tasman27
Topic Starter
My computer is acting up, getting a message that it will shut down in 60 secs with a countdown screen due to an error in a file called lsass.exe. I've been able to stop that, but little else.
I get a desktop background picture, but the icons are erratic loading as are the programs in the toolbar. In addition I've lost my broadband connection. Right now I'm working off my laptop and transferring 'fixes' via jump drive where I can. It's been getting progressively worse over the past 4-5 days. I've run Malbytes and it found 3 infections but apparently wasn't the fix.Also used Stinger . Whatever this is, it has a pretty good hold on my PC. Looking for some serious help!
I put these files on a jump drive and d/l them to here. No internet connection on the desktop….more files to come per the instructions.
OTL logfile created on: 7/30/2011 10:02:31 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.70 Gb Available Physical Memory | 83.09% Memory free
6.34 Gb Paging File | 5.81 Gb Available in Paging File | 91.72% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32
Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - H:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
PRC - C:\WINDOWS\system32\svcprs32.exe ()
PRC - C:\WINDOWS\system32\mdmcls32.exe ()
PRC - C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\Retrospect.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
PRC - C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
========== Modules (SafeList) ==========
MOD - H:\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\UmxSbxw.dll (CA)
MOD - C:\WINDOWS\system32\UmxSbxExw.dll (CA)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (WinSvchostManager) – C:\WINDOWS\system32\svcprs32.exe ()
SRV - (WinExtManager) – C:\WINDOWS\system32\mdmcls32.exe ()
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (QSCopyEngine) – C:\Program Files\Iomega\QuikProtect\QpMonitor.exe ()
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LinksysUpdater) – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (RetroExpLauncher) – C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
SRV - (p2pgasvc) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AtiHDAudioService) – C:\WINDOWS\system32\drivers\AtihdXP3.sys (Advanced Micro Devices)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (KmxAMRT) – C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\system32\drivers\KmxCfg.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\system32\drivers\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\system32\drivers\KmxCF.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\system32\drivers\KmxFw.sys (CA)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\system32\drivers\KmxSbx.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\system32\drivers\KmxAgent.sys (CA)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (KmxAMVet) – C:\WINDOWS\system32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (QsFsFltr) – C:\WINDOWS\system32\drivers\QsFsFltr.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NmPar) – C:\WINDOWS\system32\drivers\NmPar.sys (Windows ® 2000 DDK provider)
DRV - (nmserial) – C:\WINDOWS\system32\drivers\NmSerial.sys (Windows ® 2000 DDK provider)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (Pnp680r) – C:\WINDOWS\system32\DRIVERS\pnp680r.sys (Silicon Image, Inc)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
========== FireFox ==========
FF - user.js..browser.search.openintab: false
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\4.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/03 11:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\Firefox [2011/07/27 17:40:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions
[2010/08/14 08:42:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions
[2010/08/15 15:47:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/17 13:20:39 | 000,000,000 | —D | M] (AddThis) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/08/15 13:43:56 | 000,000,000 | —D | M] (IE View) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/09/05 17:51:44 | 000,000,000 | —D | M] (Ancestry Toolbar) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2010/08/26 19:18:19 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/30 08:50:58 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/10 11:21:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/10 20:55:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/12 22:26:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/06 20:48:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 21:28:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/25 16:19:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/01 08:41:18 | 000,000,000 | —D | M] (Babylon) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/06/23 19:27:32 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/01/02 08:43:19 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/06/23 19:27:28 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/08/15 18:50:39 | 000,003,803 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml
O1 HOSTS File: ([2011/07/27 19:50:31 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LELA] C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
O4 - HKLM..\Run: [RetroExpress] C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (UmxSbxExw.dll) - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 00:31:03 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SmartDefragBootTime.exe) - C:\WINDOWS\System32\SmartDefragBootTime.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/07/30 20:34:52 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\Malwarebytes
[2011/07/30 19:43:42 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/07/30 19:43:39 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/30 19:43:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/30 12:40:45 | 000,000,000 | RH-D | C] – C:\Documents and Settings\JIM\Recent
[2011/07/30 09:04:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/30 08:54:41 | 000,000,000 | —D | C] – C:\Program Files\WebEx
[2011/07/30 08:54:10 | 000,023,984 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\pnarp.sys
[2011/07/30 08:54:03 | 000,025,264 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\purendis.sys
[2011/07/30 08:53:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Pure Networks Shared
[2011/07/30 08:53:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2011/07/30 08:50:57 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/07/30 08:32:13 | 000,939,368 | R— | C] (Macromedia, Inc.) – C:\WINDOWS\System32\myflash.ocx
[2011/07/29 16:21:24 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/07/28 18:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/07/28 18:46:51 | 000,347,920 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 19:06:27 | 000,101,392 | —- | C] (Advanced Micro Devices) – C:\WINDOWS\System32\drivers\AtihdXP3.sys
[2011/07/27 19:05:59 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2011/07/27 19:05:04 | 000,000,000 | —D | C] – C:\ATI
[2011/07/27 17:40:05 | 000,000,000 | —D | C] – C:\Program Files\ISSThirdParty
[2011/07/27 17:39:49 | 001,028,096 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2011/07/27 17:39:49 | 000,200,704 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\ssleay32.dll
[2011/07/27 17:39:47 | 002,654,208 | —- | C] (PureSight Technologies Ltd) – C:\WINDOWS\System32\winsflte.dll
[2011/07/27 17:39:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CA
[2011/07/27 08:27:01 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/07/27 08:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Local Settings\Application Data\eSupport.com
[2011/07/26 22:39:03 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/07/24 19:59:30 | 000,202,064 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\Isafprod.dll
[2011/07/24 19:59:30 | 000,128,336 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Isafeif.dll
[2011/07/24 19:59:30 | 000,095,568 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Vetredir.dll
[2011/07/24 19:20:51 | 000,000,000 | —D | C] – C:\WINDOWS\rnapxs
[2011/07/24 19:20:50 | 000,007,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sporder.dll
[2011/07/24 19:18:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:50 | 157,866,568 | —- | C] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/07/24 09:11:07 | 000,000,000 | —D | C] – C:\Program Files\WhoCrashed
[2011/07/23 14:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Logitech
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control Software Common
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Logitech
[2011/07/23 14:21:38 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2011/07/23 14:21:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2011/07/23 14:20:13 | 048,357,912 | —- | C] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 16:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\.frostwire5
[2011/07/10 06:28:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/10/24 19:18:28 | 000,638,976 | —- | C] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/30 21:31:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/30 21:31:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/30 19:43:42 | 000,000,805 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 16:38:48 | 000,889,547 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/30 16:38:48 | 000,782,812 | —- | M] () – C:\WINDOWS\System32\drivers\KmxAgent.asc
[2011/07/30 16:38:48 | 000,010,421 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/30 16:38:48 | 000,000,593 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/30 16:38:48 | 000,000,293 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\tasks\RegistryBooster.job
[2011/07/30 13:13:25 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/30 13:13:24 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 13:13:22 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/07/30 12:05:02 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/30 11:07:43 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 09:15:06 | 000,540,196 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/30 09:15:06 | 000,102,218 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/30 09:03:48 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Linksys EasyLink Advisor.lnk
[2011/07/30 08:45:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/07/30 08:25:29 | 000,038,727 | —- | M] () – C:\WINDOWS\Ascd_tmp.ini
[2011/07/30 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 23:59:09 | 000,004,522 | —- | M] () – C:\WINDOWS\mozy.blk
[2011/07/27 23:59:09 | 000,002,208 | —- | M] () – C:\WINDOWS\mozy.flt
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/07/27 21:12:33 | 000,000,082 | —- | M] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 19:50:31 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 18:36:03 | 000,000,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/07/27 17:39:49 | 005,845,744 | —- | M] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,872,624 | —- | M] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:35:43 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/27 08:27:02 | 000,001,695 | —- | M] () – C:\Documents and Settings\JIM\Desktop\Uniblue RegistryBooster.lnk
[2011/07/27 08:27:02 | 000,001,672 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,713 | —- | M] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:55 | 000,000,852 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/07/24 06:34:55 | 000,000,834 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2011/07/24 06:28:44 | 000,000,699 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk
[2011/07/24 05:40:32 | 000,001,552 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AllMySongs Database.lnk
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/07/23 14:24:19 | 000,002,031 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 15:41:39 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/07/13 16:22:42 | 000,265,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/10 06:30:42 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/06 15:43:46 | 000,107,633 | —- | M] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:36:03 | 000,002,074 | -H– | M] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:57 | 000,424,031 | —- | M] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/07/06 15:23:07 | 000,002,315 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PaperPort.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/30 19:43:42 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/27 22:04:23 | 000,001,790 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/27 22:04:23 | 000,001,470 | —- | C] () – C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk
[2011/07/27 21:12:33 | 000,000,082 | —- | C] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 18:45:19 | 000,000,354 | —- | C] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 17:44:31 | 000,889,547 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/27 17:44:31 | 000,010,421 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/27 17:44:31 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/27 17:44:31 | 000,000,293 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/27 17:39:49 | 005,845,744 | —- | C] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,377,008 | —- | C] () – C:\WINDOWS\System32\svcprs32.exe
[2011/07/27 17:39:47 | 002,347,760 | —- | C] () – C:\WINDOWS\System32\mdmcls32.exe
[2011/07/27 17:39:47 | 001,872,624 | —- | C] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:39:47 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\winsfinst.exe
[2011/07/27 17:26:53 | 000,128,733 | —- | C] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/26 22:20:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/07/24 19:58:50 | 001,054,032 | —- | C] () – C:\WINDOWS\System32\cfgmig32.dll
[2011/07/24 19:20:52 | 002,385,136 | —- | C] () – C:\WINDOWS\System32\winsflt_x64.dll
[2011/07/24 09:11:08 | 000,000,713 | —- | C] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:58 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/07/24 06:34:57 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/07/24 05:39:04 | 011,193,773 | —- | C] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/23 14:24:19 | 000,002,031 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/06 15:43:45 | 000,107,633 | —- | C] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:33:19 | 000,002,074 | -H– | C] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:54 | 000,424,031 | —- | C] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/05/09 08:15:35 | 000,251,298 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/03/26 14:51:50 | 000,031,561 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/03/26 14:43:39 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2011/03/26 14:43:39 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2011/03/26 14:43:38 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2011/03/26 14:43:38 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2011/03/26 14:43:38 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2011/03/26 14:43:38 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2011/03/26 14:43:38 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2011/03/26 14:43:38 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2011/03/26 14:43:38 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2011/03/26 14:43:38 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2011/03/26 14:43:38 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2011/03/26 14:43:38 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2011/03/26 14:40:58 | 000,065,793 | —- | C] () – C:\WINDOWS\System32\esfw86.bin
[2011/03/26 14:40:11 | 000,000,044 | —- | C] () – C:\WINDOWS\WFGT1500.ini
[2011/01/02 11:33:50 | 000,027,801 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2011/01/02 11:33:50 | 000,007,765 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2011/01/02 11:04:11 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\gswin32c.exe
[2011/01/02 10:30:38 | 000,027,456 | —- | C] () – C:\WINDOWS\System32\solidlocalmon.dll
[2011/01/02 10:30:38 | 000,018,752 | —- | C] () – C:\WINDOWS\System32\solidlocalui.dll
[2011/01/02 10:23:04 | 000,020,886 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2011/01/02 08:43:30 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/11/15 21:08:52 | 000,000,537 | -H– | C] () – C:\Program Files\hpothb07.tif
[2010/11/15 21:08:52 | 000,000,327 | -H– | C] () – C:\Program Files\hpothb07.dat
[2010/08/15 22:37:19 | 001,669,496 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/15 21:53:37 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/08/15 21:22:20 | 000,013,312 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 18:49:49 | 000,000,302 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2010/08/15 18:48:49 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2010/08/15 18:09:51 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/14 08:42:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/11 19:54:18 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2010/08/11 09:21:11 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 02:48:28 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/11 02:44:10 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/08/11 02:42:05 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/08/11 02:42:00 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/11 02:41:59 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/11 02:41:58 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/08/11 02:41:58 | 000,227,587 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/11 01:18:34 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/08/11 01:18:34 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/08/11 01:18:33 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/08/11 01:18:33 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/08/11 00:56:45 | 000,039,119 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2010/08/11 00:56:37 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/11 00:56:28 | 000,038,727 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/11 00:56:27 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/11 00:51:42 | 000,000,158 | —- | C] () – C:\WINDOWS\pagesuit.ini
[2010/08/11 00:51:41 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\irisco32.dll
[2010/08/11 00:32:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 00:29:03 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 19:25:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 19:24:41 | 000,265,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/08/05 16:14:12 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ATIBRTMON.EXE
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/10/18 18:36:54 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\deskMenu2.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2002/08/29 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/08/29 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/08/29 07:00:00 | 000,540,196 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/08/29 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/08/29 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/08/29 07:00:00 | 000,102,218 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/08/29 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/08/29 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/08/29 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/05/29 08:50:02 | 000,552,960 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2000/08/29 03:59:12 | 002,971,392 | —- | C] () – C:\WINDOWS\Catherine Zeta Jones Saver V1.exe
[1999/01/22 13:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 03:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
========== LOP Check ==========
[2010/12/05 10:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/07/24 19:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2011/05/01 08:28:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/10/10 20:44:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 18:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2011/07/30 21:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RetroExp
[2011/03/27 11:28:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/01/02 10:29:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SolidDocuments
[2010/10/23 23:34:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2010/10/10 20:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/07/30 09:04:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/29 23:36:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/06/22 17:47:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011/05/01 09:55:11 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Acoustica
[2011/06/12 19:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/18 17:50:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EarMaster
[2011/07/28 18:48:19 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/03/26 15:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EPSON
[2011/06/07 20:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FixCleaner
[2010/09/18 17:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FreeFileViewer
[2011/07/24 05:59:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FrostWire
[2011/04/27 17:06:30 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\IObit
[2010/08/15 17:48:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\K9
[2011/03/26 15:04:07 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Leadertech
[2010/08/15 18:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\MyHeritage
[2011/03/26 14:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ScanSoft
[2010/08/15 17:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\The Complete Genealogy Reporter - FTB
[2010/08/14 08:42:46 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Thunderbird
[2010/08/11 01:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\TMP
[2011/06/06 08:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Uniblue
[2010/08/15 17:52:27 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VectorVest, Inc
[2011/06/17 20:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VSRevoGroup
[2011/06/27 15:24:55 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\webex
[2010/08/12 18:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Desktop Search
[2010/08/12 19:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Search
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2011/04/02 10:38:22 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1293986285.job
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\Tasks\RegistryBooster.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
[2010/12/31 19:54:43 | 000,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F9AF475E-4BA9-4B59-BA57-28BE3A55B301}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/05/28 18:58:40 | 014,970,880 | —- | M] () – C:\AdamsFanning.paf
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/30 23:56:13 | 000,001,360 | —- | M] () – C:\caEntitlementLog.txt
[2011/07/27 17:47:00 | 002,695,826 | —- | M] () – C:\caisslog.txt
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/02/28 14:23:24 | 008,109,897 | —- | M] () – C:\Fanning Family Tree.ged
[2011/05/28 18:58:22 | 003,265,738 | —- | M] () – C:\Fanning Family Tree.lst
[2010/02/28 14:32:19 | 001,575,056 | —- | M] () – C:\FFTree.zip
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/13 08:41:10 | 000,365,568 | —- | M] () – C:\market_timers.ppt
[2011/02/05 17:47:16 | 000,000,000 | —- | M] () – C:\Medical1.txt
[2007/03/10 13:48:13 | 000,030,208 | —- | M] () – C:\MenardsComp.xls
[2008/08/31 16:22:25 | 000,031,232 | —- | M] () – C:\MenardsExpenses.xls
[2009/10/31 23:27:50 | 000,384,512 | —- | M] () – C:\MenardsLeads.xls
[2009/10/25 09:43:19 | 000,054,784 | —- | M] () – C:\MenardsLeads1.xls
[2010/01/18 12:37:13 | 000,082,944 | —- | M] () – C:\MenardsPayroll.xls
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/11 09:39:59 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 20:49:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/30 21:31:05 | 3488,591,872 | -HS- | M] () – C:\pagefile.sys
[2011/07/30 08:41:12 | 000,000,032 | —- | M] () – C:\t.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/08/15 19:13:15 | 000,000,152 | —- | M] () – C:\YServer.txt
[2010/10/02 16:56:51 | 000,000,308 | R— | M] () – C:\YukonInstall.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/11 00:30:53 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/11/15 21:09:30 | 000,000,327 | -H– | M] () – C:\Program Files\hpothb07.dat
[2010/11/15 21:08:52 | 000,000,537 | -H– | M] () – C:\Program Files\hpothb07.tif
[2010/10/12 22:01:02 | 000,638,976 | —- | M] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/10 19:23:37 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/10 19:23:37 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/10 19:23:37 | 000,450,560 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 20:54:17 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/11 20:59:54 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/11 00:34:12 | 000,000,079 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/10/10 20:26:26 | 000,939,956 | —- | M] () – C:\Documents and Settings\JIM\Desktop\7z465.exe
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2009/01/31 20:50:36 | 000,524,288 | —- | M] (Chaos Software Group, Inc.) – C:\Documents and Settings\JIM\Desktop\Atomic.exe
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/06/16 18:45:58 | 027,862,496 | —- | M] () – C:\Documents and Settings\JIM\Desktop\family_tree_builder_5209i.exe
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2010/10/23 23:24:44 | 011,437,504 | —- | M] (Mozy, Inc.) – C:\Documents and Settings\JIM\Desktop\mozy-2_2_4_0.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-25 14:02:07
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\JIM\Desktop\Atomic.exe:SummaryInformation
< End of report >
OTL Extras logfile created on: 7/30/2011 9:45:51 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.72 Gb Available Physical Memory | 83.58% Memory free
6.34 Gb Paging File | 5.87 Gb Available in Paging File | 92.59% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32
Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe:*:Enabled:Iomega Home Media Network Discover Application – (Iomega Corporation)
"C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe:*:Enabled:Iomega Storage Manager – (Iomega Corp.)
"C:\Program Files\Iomega\QuikProtect\QuikProtect.exe" = C:\Program Files\Iomega\QuikProtect\QuikProtect.exe:*:Enabled:QuikProtect – (Iomega Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Thunderbird – (Mozilla Messaging)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0038B7BB-C6E6-59D4-8F6F-2B2E707F89F6}" = MozyHome
"{01A3E75B-54C0-407F-8B95-B77705C7DCC4}" = AMRT
"{022C4B5F-4A59-48DD-08A6-6EC5832DBFFE}" = Catalyst Control Center Localization Chinese Standard
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1148CE6F-6956-6ED3-1DBF-0A0046427A3E}" = CCC Help Swedish
"{1350E13C-A031-6574-961B-367DE4721E86}" = Catalyst Control Center Graphics Light
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{14A776EF-3904-3C55-508F-BB093954391E}" = Catalyst Control Center Localization Dutch
"{19762EA5-8279-8FA8-5F16-7DEEF571E5D6}" = CCC Help Russian
"{1A90FD8B-8A64-8B83-D486-E507AEC997EF}" = Catalyst Control Center Graphics Full Existing
"{1D4C0096-98D0-5290-A5F7-AAA05121FA0A}" = CCC Help Danish
"{2681A52E-FCFA-4982-A030-7B652BDD346C}" = CA Personal Firewall
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2E73FAB9-7713-D109-24DB-28339CB7A3CC}" = Catalyst Control Center Localization Norwegian
"{30517D85-B2C9-5920-77B2-6034DDC90B7C}" = CCC Help Czech
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35A6DE92-DE2E-9FBB-C919-B9CA5079116D}" = Catalyst Control Center Localization Turkish
"{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}" = WorkForce GT-1500 Scanner Driver Update
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{39C1585C-1004-5091-180A-5AFCA3D505C2}" = Catalyst Control Center Localization Thai
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{41269776-CF11-AADD-A1A9-6E1701877F88}" = CCC Help Norwegian
"{455B46A4-17C2-DDDA-F695-7F157E2C6160}" = Catalyst Control Center Localization Danish
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E10FFCA-5C09-6E8E-4DA4-B71FFC58C435}" = CCC Help Korean
"{4E568350-98BF-A31B-4E90-B23428023916}" = Catalyst Control Center Localization Spanish
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5827D56B-9A4D-6858-95C9-28B2D46F56EB}" = CCC Help German
"{5954C9DD-80C5-27FB-67FA-1DF0B5E2565A}" = Catalyst Control Center Localization Portuguese
"{5A05B328-35EB-4CED-B16F-62FA5A2642E6}" =
"{5B6844F3-8C27-C589-E519-9AAE0AC87407}" = CCC Help Dutch
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5DC1DF0D-8B08-30D9-5F5F-857ADC69201A}" = Catalyst Control Center Graphics Full New
"{5DDBDE45-EB70-DC65-6D06-6D25906E7797}" = CCC Help Japanese
"{5E075172-D826-3CFC-51F4-C9E6CF6D0690}" = CCC Help Spanish
"{618EB4D7-7D67-9126-7D63-CA39F93673DE}" = Catalyst Control Center Graphics Previews Common
"{67F5A666-181F-8AA1-0D4E-BAD64AD43B42}" = CCC Help Chinese Standard
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FB4970-45D2-1EA4-F131-A95EB60FFDDF}" = CCC Help Italian
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A053172-1F36-0307-4CA0-6AA9317EBCC1}" = CCC Help Turkish
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6B6F61D0-BBD0-E91F-8639-6EF30206ABD2}" = Catalyst Control Center Localization Japanese
"{71389CB1-6B6D-6FC2-0B74-0357D1ADC41E}" = CCC Help Finnish
"{736D005A-96E3-3B70-836C-14C80A137862}" = CCC Help French
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8124C5F0-D59A-DEFE-C3F7-02697D9BE53E}" = CCC Help Thai
"{82357963-7536-629A-F921-A3E72A5E124C}" = Catalyst Control Center Localization Korean
"{82DFB852-9594-4668-9C66-28BB6E94BCB2}" = HP Photo and Imaging 1.0 - PSC 2000 Series
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8625D3E5-2159-3FA4-3A74-AB306360E63E}" = Catalyst Control Center Localization Russian
"{888FAC3D-87CB-AB4C-EC2C-D17E0C4418E7}" = Catalyst Control Center Localization French
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{89FF3A82-A88F-4035-9E95-6E03B7BA9D9B}" = Catalyst Control Center Localization Swedish
"{8E3AA171-1D56-8A6B-E7A2-35D32800ECED}" = ATI Catalyst Install Manager
"{8E5EDE0A-6B13-A0E2-7F00-5C2660C9F771}" = Catalyst Control Center Localization Hungarian
"{8EE7E7B0-CEA9-E3FD-A63F-B27F49E9EC42}" = CCC Help Portuguese
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9418FEE4-28B4-96FD-C398-42654B956376}" = Skins
"{94AF0F78-E983-BD4B-1A26-80F2FBD5487C}" = Catalyst Control Center Localization Czech
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9749C770-90C4-EE5A-D3BB-287F53622104}" = Catalyst Control Center Core Implementation
"{99FC30C1-60A7-205F-1A00-367506E756F2}" = Catalyst Control Center Localization Greek
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}" = Readiris 7.5
"{9F36EDCC-81A8-5D37-9EB1-8BF6D96CAA23}" = Catalyst Control Center Localization Finnish
"{A0100CB5-E6CE-F516-59C1-28CF0195A875}" = ccc-core-preinstall
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A336E48B-A46E-81B5-936E-5A9A8D7FE3D8}" = CCC Help Hungarian
"{A4CCE9FD-4A40-5669-97B3-262672CD6C38}" = CCC Help Greek
"{A6B82920-25DD-41B5-A680-5B6FB65BA6D9}" = VectorVest U.S.
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.4
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B325EFE1-1301-5BC4-8788-B1C7D3702ED1}" = CCC Help Polish
"{B53FA0E4-739C-435F-9872-E3032F2E08FC}" = Iomega QuikProtect
"{BCC57687-98A2-4C4C-B0F8-BC6B6F52D4E3}" = Retrospect Express HD 2.5
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C08E4323-261D-4B2F-8F24-CDB26E2AA081}" = Iomega Home Storage Manager
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C47426F7-6434-4A18-995A-68CF6B310DDF}" = TD AMERITRADE StrategyDesk 3.4
"{C5EC81D0-3DED-435D-A46E-E3F60F7DC8AD}" = Palm Desktop
"{C8430789-D948-0314-C36B-A7D78AB67013}" = ccc-core-static
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB2FFEB2-AC62-8DE2-8806-7C263437F132}" = CCC Help English
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F69BED-0B44-8D65-5834-6A74D8F83805}" = Catalyst Control Center Localization Chinese Traditional
"{D30C0F98-3EF4-4454-8C70-F7CFB933B48A}" = VectorVest 7
"{D41864EF-CC5D-4CF4-B0B9-CA3152164157}" = ISIS Driver - EPSON GT-1500 v1.6.10802.6001
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DD45D741-53D9-80CF-D097-31131DD9C0B0}" = CCC Help Chinese Traditional
"{DE5730BC-81FB-633F-039D-5D8C8F787EDF}" = Catalyst Control Center Localization German
"{DEA18FF6-D84A-4242-9663-692E5BA56805}" = ScanSoft PaperPort 11
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E492D880-0B07-4769-9E92-6C2B7DE37716}" = Linksys EasyLink Advisor
"{E5FEB4A0-1480-F22B-9822-B56BA6172421}" = ccc-utility
"{ED93995E-8BF2-480F-8EA4-7D29E29A7052}" = HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EFF1802C-C1F1-03EC-F3E0-51048DF0009F}" = Catalyst Control Center Localization Italian
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F9956472-6E16-4F83-BF9A-F887EF4A45B7}" = EPSON Scan PDF EXtensions
"{F9C22FF2-639F-1016-7926-9A1B06CDD516}" = Catalyst Control Center Localization Polish
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acoustica MP3 CD Burner" = Acoustica MP3 CD Burner
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AllMySongs Database1.4" = AllMySongs Database
"AllMySongs Database2.0" = AllMySongs Database
"CAAPH2" = APH placeholder
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Elisha Cuthbert Screen Saver" = Elisha Cuthbert Screen Saver
"EPSON Scanner" = EPSON Scan
"eTrust Suite Personal" = CA Internet Security Suite
"Family Tree Builder" = MyHeritage Family Tree Builder
"FrostWire" = FrostWire 4.21.5
"hp instant support" = hp instant support
"hp psc 2200 series_Driver" = hp psc 2200 series
"ie8" = Windows Internet Explorer 8
"K9" = K9
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"Mozilla Thunderbird (3.1.11)" = Mozilla Thunderbird (3.1.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroVision!UninstallKey" = Nero Digital
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Picasa 3" = Picasa 3
"PSC 2000 Series" = HP Photo and Imaging 1.0 - PSC 2000 Series
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.92
"Silent Package Run-Time Sample" = EPSON GT-1500 User's Guide
"Smart Defrag 2_is1" = Smart Defrag 2
"Stacy Keibler Heavenly" = Stacy Keibler Heavenly
"thinkorswim from TD AMERITRADE" = thinkorswim from TD AMERITRADE
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WhoCrashed_is1" = WhoCrashed 3.01
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ System Events ]
Error - 7/29/2011 11:29:33 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Simple TCP/IP Services service terminated with the following error:
%%10092
Error - 7/29/2011 11:29:35 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
mv61xx
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7034
Description = The Linksys Updater service terminated unexpectedly. It has done
this 1 time(s).
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).
Error - 7/29/2011 11:31:24 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register
with DCOM within the required timeout.
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).
Error - 7/29/2011 11:32:22 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:15:12 PM, on 7/30/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe
C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\KeirNet\K9\K9.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\WINDOWS\system32\svcprs32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrospect.exe
H:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CA Anti-Phishing Toolbar Helper - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: CA Anti-Phishing Toolbar - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\Six Engine\SixEngine.exe" -r
O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe"
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-789336058-602162358-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (User '?')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: www.vectorvest.com
O15 - Trusted Zone: http://www.vectorvest.com
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAAMSvc - CA - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QSCopyEngine - Unknown owner - C:\Program Files\Iomega\QuikProtect\QpMonitor.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: WinSock Extention Manager (WinExtManager) - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe
–
End of file - 11467 bytes
.
==== Installed Programs ======================
.
.
ABBYY FineReader 6.0 Sprint
Acoustica MP3 CD Burner
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.0)
Advanced SystemCare 3
AllMySongs Database
AMRT
APH placeholder
Apple Application Support
Apple Software Update
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Catalyst Install Manager
ATI HYDRAVISION
ATI Problem Report Wizard
CA Anti-Phishing
CA Anti-Spam
CA Anti-Virus Plus
CA Backup and Migration
CA Internet Security Suite
CA Parental Controls
CA Personal Firewall
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Compatibility Pack for the 2007 Office system
Definition update for Microsoft Office 2010 (KB982726)
DNAMigrator
Elisha Cuthbert Screen Saver
Epson Copy Utility 3.4
Epson Event Manager
EPSON GT-1500 User's Guide
EPSON Scan
EPSON Scan PDF EXtensions
EPU-6 Engine
FrostWire 4.21.5
Google Earth Plug-in
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
hp instant support
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2200 series
Iomega Home Storage Manager
Iomega QuikProtect
ISIS Driver - EPSON GT-1500 v1.6.10802.6001
Java Auto Updater
Java™ 6 Update 26
Java™ 6 Update 3
K9
Linksys EasyLink Advisor
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 14
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XML Parser
MozBackup 1.4.10
Mozilla Firefox (3.6.14)
Mozilla Thunderbird (3.1.11)
MozyHome
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyHeritage Family Tree Builder
Nero Digital
Palm Desktop
PaperPort Image Printer
Picasa 3
Power Tab Editor 1.7
Pure Networks Platform
QuickTime
Readiris 7.5
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Retrospect Express HD 2.5
Revo Uninstaller 1.92
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Skins
Smart Defrag 2
SoundMAX
Stacy Keibler Heavenly
TD AMERITRADE StrategyDesk 3.4
thinkorswim from TD AMERITRADE
Uniblue RegistryBooster
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982632)
Update for Windows Internet Explorer 8 (KB982664)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VectorVest 7
VectorVest U.S.
WebEx
WebEx Support Manager for Internet Explorer
WebFldrs XP
WhoCrashed 3.01
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Search 4.0
Windows XP Service Pack 3
WorkForce GT-1500 Scanner Driver Update
Yahoo! Messenger
.
==== End Of File ===========================
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 22:17:05.84 on Sat 07/30/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = hxxp://search.myheritage.com
uInternet Settings,ProxyOverride = 127.0.0.1
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
mURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: CA Anti-Phishing Toolbar Helper: {45011cf5-e4a9-4f13-9093-f30a784eb9b2} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\microsoft office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Six Engine] "c:\program files\asus\six engine\SixEngine.exe" -r
mRun: [Iomega Home Storage Manager] c:\program files\iomega\home storage manager\Iomega Discovery.exe
mRun: [RetroExpress] c:\progra~1\retros~1\retros~1.5\RetroExpress.exe /h
mRun: [QuiKProtect] c:\program files\iomega\quikprotect\StartQuikProtect.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe"
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [LELA] "c:\program files\linksys\linksys easylink advisor\Linksys EasyLink Advisor.exe" /minimized
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\microsoft office\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\microsoft office\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: microsoft.com\www.update
Trusted Zone: vectorvest.com\www
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: UmxSbxExw.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\jim\applic~1\mozilla\firefox\profiles\ktncdtcs.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.addthis.com/search?pco=fxe-3.1.2&locale;=en-US&sl;=ub&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\firefox\components\CAFxToolBar.dll
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\FFHst.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\progra~1\microsoft office\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\microsoft office\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npatgpc.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.urlbar.hideGoButton -
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_open_feature.location - True
FF - user.js: dom.disable_window_open_feature.menubar - True
FF - user.js: dom.disable_window_open_feature.minimizable - True
FF - user.js: dom.disable_window_open_feature.scrollbars - True
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R? CAISafe;CAISafe
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? KmxAMVet;KmxAMVet
R? LinksysUpdater;Linksys Updater
R? MBAMSwissArmy;MBAMSwissArmy
R? MpKslc4009304;MpKslc4009304
R? MpKslcda4fc30;MpKslcda4fc30
R? mv61xx;mv61xx
R? NmPar;Unusable Parallel Port
R? nmserial;PCI Serial Port
R? osppsvc;Office Software Protection Platform
R? QSCopyEngine;QSCopyEngine
R? QsFsFltr;QsFsFltr
R? UmxAgent;HIPS Event Manager
R? UmxCfg;HIPS Configuration Interpreter
R? UmxPol;HIPS Policy Manager
R? WinRM;Windows Remote Management (WS-Management)
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? AtiHDAudioService;ATI Function Driver for HD Audio Service
S? AvgLdx86;AVG AVI Loader Driver x86
S? AvgMfx86;AVG On-access Scanner Minifilter Driver x86
S? AvgRkx86;avgrkx86.sys
S? AvgTdiX;AVG8 Network Redirector
S? CAAMSvc;CAAMSvc
S? ccSchedulerSVC;CA Common Scheduler Service
S? KmxAgent;KmxAgent
S? KmxAMRT;KmxAMRT
S? KmxCF;KmxCF
S? KmxCfg;KmxCfg
S? KmxFile;KmxFile
S? KmxFw;KmxFw
S? KmxSbx;KmxSbx
S? KmxStart;KmxStart
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? SmartDefragDriver;SmartDefragDriver
S? WinExtManager;WinSock Extention Manager
S? WinSvchostManager;WinSock Svchost Manager
.
=============== Created Last 30 ================
.
2011-07-31 01:34:52 ——– d—–w- c:\docume~1\jim\applic~1\Malwarebytes
2011-07-31 00:43:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-31 00:43:42 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-07-31 00:43:39 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-31 00:43:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-07-30 14:04:55 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{35ACA973-70F0-495F-9092-74A130711865}
2011-07-30 13:54:41 ——– d—–w- c:\program files\WebEx
2011-07-30 13:54:10 23984 —-a-w- c:\windows\system32\drivers\pnarp.sys
2011-07-30 13:54:03 25264 —-a-w- c:\windows\system32\drivers\purendis.sys
2011-07-30 13:53:57 ——– d—–w- c:\program files\common files\Pure Networks Shared
2011-07-30 13:53:41 ——– d—–w- c:\docume~1\alluse~1\applic~1\Pure Networks
2011-07-30 13:32:13 939368 —-a-r- c:\windows\system32\myflash.ocx
2011-07-28 23:48:19 ——– d—–w- c:\docume~1\jim\applic~1\ElevatedDiagnostics
2011-07-28 00:06:27 101392 —-a-w- c:\windows\system32\drivers\AtihdXP3.sys
2011-07-28 00:05:59 ——– d—–w- c:\program files\ATI
2011-07-28 00:05:04 ——– d—–w- C:\ATI
2011-07-27 22:40:05 ——– d—–w- c:\program files\ISSThirdParty
2011-07-27 22:39:49 5845744 —-a-w- c:\windows\system32\win32cpr.dll
2011-07-27 22:39:49 200704 —-a-w- c:\windows\system32\ssleay32.dll
2011-07-27 22:39:49 1377008 —-a-w- c:\windows\system32\svcprs32.exe
2011-07-27 22:39:49 1028096 —-a-w- c:\windows\system32\libeay32.dll
2011-07-27 22:39:47 286208 —-a-w- c:\windows\system32\winsfinst.exe
2011-07-27 22:39:47 2654208 —-a-w- c:\windows\system32\winsflte.dll
2011-07-27 22:39:47 2347760 —-a-w- c:\windows\system32\mdmcls32.exe
2011-07-27 22:39:47 1872624 —-a-w- c:\windows\system32\winsflt.dll
2011-07-27 13:27:01 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-27 13:25:56 ——– d—–w- c:\docume~1\jim\locals~1\applic~1\eSupport.com
2011-07-27 03:39:03 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-25 00:59:30 95568 —-a-w- c:\windows\system32\Vetredir.dll
2011-07-25 00:59:30 202064 —-a-w- c:\windows\system32\Isafprod.dll
2011-07-25 00:59:30 128336 —-a-w- c:\windows\system32\Isafeif.dll
2011-07-25 00:58:50 1054032 —-a-w- c:\windows\system32\cfgmig32.dll
2011-07-25 00:20:52 2385136 —-a-w- c:\windows\system32\winsflt_x64.dll
2011-07-25 00:20:51 ——– d—–w- c:\windows\rnapxs
2011-07-25 00:20:50 7440 —-a-w- c:\windows\system32\sporder.dll
2011-07-25 00:20:50 32768 —-a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-07-25 00:18:58 ——– d—–w- c:\docume~1\alluse~1\applic~1\CA
2011-07-24 14:11:07 ——– d—–w- c:\program files\WhoCrashed
2011-07-24 11:34:58 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-07-24 11:34:57 13496 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-07-23 19:24:26 ——– d—–w- c:\documents and settings\jim\Logitech
2011-07-23 19:21:45 ——– d—–w- c:\program files\common files\Remote Control Software Common
2011-07-23 19:21:30 ——– d—–w- c:\program files\common files\Remote Control USB Driver
2011-07-23 19:21:24 757760 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2011-07-23 19:21:24 69715 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2011-07-23 19:21:24 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2011-07-23 19:21:24 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2011-07-23 19:21:24 204800 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2011-07-23 19:21:24 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2011-07-23 19:21:23 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2011-07-16 21:34:20 ——– d—–w- c:\documents and settings\jim\.frostwire5
.
==================== Find3M ====================
.
2011-07-10 11:30:42 404640 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-29 16:36:20 387600 -c–a-w- c:\windows\system32\FTBSaver.scr
2011-05-04 09:52:22 472808 -c–a-w- c:\windows\system32\deployJava1.dll
2011-05-04 07:25:49 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2010-10-13 03:01:02 638976 —-a-w- c:\program files\Uninstall IObit Toolbar.dll
.
============= FINISH: 22:17:49.70 ===============
That's all I got! Now, if someone could look at these and tell me what happened to my PC, I'd appreciate it! It's been acting up for about 4-5 days now with weird error messages and shutdowns. I originally started this post in MS Windows forum so there's a bit of history there from the past few days also.
Thanks!
Taz
I get a desktop background picture, but the icons are erratic loading as are the programs in the toolbar. In addition I've lost my broadband connection. Right now I'm working off my laptop and transferring 'fixes' via jump drive where I can. It's been getting progressively worse over the past 4-5 days. I've run Malbytes and it found 3 infections but apparently wasn't the fix.Also used Stinger . Whatever this is, it has a pretty good hold on my PC. Looking for some serious help!
OTL logfile created on: 7/30/2011 10:02:31 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.70 Gb Available Physical Memory | 83.09% Memory free
6.34 Gb Paging File | 5.81 Gb Available in Paging File | 91.72% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32
Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - H:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
PRC - C:\WINDOWS\system32\svcprs32.exe ()
PRC - C:\WINDOWS\system32\mdmcls32.exe ()
PRC - C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\Retrospect.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
PRC - C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
========== Modules (SafeList) ==========
MOD - H:\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\UmxSbxw.dll (CA)
MOD - C:\WINDOWS\system32\UmxSbxExw.dll (CA)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (WinSvchostManager) – C:\WINDOWS\system32\svcprs32.exe ()
SRV - (WinExtManager) – C:\WINDOWS\system32\mdmcls32.exe ()
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (QSCopyEngine) – C:\Program Files\Iomega\QuikProtect\QpMonitor.exe ()
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LinksysUpdater) – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (RetroExpLauncher) – C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
SRV - (p2pgasvc) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AtiHDAudioService) – C:\WINDOWS\system32\drivers\AtihdXP3.sys (Advanced Micro Devices)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (KmxAMRT) – C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\system32\drivers\KmxCfg.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\system32\drivers\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\system32\drivers\KmxCF.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\system32\drivers\KmxFw.sys (CA)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\system32\drivers\KmxSbx.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\system32\drivers\KmxAgent.sys (CA)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (KmxAMVet) – C:\WINDOWS\system32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (QsFsFltr) – C:\WINDOWS\system32\drivers\QsFsFltr.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NmPar) – C:\WINDOWS\system32\drivers\NmPar.sys (Windows ® 2000 DDK provider)
DRV - (nmserial) – C:\WINDOWS\system32\drivers\NmSerial.sys (Windows ® 2000 DDK provider)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (Pnp680r) – C:\WINDOWS\system32\DRIVERS\pnp680r.sys (Silicon Image, Inc)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
========== FireFox ==========
FF - user.js..browser.search.openintab: false
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\4.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/03 11:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\Firefox [2011/07/27 17:40:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions
[2010/08/14 08:42:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions
[2010/08/15 15:47:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/17 13:20:39 | 000,000,000 | —D | M] (AddThis) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/08/15 13:43:56 | 000,000,000 | —D | M] (IE View) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/09/05 17:51:44 | 000,000,000 | —D | M] (Ancestry Toolbar) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2010/08/26 19:18:19 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/30 08:50:58 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/10 11:21:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/10 20:55:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/12 22:26:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/06 20:48:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 21:28:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/25 16:19:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/01 08:41:18 | 000,000,000 | —D | M] (Babylon) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/06/23 19:27:32 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/01/02 08:43:19 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/06/23 19:27:28 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/08/15 18:50:39 | 000,003,803 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml
O1 HOSTS File: ([2011/07/27 19:50:31 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LELA] C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
O4 - HKLM..\Run: [RetroExpress] C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (UmxSbxExw.dll) - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 00:31:03 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SmartDefragBootTime.exe) - C:\WINDOWS\System32\SmartDefragBootTime.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/07/30 20:34:52 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\Malwarebytes
[2011/07/30 19:43:42 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/07/30 19:43:39 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/30 19:43:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/30 12:40:45 | 000,000,000 | RH-D | C] – C:\Documents and Settings\JIM\Recent
[2011/07/30 09:04:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/30 08:54:41 | 000,000,000 | —D | C] – C:\Program Files\WebEx
[2011/07/30 08:54:10 | 000,023,984 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\pnarp.sys
[2011/07/30 08:54:03 | 000,025,264 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\purendis.sys
[2011/07/30 08:53:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Pure Networks Shared
[2011/07/30 08:53:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2011/07/30 08:50:57 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/07/30 08:32:13 | 000,939,368 | R— | C] (Macromedia, Inc.) – C:\WINDOWS\System32\myflash.ocx
[2011/07/29 16:21:24 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/07/28 18:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/07/28 18:46:51 | 000,347,920 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 19:06:27 | 000,101,392 | —- | C] (Advanced Micro Devices) – C:\WINDOWS\System32\drivers\AtihdXP3.sys
[2011/07/27 19:05:59 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2011/07/27 19:05:04 | 000,000,000 | —D | C] – C:\ATI
[2011/07/27 17:40:05 | 000,000,000 | —D | C] – C:\Program Files\ISSThirdParty
[2011/07/27 17:39:49 | 001,028,096 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2011/07/27 17:39:49 | 000,200,704 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\ssleay32.dll
[2011/07/27 17:39:47 | 002,654,208 | —- | C] (PureSight Technologies Ltd) – C:\WINDOWS\System32\winsflte.dll
[2011/07/27 17:39:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CA
[2011/07/27 08:27:01 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/07/27 08:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Local Settings\Application Data\eSupport.com
[2011/07/26 22:39:03 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/07/24 19:59:30 | 000,202,064 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\Isafprod.dll
[2011/07/24 19:59:30 | 000,128,336 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Isafeif.dll
[2011/07/24 19:59:30 | 000,095,568 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Vetredir.dll
[2011/07/24 19:20:51 | 000,000,000 | —D | C] – C:\WINDOWS\rnapxs
[2011/07/24 19:20:50 | 000,007,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sporder.dll
[2011/07/24 19:18:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:50 | 157,866,568 | —- | C] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/07/24 09:11:07 | 000,000,000 | —D | C] – C:\Program Files\WhoCrashed
[2011/07/23 14:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Logitech
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control Software Common
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Logitech
[2011/07/23 14:21:38 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2011/07/23 14:21:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2011/07/23 14:20:13 | 048,357,912 | —- | C] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 16:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\.frostwire5
[2011/07/10 06:28:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/10/24 19:18:28 | 000,638,976 | —- | C] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/30 21:31:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/30 21:31:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/30 19:43:42 | 000,000,805 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 16:38:48 | 000,889,547 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/30 16:38:48 | 000,782,812 | —- | M] () – C:\WINDOWS\System32\drivers\KmxAgent.asc
[2011/07/30 16:38:48 | 000,010,421 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/30 16:38:48 | 000,000,593 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/30 16:38:48 | 000,000,293 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\tasks\RegistryBooster.job
[2011/07/30 13:13:25 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/30 13:13:24 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 13:13:22 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/07/30 12:05:02 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/30 11:07:43 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 09:15:06 | 000,540,196 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/30 09:15:06 | 000,102,218 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/30 09:03:48 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Linksys EasyLink Advisor.lnk
[2011/07/30 08:45:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/07/30 08:25:29 | 000,038,727 | —- | M] () – C:\WINDOWS\Ascd_tmp.ini
[2011/07/30 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 23:59:09 | 000,004,522 | —- | M] () – C:\WINDOWS\mozy.blk
[2011/07/27 23:59:09 | 000,002,208 | —- | M] () – C:\WINDOWS\mozy.flt
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/07/27 21:12:33 | 000,000,082 | —- | M] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 19:50:31 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 18:36:03 | 000,000,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/07/27 17:39:49 | 005,845,744 | —- | M] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,872,624 | —- | M] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:35:43 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/27 08:27:02 | 000,001,695 | —- | M] () – C:\Documents and Settings\JIM\Desktop\Uniblue RegistryBooster.lnk
[2011/07/27 08:27:02 | 000,001,672 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,713 | —- | M] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:55 | 000,000,852 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/07/24 06:34:55 | 000,000,834 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2011/07/24 06:28:44 | 000,000,699 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk
[2011/07/24 05:40:32 | 000,001,552 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AllMySongs Database.lnk
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/07/23 14:24:19 | 000,002,031 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 15:41:39 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/07/13 16:22:42 | 000,265,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/10 06:30:42 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/06 15:43:46 | 000,107,633 | —- | M] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:36:03 | 000,002,074 | -H– | M] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:57 | 000,424,031 | —- | M] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/07/06 15:23:07 | 000,002,315 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PaperPort.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/30 19:43:42 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/27 22:04:23 | 000,001,790 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/27 22:04:23 | 000,001,470 | —- | C] () – C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk
[2011/07/27 21:12:33 | 000,000,082 | —- | C] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 18:45:19 | 000,000,354 | —- | C] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 17:44:31 | 000,889,547 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/27 17:44:31 | 000,010,421 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/27 17:44:31 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/27 17:44:31 | 000,000,293 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/27 17:39:49 | 005,845,744 | —- | C] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,377,008 | —- | C] () – C:\WINDOWS\System32\svcprs32.exe
[2011/07/27 17:39:47 | 002,347,760 | —- | C] () – C:\WINDOWS\System32\mdmcls32.exe
[2011/07/27 17:39:47 | 001,872,624 | —- | C] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:39:47 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\winsfinst.exe
[2011/07/27 17:26:53 | 000,128,733 | —- | C] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/26 22:20:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/07/24 19:58:50 | 001,054,032 | —- | C] () – C:\WINDOWS\System32\cfgmig32.dll
[2011/07/24 19:20:52 | 002,385,136 | —- | C] () – C:\WINDOWS\System32\winsflt_x64.dll
[2011/07/24 09:11:08 | 000,000,713 | —- | C] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:58 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/07/24 06:34:57 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/07/24 05:39:04 | 011,193,773 | —- | C] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/23 14:24:19 | 000,002,031 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/06 15:43:45 | 000,107,633 | —- | C] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:33:19 | 000,002,074 | -H– | C] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:54 | 000,424,031 | —- | C] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/05/09 08:15:35 | 000,251,298 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/03/26 14:51:50 | 000,031,561 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/03/26 14:43:39 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2011/03/26 14:43:39 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2011/03/26 14:43:38 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2011/03/26 14:43:38 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2011/03/26 14:43:38 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2011/03/26 14:43:38 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2011/03/26 14:43:38 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2011/03/26 14:43:38 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2011/03/26 14:43:38 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2011/03/26 14:43:38 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2011/03/26 14:43:38 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2011/03/26 14:43:38 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2011/03/26 14:40:58 | 000,065,793 | —- | C] () – C:\WINDOWS\System32\esfw86.bin
[2011/03/26 14:40:11 | 000,000,044 | —- | C] () – C:\WINDOWS\WFGT1500.ini
[2011/01/02 11:33:50 | 000,027,801 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2011/01/02 11:33:50 | 000,007,765 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2011/01/02 11:04:11 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\gswin32c.exe
[2011/01/02 10:30:38 | 000,027,456 | —- | C] () – C:\WINDOWS\System32\solidlocalmon.dll
[2011/01/02 10:30:38 | 000,018,752 | —- | C] () – C:\WINDOWS\System32\solidlocalui.dll
[2011/01/02 10:23:04 | 000,020,886 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2011/01/02 08:43:30 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/11/15 21:08:52 | 000,000,537 | -H– | C] () – C:\Program Files\hpothb07.tif
[2010/11/15 21:08:52 | 000,000,327 | -H– | C] () – C:\Program Files\hpothb07.dat
[2010/08/15 22:37:19 | 001,669,496 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/15 21:53:37 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/08/15 21:22:20 | 000,013,312 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 18:49:49 | 000,000,302 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2010/08/15 18:48:49 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2010/08/15 18:09:51 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/14 08:42:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/11 19:54:18 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2010/08/11 09:21:11 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 02:48:28 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/11 02:44:10 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/08/11 02:42:05 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/08/11 02:42:00 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/11 02:41:59 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/11 02:41:58 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/08/11 02:41:58 | 000,227,587 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/11 01:18:34 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/08/11 01:18:34 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/08/11 01:18:33 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/08/11 01:18:33 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/08/11 00:56:45 | 000,039,119 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2010/08/11 00:56:37 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/11 00:56:28 | 000,038,727 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/11 00:56:27 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/11 00:51:42 | 000,000,158 | —- | C] () – C:\WINDOWS\pagesuit.ini
[2010/08/11 00:51:41 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\irisco32.dll
[2010/08/11 00:32:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 00:29:03 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 19:25:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 19:24:41 | 000,265,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/08/05 16:14:12 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ATIBRTMON.EXE
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/10/18 18:36:54 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\deskMenu2.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2002/08/29 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/08/29 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/08/29 07:00:00 | 000,540,196 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/08/29 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/08/29 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/08/29 07:00:00 | 000,102,218 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/08/29 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/08/29 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/08/29 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/05/29 08:50:02 | 000,552,960 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2000/08/29 03:59:12 | 002,971,392 | —- | C] () – C:\WINDOWS\Catherine Zeta Jones Saver V1.exe
[1999/01/22 13:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 03:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
========== LOP Check ==========
[2010/12/05 10:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/07/24 19:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2011/05/01 08:28:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/10/10 20:44:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 18:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2011/07/30 21:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RetroExp
[2011/03/27 11:28:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/01/02 10:29:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SolidDocuments
[2010/10/23 23:34:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2010/10/10 20:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/07/30 09:04:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/29 23:36:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/06/22 17:47:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011/05/01 09:55:11 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Acoustica
[2011/06/12 19:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/18 17:50:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EarMaster
[2011/07/28 18:48:19 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/03/26 15:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EPSON
[2011/06/07 20:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FixCleaner
[2010/09/18 17:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FreeFileViewer
[2011/07/24 05:59:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FrostWire
[2011/04/27 17:06:30 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\IObit
[2010/08/15 17:48:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\K9
[2011/03/26 15:04:07 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Leadertech
[2010/08/15 18:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\MyHeritage
[2011/03/26 14:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ScanSoft
[2010/08/15 17:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\The Complete Genealogy Reporter - FTB
[2010/08/14 08:42:46 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Thunderbird
[2010/08/11 01:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\TMP
[2011/06/06 08:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Uniblue
[2010/08/15 17:52:27 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VectorVest, Inc
[2011/06/17 20:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VSRevoGroup
[2011/06/27 15:24:55 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\webex
[2010/08/12 18:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Desktop Search
[2010/08/12 19:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Search
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2011/04/02 10:38:22 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1293986285.job
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\Tasks\RegistryBooster.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
[2010/12/31 19:54:43 | 000,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F9AF475E-4BA9-4B59-BA57-28BE3A55B301}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/05/28 18:58:40 | 014,970,880 | —- | M] () – C:\AdamsFanning.paf
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/30 23:56:13 | 000,001,360 | —- | M] () – C:\caEntitlementLog.txt
[2011/07/27 17:47:00 | 002,695,826 | —- | M] () – C:\caisslog.txt
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/02/28 14:23:24 | 008,109,897 | —- | M] () – C:\Fanning Family Tree.ged
[2011/05/28 18:58:22 | 003,265,738 | —- | M] () – C:\Fanning Family Tree.lst
[2010/02/28 14:32:19 | 001,575,056 | —- | M] () – C:\FFTree.zip
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/13 08:41:10 | 000,365,568 | —- | M] () – C:\market_timers.ppt
[2011/02/05 17:47:16 | 000,000,000 | —- | M] () – C:\Medical1.txt
[2007/03/10 13:48:13 | 000,030,208 | —- | M] () – C:\MenardsComp.xls
[2008/08/31 16:22:25 | 000,031,232 | —- | M] () – C:\MenardsExpenses.xls
[2009/10/31 23:27:50 | 000,384,512 | —- | M] () – C:\MenardsLeads.xls
[2009/10/25 09:43:19 | 000,054,784 | —- | M] () – C:\MenardsLeads1.xls
[2010/01/18 12:37:13 | 000,082,944 | —- | M] () – C:\MenardsPayroll.xls
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/11 09:39:59 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 20:49:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/30 21:31:05 | 3488,591,872 | -HS- | M] () – C:\pagefile.sys
[2011/07/30 08:41:12 | 000,000,032 | —- | M] () – C:\t.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/08/15 19:13:15 | 000,000,152 | —- | M] () – C:\YServer.txt
[2010/10/02 16:56:51 | 000,000,308 | R— | M] () – C:\YukonInstall.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/11 00:30:53 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/11/15 21:09:30 | 000,000,327 | -H– | M] () – C:\Program Files\hpothb07.dat
[2010/11/15 21:08:52 | 000,000,537 | -H– | M] () – C:\Program Files\hpothb07.tif
[2010/10/12 22:01:02 | 000,638,976 | —- | M] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/10 19:23:37 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/10 19:23:37 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/10 19:23:37 | 000,450,560 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 20:54:17 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/11 20:59:54 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/11 00:34:12 | 000,000,079 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/10/10 20:26:26 | 000,939,956 | —- | M] () – C:\Documents and Settings\JIM\Desktop\7z465.exe
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2009/01/31 20:50:36 | 000,524,288 | —- | M] (Chaos Software Group, Inc.) – C:\Documents and Settings\JIM\Desktop\Atomic.exe
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/06/16 18:45:58 | 027,862,496 | —- | M] () – C:\Documents and Settings\JIM\Desktop\family_tree_builder_5209i.exe
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2010/10/23 23:24:44 | 011,437,504 | —- | M] (Mozy, Inc.) – C:\Documents and Settings\JIM\Desktop\mozy-2_2_4_0.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-25 14:02:07
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\JIM\Desktop\Atomic.exe:SummaryInformation
< End of report >
OTL Extras logfile created on: 7/30/2011 9:45:51 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.72 Gb Available Physical Memory | 83.58% Memory free
6.34 Gb Paging File | 5.87 Gb Available in Paging File | 92.59% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32
Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe:*:Enabled:Iomega Home Media Network Discover Application – (Iomega Corporation)
"C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe:*:Enabled:Iomega Storage Manager – (Iomega Corp.)
"C:\Program Files\Iomega\QuikProtect\QuikProtect.exe" = C:\Program Files\Iomega\QuikProtect\QuikProtect.exe:*:Enabled:QuikProtect – (Iomega Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Thunderbird – (Mozilla Messaging)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0038B7BB-C6E6-59D4-8F6F-2B2E707F89F6}" = MozyHome
"{01A3E75B-54C0-407F-8B95-B77705C7DCC4}" = AMRT
"{022C4B5F-4A59-48DD-08A6-6EC5832DBFFE}" = Catalyst Control Center Localization Chinese Standard
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1148CE6F-6956-6ED3-1DBF-0A0046427A3E}" = CCC Help Swedish
"{1350E13C-A031-6574-961B-367DE4721E86}" = Catalyst Control Center Graphics Light
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{14A776EF-3904-3C55-508F-BB093954391E}" = Catalyst Control Center Localization Dutch
"{19762EA5-8279-8FA8-5F16-7DEEF571E5D6}" = CCC Help Russian
"{1A90FD8B-8A64-8B83-D486-E507AEC997EF}" = Catalyst Control Center Graphics Full Existing
"{1D4C0096-98D0-5290-A5F7-AAA05121FA0A}" = CCC Help Danish
"{2681A52E-FCFA-4982-A030-7B652BDD346C}" = CA Personal Firewall
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2E73FAB9-7713-D109-24DB-28339CB7A3CC}" = Catalyst Control Center Localization Norwegian
"{30517D85-B2C9-5920-77B2-6034DDC90B7C}" = CCC Help Czech
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35A6DE92-DE2E-9FBB-C919-B9CA5079116D}" = Catalyst Control Center Localization Turkish
"{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}" = WorkForce GT-1500 Scanner Driver Update
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{39C1585C-1004-5091-180A-5AFCA3D505C2}" = Catalyst Control Center Localization Thai
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{41269776-CF11-AADD-A1A9-6E1701877F88}" = CCC Help Norwegian
"{455B46A4-17C2-DDDA-F695-7F157E2C6160}" = Catalyst Control Center Localization Danish
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E10FFCA-5C09-6E8E-4DA4-B71FFC58C435}" = CCC Help Korean
"{4E568350-98BF-A31B-4E90-B23428023916}" = Catalyst Control Center Localization Spanish
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5827D56B-9A4D-6858-95C9-28B2D46F56EB}" = CCC Help German
"{5954C9DD-80C5-27FB-67FA-1DF0B5E2565A}" = Catalyst Control Center Localization Portuguese
"{5A05B328-35EB-4CED-B16F-62FA5A2642E6}" =
"{5B6844F3-8C27-C589-E519-9AAE0AC87407}" = CCC Help Dutch
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5DC1DF0D-8B08-30D9-5F5F-857ADC69201A}" = Catalyst Control Center Graphics Full New
"{5DDBDE45-EB70-DC65-6D06-6D25906E7797}" = CCC Help Japanese
"{5E075172-D826-3CFC-51F4-C9E6CF6D0690}" = CCC Help Spanish
"{618EB4D7-7D67-9126-7D63-CA39F93673DE}" = Catalyst Control Center Graphics Previews Common
"{67F5A666-181F-8AA1-0D4E-BAD64AD43B42}" = CCC Help Chinese Standard
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FB4970-45D2-1EA4-F131-A95EB60FFDDF}" = CCC Help Italian
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A053172-1F36-0307-4CA0-6AA9317EBCC1}" = CCC Help Turkish
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6B6F61D0-BBD0-E91F-8639-6EF30206ABD2}" = Catalyst Control Center Localization Japanese
"{71389CB1-6B6D-6FC2-0B74-0357D1ADC41E}" = CCC Help Finnish
"{736D005A-96E3-3B70-836C-14C80A137862}" = CCC Help French
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8124C5F0-D59A-DEFE-C3F7-02697D9BE53E}" = CCC Help Thai
"{82357963-7536-629A-F921-A3E72A5E124C}" = Catalyst Control Center Localization Korean
"{82DFB852-9594-4668-9C66-28BB6E94BCB2}" = HP Photo and Imaging 1.0 - PSC 2000 Series
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8625D3E5-2159-3FA4-3A74-AB306360E63E}" = Catalyst Control Center Localization Russian
"{888FAC3D-87CB-AB4C-EC2C-D17E0C4418E7}" = Catalyst Control Center Localization French
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{89FF3A82-A88F-4035-9E95-6E03B7BA9D9B}" = Catalyst Control Center Localization Swedish
"{8E3AA171-1D56-8A6B-E7A2-35D32800ECED}" = ATI Catalyst Install Manager
"{8E5EDE0A-6B13-A0E2-7F00-5C2660C9F771}" = Catalyst Control Center Localization Hungarian
"{8EE7E7B0-CEA9-E3FD-A63F-B27F49E9EC42}" = CCC Help Portuguese
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9418FEE4-28B4-96FD-C398-42654B956376}" = Skins
"{94AF0F78-E983-BD4B-1A26-80F2FBD5487C}" = Catalyst Control Center Localization Czech
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9749C770-90C4-EE5A-D3BB-287F53622104}" = Catalyst Control Center Core Implementation
"{99FC30C1-60A7-205F-1A00-367506E756F2}" = Catalyst Control Center Localization Greek
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}" = Readiris 7.5
"{9F36EDCC-81A8-5D37-9EB1-8BF6D96CAA23}" = Catalyst Control Center Localization Finnish
"{A0100CB5-E6CE-F516-59C1-28CF0195A875}" = ccc-core-preinstall
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A336E48B-A46E-81B5-936E-5A9A8D7FE3D8}" = CCC Help Hungarian
"{A4CCE9FD-4A40-5669-97B3-262672CD6C38}" = CCC Help Greek
"{A6B82920-25DD-41B5-A680-5B6FB65BA6D9}" = VectorVest U.S.
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.4
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B325EFE1-1301-5BC4-8788-B1C7D3702ED1}" = CCC Help Polish
"{B53FA0E4-739C-435F-9872-E3032F2E08FC}" = Iomega QuikProtect
"{BCC57687-98A2-4C4C-B0F8-BC6B6F52D4E3}" = Retrospect Express HD 2.5
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C08E4323-261D-4B2F-8F24-CDB26E2AA081}" = Iomega Home Storage Manager
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C47426F7-6434-4A18-995A-68CF6B310DDF}" = TD AMERITRADE StrategyDesk 3.4
"{C5EC81D0-3DED-435D-A46E-E3F60F7DC8AD}" = Palm Desktop
"{C8430789-D948-0314-C36B-A7D78AB67013}" = ccc-core-static
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB2FFEB2-AC62-8DE2-8806-7C263437F132}" = CCC Help English
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F69BED-0B44-8D65-5834-6A74D8F83805}" = Catalyst Control Center Localization Chinese Traditional
"{D30C0F98-3EF4-4454-8C70-F7CFB933B48A}" = VectorVest 7
"{D41864EF-CC5D-4CF4-B0B9-CA3152164157}" = ISIS Driver - EPSON GT-1500 v1.6.10802.6001
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DD45D741-53D9-80CF-D097-31131DD9C0B0}" = CCC Help Chinese Traditional
"{DE5730BC-81FB-633F-039D-5D8C8F787EDF}" = Catalyst Control Center Localization German
"{DEA18FF6-D84A-4242-9663-692E5BA56805}" = ScanSoft PaperPort 11
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E492D880-0B07-4769-9E92-6C2B7DE37716}" = Linksys EasyLink Advisor
"{E5FEB4A0-1480-F22B-9822-B56BA6172421}" = ccc-utility
"{ED93995E-8BF2-480F-8EA4-7D29E29A7052}" = HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EFF1802C-C1F1-03EC-F3E0-51048DF0009F}" = Catalyst Control Center Localization Italian
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F9956472-6E16-4F83-BF9A-F887EF4A45B7}" = EPSON Scan PDF EXtensions
"{F9C22FF2-639F-1016-7926-9A1B06CDD516}" = Catalyst Control Center Localization Polish
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acoustica MP3 CD Burner" = Acoustica MP3 CD Burner
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AllMySongs Database1.4" = AllMySongs Database
"AllMySongs Database2.0" = AllMySongs Database
"CAAPH2" = APH placeholder
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Elisha Cuthbert Screen Saver" = Elisha Cuthbert Screen Saver
"EPSON Scanner" = EPSON Scan
"eTrust Suite Personal" = CA Internet Security Suite
"Family Tree Builder" = MyHeritage Family Tree Builder
"FrostWire" = FrostWire 4.21.5
"hp instant support" = hp instant support
"hp psc 2200 series_Driver" = hp psc 2200 series
"ie8" = Windows Internet Explorer 8
"K9" = K9
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"Mozilla Thunderbird (3.1.11)" = Mozilla Thunderbird (3.1.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroVision!UninstallKey" = Nero Digital
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Picasa 3" = Picasa 3
"PSC 2000 Series" = HP Photo and Imaging 1.0 - PSC 2000 Series
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.92
"Silent Package Run-Time Sample" = EPSON GT-1500 User's Guide
"Smart Defrag 2_is1" = Smart Defrag 2
"Stacy Keibler Heavenly" = Stacy Keibler Heavenly
"thinkorswim from TD AMERITRADE" = thinkorswim from TD AMERITRADE
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WhoCrashed_is1" = WhoCrashed 3.01
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =
Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =
Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.
[ System Events ]
Error - 7/29/2011 11:29:33 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Simple TCP/IP Services service terminated with the following error:
%%10092
Error - 7/29/2011 11:29:35 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
mv61xx
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7034
Description = The Linksys Updater service terminated unexpectedly. It has done
this 1 time(s).
Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).
Error - 7/29/2011 11:31:24 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register
with DCOM within the required timeout.
Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).
Error - 7/29/2011 11:32:22 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:15:12 PM, on 7/30/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe
C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\KeirNet\K9\K9.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\WINDOWS\system32\svcprs32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrospect.exe
H:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CA Anti-Phishing Toolbar Helper - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: CA Anti-Phishing Toolbar - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\Six Engine\SixEngine.exe" -r
O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe"
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-789336058-602162358-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (User '?')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: www.vectorvest.com
O15 - Trusted Zone: http://www.vectorvest.com
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAAMSvc - CA - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QSCopyEngine - Unknown owner - C:\Program Files\Iomega\QuikProtect\QpMonitor.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: WinSock Extention Manager (WinExtManager) - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe
–
End of file - 11467 bytes
.
==== Installed Programs ======================
.
.
ABBYY FineReader 6.0 Sprint
Acoustica MP3 CD Burner
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.0)
Advanced SystemCare 3
AllMySongs Database
AMRT
APH placeholder
Apple Application Support
Apple Software Update
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Catalyst Install Manager
ATI HYDRAVISION
ATI Problem Report Wizard
CA Anti-Phishing
CA Anti-Spam
CA Anti-Virus Plus
CA Backup and Migration
CA Internet Security Suite
CA Parental Controls
CA Personal Firewall
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Compatibility Pack for the 2007 Office system
Definition update for Microsoft Office 2010 (KB982726)
DNAMigrator
Elisha Cuthbert Screen Saver
Epson Copy Utility 3.4
Epson Event Manager
EPSON GT-1500 User's Guide
EPSON Scan
EPSON Scan PDF EXtensions
EPU-6 Engine
FrostWire 4.21.5
Google Earth Plug-in
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
hp instant support
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2200 series
Iomega Home Storage Manager
Iomega QuikProtect
ISIS Driver - EPSON GT-1500 v1.6.10802.6001
Java Auto Updater
Java™ 6 Update 26
Java™ 6 Update 3
K9
Linksys EasyLink Advisor
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 14
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XML Parser
MozBackup 1.4.10
Mozilla Firefox (3.6.14)
Mozilla Thunderbird (3.1.11)
MozyHome
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyHeritage Family Tree Builder
Nero Digital
Palm Desktop
PaperPort Image Printer
Picasa 3
Power Tab Editor 1.7
Pure Networks Platform
QuickTime
Readiris 7.5
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Retrospect Express HD 2.5
Revo Uninstaller 1.92
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Skins
Smart Defrag 2
SoundMAX
Stacy Keibler Heavenly
TD AMERITRADE StrategyDesk 3.4
thinkorswim from TD AMERITRADE
Uniblue RegistryBooster
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982632)
Update for Windows Internet Explorer 8 (KB982664)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VectorVest 7
VectorVest U.S.
WebEx
WebEx Support Manager for Internet Explorer
WebFldrs XP
WhoCrashed 3.01
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Search 4.0
Windows XP Service Pack 3
WorkForce GT-1500 Scanner Driver Update
Yahoo! Messenger
.
==== End Of File ===========================
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 22:17:05.84 on Sat 07/30/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = hxxp://search.myheritage.com
uInternet Settings,ProxyOverride = 127.0.0.1
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
mURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: CA Anti-Phishing Toolbar Helper: {45011cf5-e4a9-4f13-9093-f30a784eb9b2} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\microsoft office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Six Engine] "c:\program files\asus\six engine\SixEngine.exe" -r
mRun: [Iomega Home Storage Manager] c:\program files\iomega\home storage manager\Iomega Discovery.exe
mRun: [RetroExpress] c:\progra~1\retros~1\retros~1.5\RetroExpress.exe /h
mRun: [QuiKProtect] c:\program files\iomega\quikprotect\StartQuikProtect.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe"
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [LELA] "c:\program files\linksys\linksys easylink advisor\Linksys EasyLink Advisor.exe" /minimized
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\microsoft office\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\microsoft office\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: microsoft.com\www.update
Trusted Zone: vectorvest.com\www
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: UmxSbxExw.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\jim\applic~1\mozilla\firefox\profiles\ktncdtcs.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.addthis.com/search?pco=fxe-3.1.2&locale;=en-US&sl;=ub&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\firefox\components\CAFxToolBar.dll
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\FFHst.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\progra~1\microsoft office\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\microsoft office\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npatgpc.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.urlbar.hideGoButton -
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_open_feature.location - True
FF - user.js: dom.disable_window_open_feature.menubar - True
FF - user.js: dom.disable_window_open_feature.minimizable - True
FF - user.js: dom.disable_window_open_feature.scrollbars - True
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R? CAISafe;CAISafe
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? KmxAMVet;KmxAMVet
R? LinksysUpdater;Linksys Updater
R? MBAMSwissArmy;MBAMSwissArmy
R? MpKslc4009304;MpKslc4009304
R? MpKslcda4fc30;MpKslcda4fc30
R? mv61xx;mv61xx
R? NmPar;Unusable Parallel Port
R? nmserial;PCI Serial Port
R? osppsvc;Office Software Protection Platform
R? QSCopyEngine;QSCopyEngine
R? QsFsFltr;QsFsFltr
R? UmxAgent;HIPS Event Manager
R? UmxCfg;HIPS Configuration Interpreter
R? UmxPol;HIPS Policy Manager
R? WinRM;Windows Remote Management (WS-Management)
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? AtiHDAudioService;ATI Function Driver for HD Audio Service
S? AvgLdx86;AVG AVI Loader Driver x86
S? AvgMfx86;AVG On-access Scanner Minifilter Driver x86
S? AvgRkx86;avgrkx86.sys
S? AvgTdiX;AVG8 Network Redirector
S? CAAMSvc;CAAMSvc
S? ccSchedulerSVC;CA Common Scheduler Service
S? KmxAgent;KmxAgent
S? KmxAMRT;KmxAMRT
S? KmxCF;KmxCF
S? KmxCfg;KmxCfg
S? KmxFile;KmxFile
S? KmxFw;KmxFw
S? KmxSbx;KmxSbx
S? KmxStart;KmxStart
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? SmartDefragDriver;SmartDefragDriver
S? WinExtManager;WinSock Extention Manager
S? WinSvchostManager;WinSock Svchost Manager
.
=============== Created Last 30 ================
.
2011-07-31 01:34:52 ——– d—–w- c:\docume~1\jim\applic~1\Malwarebytes
2011-07-31 00:43:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-31 00:43:42 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-07-31 00:43:39 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-31 00:43:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-07-30 14:04:55 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{35ACA973-70F0-495F-9092-74A130711865}
2011-07-30 13:54:41 ——– d—–w- c:\program files\WebEx
2011-07-30 13:54:10 23984 —-a-w- c:\windows\system32\drivers\pnarp.sys
2011-07-30 13:54:03 25264 —-a-w- c:\windows\system32\drivers\purendis.sys
2011-07-30 13:53:57 ——– d—–w- c:\program files\common files\Pure Networks Shared
2011-07-30 13:53:41 ——– d—–w- c:\docume~1\alluse~1\applic~1\Pure Networks
2011-07-30 13:32:13 939368 —-a-r- c:\windows\system32\myflash.ocx
2011-07-28 23:48:19 ——– d—–w- c:\docume~1\jim\applic~1\ElevatedDiagnostics
2011-07-28 00:06:27 101392 —-a-w- c:\windows\system32\drivers\AtihdXP3.sys
2011-07-28 00:05:59 ——– d—–w- c:\program files\ATI
2011-07-28 00:05:04 ——– d—–w- C:\ATI
2011-07-27 22:40:05 ——– d—–w- c:\program files\ISSThirdParty
2011-07-27 22:39:49 5845744 —-a-w- c:\windows\system32\win32cpr.dll
2011-07-27 22:39:49 200704 —-a-w- c:\windows\system32\ssleay32.dll
2011-07-27 22:39:49 1377008 —-a-w- c:\windows\system32\svcprs32.exe
2011-07-27 22:39:49 1028096 —-a-w- c:\windows\system32\libeay32.dll
2011-07-27 22:39:47 286208 —-a-w- c:\windows\system32\winsfinst.exe
2011-07-27 22:39:47 2654208 —-a-w- c:\windows\system32\winsflte.dll
2011-07-27 22:39:47 2347760 —-a-w- c:\windows\system32\mdmcls32.exe
2011-07-27 22:39:47 1872624 —-a-w- c:\windows\system32\winsflt.dll
2011-07-27 13:27:01 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-27 13:25:56 ——– d—–w- c:\docume~1\jim\locals~1\applic~1\eSupport.com
2011-07-27 03:39:03 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-25 00:59:30 95568 —-a-w- c:\windows\system32\Vetredir.dll
2011-07-25 00:59:30 202064 —-a-w- c:\windows\system32\Isafprod.dll
2011-07-25 00:59:30 128336 —-a-w- c:\windows\system32\Isafeif.dll
2011-07-25 00:58:50 1054032 —-a-w- c:\windows\system32\cfgmig32.dll
2011-07-25 00:20:52 2385136 —-a-w- c:\windows\system32\winsflt_x64.dll
2011-07-25 00:20:51 ——– d—–w- c:\windows\rnapxs
2011-07-25 00:20:50 7440 —-a-w- c:\windows\system32\sporder.dll
2011-07-25 00:20:50 32768 —-a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-07-25 00:18:58 ——– d—–w- c:\docume~1\alluse~1\applic~1\CA
2011-07-24 14:11:07 ——– d—–w- c:\program files\WhoCrashed
2011-07-24 11:34:58 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-07-24 11:34:57 13496 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-07-23 19:24:26 ——– d—–w- c:\documents and settings\jim\Logitech
2011-07-23 19:21:45 ——– d—–w- c:\program files\common files\Remote Control Software Common
2011-07-23 19:21:30 ——– d—–w- c:\program files\common files\Remote Control USB Driver
2011-07-23 19:21:24 757760 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2011-07-23 19:21:24 69715 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2011-07-23 19:21:24 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2011-07-23 19:21:24 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2011-07-23 19:21:24 204800 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2011-07-23 19:21:24 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2011-07-23 19:21:23 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2011-07-16 21:34:20 ——– d—–w- c:\documents and settings\jim\.frostwire5
.
==================== Find3M ====================
.
2011-07-10 11:30:42 404640 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-29 16:36:20 387600 -c–a-w- c:\windows\system32\FTBSaver.scr
2011-05-04 09:52:22 472808 -c–a-w- c:\windows\system32\deployJava1.dll
2011-05-04 07:25:49 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2010-10-13 03:01:02 638976 —-a-w- c:\program files\Uninstall IObit Toolbar.dll
.
============= FINISH: 22:17:49.70 ===============
That's all I got! Now, if someone could look at these and tell me what happened to my PC, I'd appreciate it! It's been acting up for about 4-5 days now with weird error messages and shutdowns. I originally started this post in MS Windows forum so there's a bit of history there from the past few days also.
Thanks!
Taz