refused to let go - XP was good for that. I recommend you repeat LDTate's Device Manager, uninstall drivers steps, but instead of rebooting, shutdown and unplug the computer from the wall (or hit the master power switch, if your PSU has one). Wait 15 seconds or and start it up and see what happens. The ATX Form Factor standard requires +5Vsb voltage be applied across several points on the motherboard to keep them alive. These include "Wake on…" features, which includes Wake on LAN. Unplugging (or flipping master power switch) removes the standby voltage that may be holding some settings the driver update needs access to. If no good, you may need to boot into the BIOS Setup Menu to disable the device, then reboot to clear the settings. And if all else fails, you may need to buy or borrow a network card - to force Windows to see new hardware and use a different driver all together. Often, if I have a problem updating NVIDIA drivers, I will install an old ATI card to force a complete reset of Windows - then I reinstall the NVIDIA to reset it back, but correctly this time. I have a spare NVIDIA card in case I have the same problem with ATI/AMD drivers. And I have a spare NIC and sound card for the same purpose. Swapping hardware (and drivers) usually works. I'd also try another Ethernet cable. A flaky cable can really give some strange network errors. And you might even try a different port on the router - I have 3-port Linksys that used to be a 4-port. There's also sfc /scannow but you probably need an original disk for that.
OK tried it. Got a "Found Nardware message" but then followed with the "problem installing" message. I'm not too familiar with BIOS, is there a specific section I should look for in the boot menu where I can check if its been disabled?
quick update - NIC did not solve the issue. I am staking the system in for hands on support. Thank you so much for your time and assistance. This was truly puzzling issue.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI