MichelleBishop
Topic Starter
Learning as I go…here's the situation: Pop-ups looking like windows security notifications took over my computer-the culprit was "Vista Anti-Virus 2012…eliminated it once with Malwarebytes anti-malware…it's back one week later…used MWB again and it appears to be gone, except when I click on program shortcut links, i.e. Internet Explorer, onscreen keyboard, solitaire, RealPlayer, up pops an "Open With" dialogue box asking me to "Choose the program you want to use to open this file:" Here is the result of my OTL scan, OTL.txt file:
OTL logfile created on: 1/8/2012 4:05:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Michelle\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 60.95% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.30% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 25.97 Gb Free Space | 19.33% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 4.12 Gb Free Space | 28.11% Space Free | Partition Type: NTFS
Computer Name: MICHELLE | User Name: Michelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Michelle\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Windows\System32\fsproflt.exe (FSPro Labs)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Windows\sminst\SftService.exe (SoftThinks)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MenuSkinning\81e6be802192a566528fece5fa6a8789\MenuSkinning.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\69a1720a5ab185c7136a0f058b38961f\VistaBridgeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DellDock\25c76ad67fef8be9d616eee5c9b09ad5\DellDock.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\6f95622a73f120e3519d1103fd57c291\MyDock.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (fsproflt) – C:\Windows\System32\fsproflt.exe (FSPro Labs)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (SftService) – C:\Windows\sminst\sftservice.EXE (SoftThinks)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Driver Services (SafeList) ==========
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MSHUSBVideo) – C:\Windows\System32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (USBModem) – C:\Windows\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\Windows\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\Windows\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (PCD5SRVC{3F6A8B78-EC003E00-05040104}) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (FSProFilter) – C:\Windows\System32\Drivers\FSPFltd.sys (FSPro Labs)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (QCDonner) Logitech QuickCam Express(PID_0840) – C:\Windows\System32\drivers\lvcd.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search..defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngineURL: "http://mp3tubetoolbar.com/?&prt;=pinballtbfour01ff&clid;=7802689e8e10412e949ed474dae1d9d3&subid;=&keywords;={searchTerms}"
FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbarsearch.com/?prt=pinballtbfour01ff&clid;=7802689e8e10412e949ed474dae1d9d3&subid;=&Keywords;={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.5.2
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.22
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.8.0.8855
FF - prefs.js..extensions.enabledItems: [removed]:6.0.1367
FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/08 12:51:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/08 12:51:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/20 03:24:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/04 11:49:15 | 000,000,000 | —D | M]
[2010/06/01 04:29:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\a6uc8xva.default\extensions
[2012/01/08 14:40:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/25 18:50:05 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/11/17 19:05:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/05 11:31:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/08/04 23:25:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/09/14 04:48:25 | 000,002,506 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: DivX HiQ = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: avast! WebRep = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AT_KarimRashidV3 = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldjcbfljkplgifccngillicohclloidg\3_0\
CHR - Extension: Skype Click to Call = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
CHR - Extension: Gmail = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2006/09/18 13:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe (FSPro Labs)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Program Files\Software602\Print2PDF\Print602.dll (Software602 a.s.)
O9 - Extra 'Tools' menuitem : Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Program Files\Software602\Print2PDF\Print602.dll (Software602 a.s.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.com/DellDriverScanner/DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…554/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{576D5C9A-D5EA-44C8-B117-4140FABBE3FF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - File not found
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Michelle\Pictures\iced snowfla.jpg
O24 - Desktop BackupWallPaper: C:\Users\Michelle\Pictures\iced snowfla.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 13:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 13:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O33 - MountPoints2\{336bd958-5209-11e0-936d-a4badb9f2af6}\Shell - "" = AutoRun
O33 - MountPoints2\{3aa8d41c-41ef-11df-a0fa-a4badb9f2af6}\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = AX] – "%1" %*
O37 - HKCU\…exe [@ = 1Xu] – "C:\Users\Michelle\AppData\Local\yvd.exe" -a "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/08 11:50:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2012/01/08 11:26:47 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/01/08 11:26:47 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/01/08 10:04:47 | 000,453,424 | —- | C] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/05 20:27:29 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\TPB-The.Twilight.Saga.Eclipse.2010.480p.BRRip.XviD.AC3-FLAWL3SS
[2012/01/04 23:05:46 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\The.Twilight.Saga.Breaking.Dawn.2011.CAMRiP.XViD.Baker92
[2012/01/04 22:39:07 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\David Bowie - Best of Bowie
[2012/01/02 09:28:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegCure
[2012/01/02 09:28:31 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2012/01/02 09:22:34 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\RegCure 3.0.2(latest) by Kkeibul
[2012/01/01 10:37:13 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/31 22:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/12/31 22:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/12/31 22:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/12/31 22:16:07 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/12/31 22:16:06 | 000,000,000 | –SD | C] – C:\ComboFix
[2011/12/31 22:14:59 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/28 02:37:18 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\dvd
[2011/12/28 02:31:29 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\DVD Flick
[2011/12/28 02:30:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick
[2011/12/28 02:29:02 | 000,609,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comctl32.ocx
[2011/12/28 02:29:02 | 000,040,960 | —- | C] (vbAccelerator) – C:\Windows\System32\ssubtmr6.dll
[2011/12/28 02:29:02 | 000,036,864 | —- | C] (Robdogg Inc.) – C:\Windows\System32\trayicon_handler.ocx
[2011/12/28 02:29:02 | 000,028,672 | —- | C] (-) – C:\Windows\System32\mousewheel.ocx
[2011/12/28 02:29:01 | 000,212,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\richtx32.ocx
[2011/12/28 02:29:01 | 000,000,000 | —D | C] – C:\Program Files\DVD Flick
[2011/12/25 18:48:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/12/25 18:48:13 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2011/12/21 23:28:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLAC
[2011/12/21 23:28:43 | 000,000,000 | —D | C] – C:\Program Files\FLAC
[2011/12/19 21:38:52 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\VA-Now_Christmas_2011-2CD-2011-pLAN9 www.0dayvinyls.org
[2011/12/19 21:31:54 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\So Fresh Songs For Christmas 2010 2CD 320KB TBS Spookkie
[2011/12/19 21:30:46 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\Christmas - Xmas Party - 3-CD-Boxset-[TFM]
[2011/12/17 19:45:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/12/17 09:51:26 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2011/12/17 09:51:21 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2011/12/14 03:15:17 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 03:15:14 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 03:15:14 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 03:15:13 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 03:15:12 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 03:15:07 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/13 14:01:35 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/13 14:01:35 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/13 13:50:23 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/13 13:50:21 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/13 13:50:20 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/13 13:49:16 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/11 21:30:42 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\Michelle pcsi
[2011/12/10 22:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jomrati
[2011/12/10 22:51:12 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jomrati
[2011/12/10 22:51:09 | 000,000,000 | —D | C] – C:\Program Files\Jomrati
[2011/12/10 22:50:38 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\Setup1.exe
[2011/12/10 22:50:37 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\ST6UNST.EXE
[5 C:\Users\Michelle\AppData\Local\*.tmp files -> C:\Users\Michelle\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/08 16:00:17 | 000,004,128 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 16:00:17 | 000,004,128 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 15:59:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/08 15:59:52 | 3177,594,880 | -HS- | M] () – C:\hiberfil.sys
[2012/01/08 15:49:14 | 000,078,885 | —- | M] () – C:\Users\Michelle\Desktop\Gold-Flo_sheet.pdf
[2012/01/08 15:42:35 | 000,577,485 | —- | M] () – C:\Users\Michelle\Desktop\facet fuel pump.pdf
[2012/01/08 11:50:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2012/01/08 11:30:06 | 000,002,489 | —- | M] () – C:\Users\Michelle\Desktop\HiJackThis.lnk
[2012/01/08 10:05:26 | 000,453,424 | —- | M] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/08 09:07:49 | 000,000,334 | —- | M] () – C:\Windows\tasks\DriverScanner.job
[2012/01/08 08:47:41 | 000,023,472 | -HS- | M] () – C:\Users\Michelle\AppData\Local\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/08 08:47:41 | 000,023,472 | -HS- | M] () – C:\ProgramData\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/07 15:44:06 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/01/05 18:37:37 | 000,000,000 | —- | M] () – C:\Users\Michelle\AppData\Local\{2A68A1E6-542C-43BC-94A1-452279073888}
[2012/01/05 17:56:16 | 000,000,370 | —- | M] () – C:\Windows\tasks\RegCure Startup.job
[2012/01/03 00:11:01 | 000,030,208 | —- | M] () – C:\Users\Michelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/02 19:04:04 | 000,000,396 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2012/01/02 09:31:20 | 000,000,378 | —- | M] () – C:\Windows\tasks\RegCure.job
[2011/12/31 22:08:34 | 000,009,942 | -HS- | M] () – C:\ProgramData\40581635
[2011/12/31 21:57:46 | 000,010,502 | -HS- | M] () – C:\Users\Michelle\AppData\Local\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/31 21:57:46 | 000,010,502 | -HS- | M] () – C:\ProgramData\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/30 20:21:37 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/30 20:16:33 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2011/12/21 21:33:55 | 000,099,840 | —- | M] () – C:\Users\Michelle\Documents\yule log.pub
[2011/12/20 22:08:11 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/20 22:08:11 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/14 06:34:30 | 000,379,584 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/10 22:50:38 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\Setup1.exe
[2011/12/10 22:50:37 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\Windows\ST6UNST.EXE
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[5 C:\Users\Michelle\AppData\Local\*.tmp files -> C:\Users\Michelle\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/08 15:49:14 | 000,078,885 | —- | C] () – C:\Users\Michelle\Desktop\Gold-Flo_sheet.pdf
[2012/01/08 15:42:35 | 000,577,485 | —- | C] () – C:\Users\Michelle\Desktop\facet fuel pump.pdf
[2012/01/08 11:26:48 | 000,002,489 | —- | C] () – C:\Users\Michelle\Desktop\HiJackThis.lnk
[2012/01/08 03:47:09 | 000,023,472 | -HS- | C] () – C:\Users\Michelle\AppData\Local\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/08 03:47:09 | 000,023,472 | -HS- | C] () – C:\ProgramData\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/05 18:37:37 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2A68A1E6-542C-43BC-94A1-452279073888}
[2012/01/05 17:56:15 | 000,000,370 | —- | C] () – C:\Windows\tasks\RegCure Startup.job
[2012/01/02 09:31:20 | 000,000,396 | —- | C] () – C:\Windows\tasks\RegCure Program Check.job
[2012/01/02 09:31:19 | 000,000,378 | —- | C] () – C:\Windows\tasks\RegCure.job
[2012/01/01 19:43:12 | 3177,594,880 | -HS- | C] () – C:\hiberfil.sys
[2011/12/31 22:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/12/31 22:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/12/31 22:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/12/31 22:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/12/31 22:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/31 20:08:25 | 000,009,942 | -HS- | C] () – C:\ProgramData\40581635
[2011/12/30 20:44:45 | 000,010,502 | -HS- | C] () – C:\Users\Michelle\AppData\Local\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/30 20:44:45 | 000,010,502 | -HS- | C] () – C:\ProgramData\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/21 21:33:55 | 000,099,840 | —- | C] () – C:\Users\Michelle\Documents\yule log.pub
[2011/11/12 22:05:18 | 000,484,352 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2011/11/05 19:13:46 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2855CEEC-8738-4DDC-8CC1-B74763F71AB9}
[2011/11/03 19:07:02 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{B39DA448-7414-402A-B659-F947F88FA288}
[2011/11/03 07:59:43 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{0CDE21AC-147B-4638-BA62-871E54B553E0}
[2011/10/31 04:38:04 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{8B8AE814-6A19-47D3-A638-C069075BE3B4}
[2011/10/31 04:32:13 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{D94D4CBB-BCA4-40F9-9BA5-34510BCC0A5E}
[2011/10/30 22:20:37 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{3186789C-59D3-43DD-BF4F-D5A598753D0C}
[2011/10/30 22:19:24 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{B65A94DD-504C-49FB-A2AB-F5687DBD2E22}
[2011/10/30 22:15:05 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2EF3DF48-D9BA-47FD-B001-D0C4F7447481}
[2011/10/30 21:56:15 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{3B13DEEB-A32E-47B1-B6EC-04DEEC0C6FD2}
[2011/10/29 21:45:52 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{7AF9BCAA-3047-49EF-88CA-4C666C674ADD}
[2011/10/26 01:46:07 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/10/26 01:45:29 | 000,262,775 | —- | C] () – C:\Users\Michelle\AppData\Local\census.cache
[2011/10/26 01:45:04 | 000,200,105 | —- | C] () – C:\Users\Michelle\AppData\Local\ars.cache
[2011/10/24 23:34:33 | 000,000,000 | —- | C] () – C:\ProgramData\c2b5892df79b7c60e07a6ee6ccf7b81f_c
[2011/09/30 02:21:56 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2011/07/26 17:08:40 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{E3D19B65-A322-430E-8257-CE459AE42787}
[2011/06/15 09:20:52 | 000,105,240 | —- | C] () – C:\Windows\System32\RSTCoin.dll
[2011/05/29 20:15:58 | 000,000,036 | —- | C] () – C:\Users\Michelle\AppData\Local\housecall.guid.cache
[2011/05/21 07:42:09 | 000,000,372 | —- | C] () – C:\Windows\LuckyStreakPoker.ini
[2011/05/19 10:59:20 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2854FE19-6929-498A-99B3-BABB15E6575B}
[2011/05/17 00:54:25 | 000,095,847 | —- | C] () – C:\Users\Michelle\AppData\Roaming\Talk.dmp
[2011/01/06 01:35:53 | 000,162,763 | —- | C] () – C:\Windows\hpoins28.dat.temp
[2011/01/06 01:35:53 | 000,000,796 | —- | C] () – C:\Windows\hpomdl28.dat.temp
[2010/07/12 02:56:07 | 008,892,928 | —- | C] () – C:\ProgramData\atscie.msi
[2010/04/30 23:52:47 | 000,000,048 | —- | C] () – C:\Windows\TaxACT09.ini
[2010/04/13 02:28:38 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2010/04/13 02:22:52 | 000,982,196 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/04/13 02:22:51 | 000,139,824 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2010/04/13 02:22:51 | 000,097,448 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/04/13 02:22:50 | 000,417,344 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/03/25 19:57:28 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2010/03/23 12:50:52 | 000,023,317 | —- | C] () – C:\Users\Michelle\AppData\Roaming\UserTile.png
[2009/11/13 14:11:20 | 000,001,356 | —- | C] () – C:\Users\Michelle\AppData\Local\d3d9caps.dat
[2009/09/17 00:50:42 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/17 00:50:41 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/17 00:50:19 | 000,041,984 | —- | C] () – C:\Windows\System32\mimefilt.dll
[2009/06/15 21:43:15 | 000,030,208 | —- | C] () – C:\Users\Michelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/15 18:42:46 | 000,000,924 | —- | C] () – C:\Users\Michelle\AppData\Roaming\wklnhst.dat
[2009/05/09 20:42:49 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1576.dll
[2009/05/09 20:42:49 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2009/05/09 20:39:00 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/09 18:30:10 | 000,066,048 | —- | C] () – C:\Windows\System32\STWiz.dll
[2009/05/09 18:30:09 | 000,471,040 | —- | C] () – C:\Windows\System32\PSTImage.dll
[2009/05/09 18:30:09 | 000,385,024 | —- | C] () – C:\Windows\System32\STODD.dll
[2009/05/09 18:30:09 | 000,380,928 | —- | C] () – C:\Windows\System32\STODDRD.dll
[2009/05/09 18:30:09 | 000,266,240 | —- | C] () – C:\Windows\System32\STODDIM.dll
[2009/05/09 18:30:09 | 000,253,952 | —- | C] () – C:\Windows\System32\STODDSC.dll
[2009/05/09 18:30:09 | 000,229,376 | —- | C] () – C:\Windows\System32\STFiles.dll
[2009/05/09 18:30:09 | 000,122,880 | —- | C] () – C:\Windows\System32\STLog.dll
[2009/05/09 18:30:09 | 000,118,784 | —- | C] () – C:\Windows\System32\STCrypto.dll
[2009/05/09 18:30:09 | 000,115,712 | —- | C] () – C:\Windows\System32\STNLS.dll
[2009/05/09 18:30:09 | 000,110,592 | —- | C] () – C:\Windows\System32\PSTVdsDisk.dll
[2009/05/09 18:30:09 | 000,106,496 | —- | C] () – C:\Windows\System32\STPE.dll
[2009/05/09 18:30:09 | 000,098,304 | —- | C] () – C:\Windows\System32\STFileMonitor.dll
[2009/05/09 18:30:09 | 000,094,208 | —- | C] () – C:\Windows\System32\STMsXml.dll
[2009/05/09 18:30:09 | 000,090,112 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2009/05/09 18:30:09 | 000,077,824 | —- | C] () – C:\Windows\System32\STLangXml.dll
[2009/05/09 18:30:09 | 000,073,728 | —- | C] () – C:\Windows\System32\zlib1.dll
[2009/05/09 18:30:09 | 000,069,632 | —- | C] () – C:\Windows\System32\STRegistry.dll
[2009/05/09 18:30:09 | 000,065,536 | —- | C] () – C:\Windows\System32\STProcess.dll
[2009/05/09 18:30:08 | 000,126,976 | —- | C] () – C:\Windows\System32\STWmiM.dll
[2009/05/09 18:30:08 | 000,102,400 | —- | C] () – C:\Windows\System32\STShellVC6.dll
[2009/05/09 18:30:06 | 000,053,248 | —- | C] () – C:\Windows\System32\STCoreXml.dll
[2009/05/09 18:30:05 | 001,118,208 | —- | C] () – C:\Windows\System32\libxml2.dll
[2009/05/09 18:05:24 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2009/05/09 18:05:23 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/05/09 18:05:22 | 000,026,112 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2009/04/10 13:50:26 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2008/02/03 15:37:35 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 04:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 04:44:53 | 000,379,584 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 02:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 02:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 02:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 02:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 02:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 00:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 00:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/01 23:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/01 23:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2009/06/19 22:38:36 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\acccore
[2011/07/28 03:20:29 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Anarchy
[2010/06/22 04:20:57 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Awem
[2010/03/22 12:25:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\AzuazGames
[2011/11/16 02:00:17 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\C4amH5sWJdLgZhX
[2010/05/01 09:58:24 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/29 02:48:54 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Dekovir
[2011/11/16 02:27:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\e7fRLTXYCkVzNx0
[2011/11/15 21:51:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\eibD3pnG4Q6KfLg
[2009/06/26 23:15:07 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Farm Mania
[2011/11/16 02:00:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\felOBtzP0c1v2n4
[2011/11/12 22:05:36 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\FreeAudioPack
[2009/08/17 21:16:50 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\funkitron
[2011/05/14 00:25:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Goodsol
[2011/11/15 21:20:30 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\HWf9XYkrNAci3GQ
[2011/12/08 19:40:45 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iolo
[2011/05/19 00:18:22 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iWin
[2011/11/15 21:51:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\jXqjYeIzOt
[2011/11/15 21:20:24 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\KFG5sJ6dE8RTjCl
[2011/01/08 12:51:17 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Local
[2010/06/21 22:46:21 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Ludia
[2011/07/25 22:59:02 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Media Get LLC
[2010/05/30 00:50:54 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Motion Technologies
[2011/05/14 04:06:03 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\MusicNet
[2011/05/17 00:34:06 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\NCH Swift Sound
[2011/01/10 22:46:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\PCDr
[2010/03/23 12:50:52 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\PeerNetworking
[2010/06/22 03:25:38 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Quirky Games
[2010/03/25 19:57:40 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Silverback Productions
[2011/03/19 05:58:13 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Smith Micro
[2010/09/17 18:28:04 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Software602
[2009/06/15 18:42:51 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Template
[2011/05/17 03:02:01 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Uniblue
[2010/05/29 20:40:57 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Wildfire
[2009/08/29 00:10:31 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\WildTangentv1005
[2010/07/21 22:16:32 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Winv1000
[2010/07/25 21:19:50 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\YoudaGames
[2010/03/29 02:48:53 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Zylom
[2012/01/08 09:07:49 | 000,000,334 | —- | M] () – C:\Windows\Tasks\DriverScanner.job
[2012/01/02 19:04:04 | 000,000,396 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2012/01/05 17:56:16 | 000,000,370 | —- | M] () – C:\Windows\Tasks\RegCure Startup.job
[2012/01/02 09:31:20 | 000,000,378 | —- | M] () – C:\Windows\Tasks\RegCure.job
[2012/01/08 15:58:57 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/04 03:12:47 | 000,000,428 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{36208B43-B2D5-4E48-941E-647F85B3C819}.job
[2011/01/04 03:08:00 | 000,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A4669C00-D109-4B35-ACB9-2A389274988B}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 13:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 22:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 13:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/05/09 20:43:00 | 000,003,462 | RH– | M] () – C:\dell.sdr
[2010/03/03 12:41:02 | 000,096,264 | —- | M] (Microsoft Corporation) – C:\GameuxInstallHelper.dll
[2012/01/08 15:59:52 | 3177,594,880 | -HS- | M] () – C:\hiberfil.sys
[2010/05/16 14:58:31 | 000,304,152 | —- | M] () – C:\img2-001.raw
[2010/05/17 23:59:44 | 000,921,624 | —- | M] () – C:\img2-002.raw
[2009/07/21 04:15:42 | 000,304,152 | —- | M] () – C:\img2-003.raw
[2010/05/18 00:13:17 | 000,057,624 | —- | M] () – C:\img2-016.raw
[2010/08/18 01:28:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/06/19 22:38:16 | 000,000,367 | -H– | M] () – C:\IPH.PH
[2010/08/18 01:28:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/01/08 15:59:51 | 3493,470,208 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 04:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 04:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 04:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/26 14:01:11 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 13:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/01/20 18:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 18:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 10:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/09/02 00:08:13 | 000,001,610 | -H– | M] () – C:\Users\Michelle\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2008/01/20 18:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 19:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 19:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 19:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 02:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 02:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/18 11:13:56 | 000,000,452 | -HS- | M] () – C:\Users\Michelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/08 10:05:26 | 000,453,424 | —- | M] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/08 11:50:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2009/04/10 13:50:26 | 000,013,023 | —- | M] () – C:\Windows\VX3000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-23 07:18:23
< >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$] -> -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 368 bytes -> C:\Windows\System32\drivers\fyyxiial.sys:changelist
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:93F3E4C9
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3DBE30A1
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AB03533D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:207D7AF7
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:90C12AC3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:30E15544
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3939CF5F
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:1DEF8447
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:AA199F0F
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E0E19514
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:972E051C
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5154845A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:30F93CC3
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DF30C7A6
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:59846E5E
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:E98B604F
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:E025AEA1
< End of report >
Here's the result of the Extras.txt scan:
OTL Extras logfile created on: 1/8/2012 4:05:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Michelle\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 60.95% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.30% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 25.97 Gb Free Space | 19.33% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 4.12 Gb Free Space | 28.11% Space Free | Partition Type: NTFS
Computer Name: MICHELLE | User Name: Michelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = 1Xu] – "C:\Users\Michelle\AppData\Local\yvd.exe" -a "%1" %*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{015B087C-9436-4103-813D-3E5F8825C8F1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{034FE0A9-EFC9-4539-AAE7-88F03C50D4FC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{06BF8E0E-2817-4CD7-8293-A1C2DEE8C449}" = lport=139 | protocol=6 | dir=in | app=system |
"{08B9D8B4-190C-4381-BD99-1E08AFD287A5}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{0A483666-F3AA-4656-899F-EDC9DFACE8AE}" = lport=4100 | protocol=17 | dir=in | name=upnp router control port |
"{10C2C10E-E3F8-448C-9207-3CA703E92933}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{12BA6350-EB12-4E4A-88AE-6DB3AD8628D1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{13241885-51E4-494C-9A9E-8535F7697B70}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{17A907C3-9DFD-4B2B-BC79-E9B447C02E5B}" = rport=2869 | protocol=6 | dir=out | app=system |
"{20E8D1F1-BFA0-4798-88A2-D7B147F95959}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{243E21B7-E291-450C-9862-D2C27C3B18DD}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{26583938-AFEA-45FB-AA4E-4EEDB5B655A1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{2D843BB9-E8F4-4632-91C5-C05F5DB20366}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3194E9F1-4F63-44E2-B4BA-63BF9E92B382}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3EFD0E73-DABD-49AC-A886-73F58B72357E}" = lport=445 | protocol=6 | dir=in | app=system |
"{3FAB4027-4FA7-40E1-A607-D5879DAE3F5E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4064080D-7660-4D3A-83C1-BAC60A393458}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4A5053DC-DB3F-4AD5-958A-6E7745D1C8F4}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4B73944E-01F4-4385-97B0-E405E788EA28}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D87539B-0A6E-4619-BE8E-766273646E7B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{4E9B29CD-EB90-4C12-9A15-AF4487041836}" = rport=138 | protocol=17 | dir=out | app=system |
"{564B92C4-20A1-41F3-8224-E0E705C19493}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{5BD62A44-6211-4291-A5DA-B4D78F2EB4CB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{60F2CADE-32FA-4A61-ADCA-4F5CA8CDE59F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{6391091D-C3BA-4EC0-9EC7-4C773156954F}" = lport=445 | protocol=6 | dir=in | app=system |
"{6BFD54E1-E4B8-4465-B911-12F25F159954}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6E9276F2-04E8-409E-A13E-F5D75837A81B}" = lport=138 | protocol=17 | dir=in | app=system |
"{74E378AA-0F11-4FAC-9492-DD8F26374884}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8405560B-ED09-42B3-9A8A-ADC15C7A6903}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8E41856F-7B24-41FC-9148-92379DC01C85}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8EB2E02D-DE3C-4A65-A299-B39C3874D9FF}" = rport=445 | protocol=6 | dir=out | app=system |
"{8FDFB95F-99E9-418A-B72B-E5F44E1CDDEC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{90ECF05B-183C-4F2D-BFE0-622F2F0D5DBD}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{92493B5A-C1A6-460A-9FD1-042BAD72EAA7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{98AF3867-0940-4ACA-9868-B416457B09E9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A122A609-C991-444A-ADB9-3102E08501F0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A2DD7D74-B7DB-4F6B-8327-E24EBA84D000}" = rport=137 | protocol=17 | dir=out | app=system |
"{AA47A43A-A9FD-43FC-9689-D6EF458725BF}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{AAFB824B-D1EC-49E5-B1A7-F8F3E76BDBF3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AB9F1D53-E57F-4CDC-90A2-7A39554EC06B}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{ABACFBB3-8540-48D6-9AEB-5D792653DE5C}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{AE0CE16B-BC1C-4A52-98D7-E31CC024EABB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{B5010FB2-B33A-4D90-8793-C84D035E7449}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BBB86563-A2A0-4EA5-9173-ECF31AAB7A9B}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{BEDB36B6-11BA-4306-AAAA-36FDF2060A3B}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{C168DF99-A8CA-4F98-B835-79C250039713}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C28385EF-BA3C-49D4-9AE5-A848D0301DD6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C34B5637-452B-417C-A294-AB7B7E1F78EE}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CD3D7DE0-2D07-4FAE-923A-8B7111238E6B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D573C6B9-045B-49B1-8460-5976616E8BF0}" = lport=137 | protocol=17 | dir=in | app=system |
"{E72921DF-58B0-43D1-A327-CE08271DF8AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{EC54F4AD-227B-478A-B2E2-39F1920BADAF}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{EF44DBFE-4751-4B11-8C9D-46A8867EAD09}" = rport=139 | protocol=6 | dir=out | app=system |
"{F5507CE4-0F05-44FF-AE62-85B2EEF36882}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FC42B436-BBE1-4AB4-8E74-C0CE07D0C765}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{040ED978-B5B2-44B8-B739-6558D702F76E}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{09203817-354E-46FC-AC2E-ED47FC77A028}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{101A3AA6-29BC-4D3B-B4A1-F3BB8342FB9C}" = protocol=6 | dir=in | app=c:\program files\pazera toolbar\toolbarupdate.exe |
"{1051D100-B383-44BD-99D0-4FA20A2F4294}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{11318AFC-8099-4A59-AA38-6969437E453D}" = protocol=17 | dir=in | app=c:\program files\pazera toolbar\toolbarupdate.exe |
"{163C1C3E-F92F-45E4-A428-03F714FCA808}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{1F0A8761-9F26-4130-A3C1-CF0B5BC999A1}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{2506C2D2-45FF-4CA2-8366-0321ABC28352}" = protocol=6 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{2906AE94-D8AC-4672-9425-97BA6762F952}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{29EC4245-648B-4564-A624-89798A31FAE5}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{2B5F2F2E-FAB5-4000-9BC3-C3608C266B56}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2B71B8C5-8723-4C91-8404-8D469D254A46}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{2BE28BE1-BD68-427D-8308-A8985BB1B71B}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{318C8921-BACE-44BD-B13E-40E08E0B14E9}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{355DBE26-F5A8-4B1A-8BE3-DB9FC3018BAD}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{35CA311F-20ED-4562-A558-3DCC114A0F8F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{3905B407-FAA0-4D58-9990-8B93C9351264}" = protocol=6 | dir=out | app=system |
"{3A7CCB8A-4375-4E27-99AD-B41EA30932ED}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{4292D5F5-069D-478F-B1AB-70348B42C827}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{5028CAA2-2981-4039-B981-E3FEDDAC312E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{517ACF21-F4A5-48F1-88E4-6BBB2D8723D1}" = protocol=17 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{555E3503-BE8E-4524-839A-D796203BC07F}" = protocol=6 | dir=out | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{5A8125C7-BFF1-413D-B9AA-CC333D2D31CB}" = protocol=17 | dir=in | app=c:\program files\pazera toolbar\troubleshooter.exe |
"{5C99C0DF-5451-4052-98E7-A254C23E4661}" = protocol=6 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{63B39D41-2C5C-4D4A-903D-37B97DA8F1FC}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6A593194-161E-4E90-A980-E8952E2780B3}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6D31CFAB-426D-4B28-AD81-3346B59B405A}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{6E814D74-5A65-4554-8D32-05DDD43E3E65}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{76FE9928-103B-4226-8558-A3B1A17568F3}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{7A519F29-C8F0-40FA-8929-C06C235030C9}" = protocol=6 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{8BE93F1D-DD06-4FEE-8525-CA69DAD87F95}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{93930D0D-F6AD-4BE1-B235-D5EC49D331DA}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{94630CCA-A46F-41E7-9574-424938ED5DF2}" = protocol=17 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{96C7EAAF-4AEE-489B-B805-87B737B22979}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{9C9C9383-C85C-4A79-BCDA-F505ABC1ACAB}" = protocol=17 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{A97D5FB6-C4DB-457B-B20E-F6A04B618E8C}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{AA1FDC16-A1FE-49A9-ABA8-62F6959B79D7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AB1C0BE0-3638-4BC3-B0F8-0DA829EF9E25}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{AB7F5A79-9936-4D56-A8B6-0438726040CB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AC355751-EFF3-4BCD-91B9-29075C976AB6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{ACD7E04A-D3A9-4026-9719-99AE342AD071}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{B0C263FB-75E6-4A15-80C8-6A3666F6BF58}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD3D4A6E-CED3-4EB4-A05E-1A30054190B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BE4B0799-F385-435E-BA01-5EA649D13B85}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{C1BC1FFA-45B1-41B7-B768-53777DDAF9CA}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{C24E5B05-2AC3-49B2-8A6D-738511F74544}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{C95C6F4D-A000-4470-B48B-2EBB7707975D}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{CB5B4EE4-F1E2-4FC6-9B40-F26EBEF8C1A4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D150DF88-1924-4732-9684-1198A5DED8D0}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{D598B05B-81C6-421B-B719-B33AE5F52FEE}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{D80830B4-D3D5-4447-8F89-02C94FC76A4D}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{D82300B3-C39D-4D87-831A-751ED1026570}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{DA2F5892-5CB9-4DFF-B5CC-A500398E5164}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{DABFC7BC-6E17-49F1-AB3E-5E2F787D44FA}" = protocol=6 | dir=in | app=c:\program files\pazera toolbar\troubleshooter.exe |
"{DAF56F22-EFD7-469A-8E0F-0745A6BE2F71}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{E55496F5-16B6-43BF-B200-518E44786044}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E7EDBC97-FA1E-4A5B-86E1-AF55216001BB}" = protocol=6 | dir=in | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{F55BDD11-6851-4B86-B1F6-1B17D9F8F0AA}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{F8C5CFD1-CC55-4D94-A38A-47B155943286}" = protocol=6 | dir=out | app=system |
"{F97927DF-7D9B-44F1-A189-573F4508728E}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{FBBED9FE-9F9F-4197-A368-D119EABA6AFA}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{FE6433A9-CD36-43C5-9D08-9EB615877760}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{FE9DF07C-6418-445D-852C-031AF50A9393}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"TCP Query User{14C9FEC2-594E-48FA-BC5B-1536C3780117}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"TCP Query User{4856E0FC-C15D-440F-AEE1-BE7FD03CEE38}C:\program files\nch swift sound\talk\talk.exe" = protocol=6 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"TCP Query User{49B8C274-9170-41B5-BBCD-33C461D5A38F}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"TCP Query User{52E27ADD-BF2C-4340-A0C4-80D23F0688E9}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{57533EDB-DB87-41E8-9790-44E742B01FEE}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{676BA86A-FF84-4627-9007-349B61F5F2C3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{82A9A12A-3113-41B8-AE57-769B4A78528A}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{8F613C3E-F96B-4262-A578-9B1CC5E6A92B}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{9A60AC5D-06AF-43DE-8CA6-4BA5C3C954DB}C:\program files\nch swift sound\talk\talk.exe" = protocol=6 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"TCP Query User{A76625DA-3212-4271-8868-568D92E7EFB7}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{D94E60D0-C1A7-4727-9EDA-32E05AE6E13F}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{E1D7A377-FE87-49ED-B2B9-3BA0F519807A}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F599A68B-E118-4103-BFB3-D515863D4CF8}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{0BC2D0B6-3780-4765-A9EA-EDD1D77B2FDF}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{1F100206-6D15-4C20-9FEE-C5AC40512394}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"UDP Query User{3C19332F-4622-4013-94D5-EB69FF7A1AA6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{6491FCED-1DDB-4093-8F7B-F5D9263959C9}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7AE896A1-8307-427A-BCE8-F701425C5DBA}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{97846F5D-7A5F-4135-B588-F31A59381A00}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{ADF65486-37B3-4FB4-8BD8-D7E8130626E0}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"UDP Query User{CE7F4610-7BC5-439D-8850-397A21576F94}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{D5AFEB82-D3F9-4549-8A60-1CA47DA7C418}C:\program files\nch swift sound\talk\talk.exe" = protocol=17 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"UDP Query User{D83B3157-49B0-4EAE-8BA7-2430E703A8F4}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{DD1E92D3-0E80-46D2-9773-7F8D2711B3F3}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{F388ED51-02E6-4300-AEB5-BDD4B4956643}C:\program files\nch swift sound\talk\talk.exe" = protocol=17 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"UDP Query User{F90B1FC2-6110-4416-A075-C8F86BB75975}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{053C30EA-D4C6-47A0-8537-8D231D9BE873}" = DELL0703
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22443966-38F8-8A4D-AA16-0FBFA246881F}" = Acrobat.com
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C4B0182-8B51-46A1-89A3-FC16CA885688}" = Force ASPI GUI
"{2E661193-B28F-4D59-A534-9E0D294B39F8}" = DVD Copy Plus
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{32C74893-0243-4235-A6F3-201F0E5D2C03}" = Print2PDF
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1" = System Checkup 3.0
"{4B719A70-F14A-4f5c-90B5-346B24B7FFF1}" = Windows 7 Upgrade Advisor
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-dell" = WildTangent Games App (Dell Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7B08D306-7266-4647-A926-2F78817ED1E0}" = Microsoft Corporation
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC2BA148-EE9C-4F1A-AFCE-F38C2C71D29B}" = Mobile Broadband Generic Drivers
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}" = Microsoft LifeCam
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}" = Windows Vista Upgrade Advisor
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.22beta
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Aqua Bubble 2_is1" = Aqua Bubble 2
"avast" = avast! Free Antivirus
"Best Game Hits 3" = Best Games Hits 3
"BFG-Brain Training for Dummies" = Brain Training for Dummies
"BFGC" = Big Fish Games: Game Manager
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"CardWorks" = CardWorks Business Card Software
"ClassicCard" = Parker Brothers Classic Card Games
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Dock" = Dell Dock
"DivX Setup.divx.com" = DivX Setup
"DVD Flick_is1" = DVD Flick [removed]
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ExpressBurn" = Express Burn Disc Burning Software
"FLAC" = FLAC 1.2.1b (remove only)
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.1
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"HDMI" = Intel® Graphics Media Accelerator Driver
"Info Center_is1" = Info Center 1.0.0.7
"iWinArcade" = iWin Games (remove only)
"Jewel Quest Mysteries: The Seventh Gate Collector's Edition" = Jewel Quest Mysteries: The Seventh Gate Collector's Edition (remove only)
"Jewel Quest Solitaire II" = Jewel Quest Solitaire II (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"My Lockbox_is1" = My Lockbox 2.1
"PhotoPad" = PhotoPad Image Editor
"RegCure" = RegCure
"RegistryCleaner" = Registry Cleaner 2.1
"ST6UNST #1" = Jomrati
"TaxACT 2009" = TaxACT 2009
"TVWiz" = Intel® TV Wizard
"Veer® Images add-in" = Veer® Images add-in
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 5.9.4
"Zuma's Revenge!" = Zuma's Revenge!
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"f031ef6ac137efc5" = Dell Driver Download Manager - 1
"MediaGet" = MediaGet
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Thank you in advance for your advice/assistance…Michelle.
OTL logfile created on: 1/8/2012 4:05:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Michelle\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 60.95% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.30% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 25.97 Gb Free Space | 19.33% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 4.12 Gb Free Space | 28.11% Space Free | Partition Type: NTFS
Computer Name: MICHELLE | User Name: Michelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Michelle\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Windows\System32\fsproflt.exe (FSPro Labs)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Windows\sminst\SftService.exe (SoftThinks)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MenuSkinning\81e6be802192a566528fece5fa6a8789\MenuSkinning.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\69a1720a5ab185c7136a0f058b38961f\VistaBridgeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DellDock\25c76ad67fef8be9d616eee5c9b09ad5\DellDock.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\6f95622a73f120e3519d1103fd57c291\MyDock.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (fsproflt) – C:\Windows\System32\fsproflt.exe (FSPro Labs)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (SftService) – C:\Windows\sminst\sftservice.EXE (SoftThinks)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Driver Services (SafeList) ==========
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (MSHUSBVideo) – C:\Windows\System32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (USBModem) – C:\Windows\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\Windows\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\Windows\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (PCD5SRVC{3F6A8B78-EC003E00-05040104}) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (FSProFilter) – C:\Windows\System32\Drivers\FSPFltd.sys (FSPro Labs)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (QCDonner) Logitech QuickCam Express(PID_0840) – C:\Windows\System32\drivers\lvcd.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search..defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngineURL: "http://mp3tubetoolbar.com/?&prt;=pinballtbfour01ff&clid;=7802689e8e10412e949ed474dae1d9d3&subid;=&keywords;={searchTerms}"
FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbarsearch.com/?prt=pinballtbfour01ff&clid;=7802689e8e10412e949ed474dae1d9d3&subid;=&Keywords;={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.5.2
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.22
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.8.0.8855
FF - prefs.js..extensions.enabledItems: [removed]:6.0.1367
FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/08 12:51:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/08 12:51:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/20 03:24:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/04 11:49:15 | 000,000,000 | —D | M]
[2010/06/01 04:29:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\a6uc8xva.default\extensions
[2012/01/08 14:40:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/25 18:50:05 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/11/17 19:05:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/05 11:31:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/08/04 23:25:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/09/14 04:48:25 | 000,002,506 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: DivX HiQ = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: avast! WebRep = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AT_KarimRashidV3 = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldjcbfljkplgifccngillicohclloidg\3_0\
CHR - Extension: Skype Click to Call = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
CHR - Extension: Gmail = C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2006/09/18 13:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe (FSPro Labs)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Program Files\Software602\Print2PDF\Print602.dll (Software602 a.s.)
O9 - Extra 'Tools' menuitem : Print2PDF - {5B7027AD-AA6D-40df-8F56-9560F277D2A5} - C:\Program Files\Software602\Print2PDF\Print602.dll (Software602 a.s.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.com/DellDriverScanner/DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…554/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{576D5C9A-D5EA-44C8-B117-4140FABBE3FF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - File not found
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Michelle\Pictures\iced snowfla.jpg
O24 - Desktop BackupWallPaper: C:\Users\Michelle\Pictures\iced snowfla.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 13:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 13:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O33 - MountPoints2\{336bd958-5209-11e0-936d-a4badb9f2af6}\Shell - "" = AutoRun
O33 - MountPoints2\{3aa8d41c-41ef-11df-a0fa-a4badb9f2af6}\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = AX] – "%1" %*
O37 - HKCU\…exe [@ = 1Xu] – "C:\Users\Michelle\AppData\Local\yvd.exe" -a "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/08 11:50:47 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2012/01/08 11:26:47 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/01/08 11:26:47 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/01/08 10:04:47 | 000,453,424 | —- | C] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/05 20:27:29 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\TPB-The.Twilight.Saga.Eclipse.2010.480p.BRRip.XviD.AC3-FLAWL3SS
[2012/01/04 23:05:46 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\The.Twilight.Saga.Breaking.Dawn.2011.CAMRiP.XViD.Baker92
[2012/01/04 22:39:07 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\David Bowie - Best of Bowie
[2012/01/02 09:28:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegCure
[2012/01/02 09:28:31 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2012/01/02 09:22:34 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\RegCure 3.0.2(latest) by Kkeibul
[2012/01/01 10:37:13 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/31 22:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/12/31 22:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/12/31 22:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/12/31 22:16:07 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/12/31 22:16:06 | 000,000,000 | –SD | C] – C:\ComboFix
[2011/12/31 22:14:59 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/28 02:37:18 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\dvd
[2011/12/28 02:31:29 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\DVD Flick
[2011/12/28 02:30:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick
[2011/12/28 02:29:02 | 000,609,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comctl32.ocx
[2011/12/28 02:29:02 | 000,040,960 | —- | C] (vbAccelerator) – C:\Windows\System32\ssubtmr6.dll
[2011/12/28 02:29:02 | 000,036,864 | —- | C] (Robdogg Inc.) – C:\Windows\System32\trayicon_handler.ocx
[2011/12/28 02:29:02 | 000,028,672 | —- | C] (-) – C:\Windows\System32\mousewheel.ocx
[2011/12/28 02:29:01 | 000,212,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\richtx32.ocx
[2011/12/28 02:29:01 | 000,000,000 | —D | C] – C:\Program Files\DVD Flick
[2011/12/25 18:48:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/12/25 18:48:13 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2011/12/21 23:28:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FLAC
[2011/12/21 23:28:43 | 000,000,000 | —D | C] – C:\Program Files\FLAC
[2011/12/19 21:38:52 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\VA-Now_Christmas_2011-2CD-2011-pLAN9 www.0dayvinyls.org
[2011/12/19 21:31:54 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\So Fresh Songs For Christmas 2010 2CD 320KB TBS Spookkie
[2011/12/19 21:30:46 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\Christmas - Xmas Party - 3-CD-Boxset-[TFM]
[2011/12/17 19:45:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/12/17 09:51:26 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2011/12/17 09:51:21 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2011/12/14 03:15:17 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 03:15:14 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 03:15:14 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 03:15:13 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 03:15:12 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 03:15:07 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/13 14:01:35 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/13 14:01:35 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/13 13:50:23 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/13 13:50:21 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/13 13:50:20 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/13 13:49:16 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/11 21:30:42 | 000,000,000 | —D | C] – C:\Users\Michelle\Documents\Michelle pcsi
[2011/12/10 22:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jomrati
[2011/12/10 22:51:12 | 000,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jomrati
[2011/12/10 22:51:09 | 000,000,000 | —D | C] – C:\Program Files\Jomrati
[2011/12/10 22:50:38 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\Setup1.exe
[2011/12/10 22:50:37 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\ST6UNST.EXE
[5 C:\Users\Michelle\AppData\Local\*.tmp files -> C:\Users\Michelle\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/08 16:00:17 | 000,004,128 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 16:00:17 | 000,004,128 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 15:59:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/08 15:59:52 | 3177,594,880 | -HS- | M] () – C:\hiberfil.sys
[2012/01/08 15:49:14 | 000,078,885 | —- | M] () – C:\Users\Michelle\Desktop\Gold-Flo_sheet.pdf
[2012/01/08 15:42:35 | 000,577,485 | —- | M] () – C:\Users\Michelle\Desktop\facet fuel pump.pdf
[2012/01/08 11:50:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2012/01/08 11:30:06 | 000,002,489 | —- | M] () – C:\Users\Michelle\Desktop\HiJackThis.lnk
[2012/01/08 10:05:26 | 000,453,424 | —- | M] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/08 09:07:49 | 000,000,334 | —- | M] () – C:\Windows\tasks\DriverScanner.job
[2012/01/08 08:47:41 | 000,023,472 | -HS- | M] () – C:\Users\Michelle\AppData\Local\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/08 08:47:41 | 000,023,472 | -HS- | M] () – C:\ProgramData\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/07 15:44:06 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/01/05 18:37:37 | 000,000,000 | —- | M] () – C:\Users\Michelle\AppData\Local\{2A68A1E6-542C-43BC-94A1-452279073888}
[2012/01/05 17:56:16 | 000,000,370 | —- | M] () – C:\Windows\tasks\RegCure Startup.job
[2012/01/03 00:11:01 | 000,030,208 | —- | M] () – C:\Users\Michelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/02 19:04:04 | 000,000,396 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2012/01/02 09:31:20 | 000,000,378 | —- | M] () – C:\Windows\tasks\RegCure.job
[2011/12/31 22:08:34 | 000,009,942 | -HS- | M] () – C:\ProgramData\40581635
[2011/12/31 21:57:46 | 000,010,502 | -HS- | M] () – C:\Users\Michelle\AppData\Local\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/31 21:57:46 | 000,010,502 | -HS- | M] () – C:\ProgramData\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/30 20:21:37 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/30 20:16:33 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2011/12/21 21:33:55 | 000,099,840 | —- | M] () – C:\Users\Michelle\Documents\yule log.pub
[2011/12/20 22:08:11 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/20 22:08:11 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/14 06:34:30 | 000,379,584 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/10 22:50:38 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\Setup1.exe
[2011/12/10 22:50:37 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\Windows\ST6UNST.EXE
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[5 C:\Users\Michelle\AppData\Local\*.tmp files -> C:\Users\Michelle\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/08 15:49:14 | 000,078,885 | —- | C] () – C:\Users\Michelle\Desktop\Gold-Flo_sheet.pdf
[2012/01/08 15:42:35 | 000,577,485 | —- | C] () – C:\Users\Michelle\Desktop\facet fuel pump.pdf
[2012/01/08 11:26:48 | 000,002,489 | —- | C] () – C:\Users\Michelle\Desktop\HiJackThis.lnk
[2012/01/08 03:47:09 | 000,023,472 | -HS- | C] () – C:\Users\Michelle\AppData\Local\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/08 03:47:09 | 000,023,472 | -HS- | C] () – C:\ProgramData\44fdig18n054en2qt3hkx27q8b6p12668mhf4336o3ky65
[2012/01/05 18:37:37 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2A68A1E6-542C-43BC-94A1-452279073888}
[2012/01/05 17:56:15 | 000,000,370 | —- | C] () – C:\Windows\tasks\RegCure Startup.job
[2012/01/02 09:31:20 | 000,000,396 | —- | C] () – C:\Windows\tasks\RegCure Program Check.job
[2012/01/02 09:31:19 | 000,000,378 | —- | C] () – C:\Windows\tasks\RegCure.job
[2012/01/01 19:43:12 | 3177,594,880 | -HS- | C] () – C:\hiberfil.sys
[2011/12/31 22:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/12/31 22:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/12/31 22:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/12/31 22:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/12/31 22:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/31 20:08:25 | 000,009,942 | -HS- | C] () – C:\ProgramData\40581635
[2011/12/30 20:44:45 | 000,010,502 | -HS- | C] () – C:\Users\Michelle\AppData\Local\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/30 20:44:45 | 000,010,502 | -HS- | C] () – C:\ProgramData\tiu550yq4tnw38lg7h537t8crphav1yt2ausr
[2011/12/21 21:33:55 | 000,099,840 | —- | C] () – C:\Users\Michelle\Documents\yule log.pub
[2011/11/12 22:05:18 | 000,484,352 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2011/11/05 19:13:46 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2855CEEC-8738-4DDC-8CC1-B74763F71AB9}
[2011/11/03 19:07:02 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{B39DA448-7414-402A-B659-F947F88FA288}
[2011/11/03 07:59:43 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{0CDE21AC-147B-4638-BA62-871E54B553E0}
[2011/10/31 04:38:04 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{8B8AE814-6A19-47D3-A638-C069075BE3B4}
[2011/10/31 04:32:13 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{D94D4CBB-BCA4-40F9-9BA5-34510BCC0A5E}
[2011/10/30 22:20:37 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{3186789C-59D3-43DD-BF4F-D5A598753D0C}
[2011/10/30 22:19:24 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{B65A94DD-504C-49FB-A2AB-F5687DBD2E22}
[2011/10/30 22:15:05 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2EF3DF48-D9BA-47FD-B001-D0C4F7447481}
[2011/10/30 21:56:15 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{3B13DEEB-A32E-47B1-B6EC-04DEEC0C6FD2}
[2011/10/29 21:45:52 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{7AF9BCAA-3047-49EF-88CA-4C666C674ADD}
[2011/10/26 01:46:07 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/10/26 01:45:29 | 000,262,775 | —- | C] () – C:\Users\Michelle\AppData\Local\census.cache
[2011/10/26 01:45:04 | 000,200,105 | —- | C] () – C:\Users\Michelle\AppData\Local\ars.cache
[2011/10/24 23:34:33 | 000,000,000 | —- | C] () – C:\ProgramData\c2b5892df79b7c60e07a6ee6ccf7b81f_c
[2011/09/30 02:21:56 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2011/07/26 17:08:40 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{E3D19B65-A322-430E-8257-CE459AE42787}
[2011/06/15 09:20:52 | 000,105,240 | —- | C] () – C:\Windows\System32\RSTCoin.dll
[2011/05/29 20:15:58 | 000,000,036 | —- | C] () – C:\Users\Michelle\AppData\Local\housecall.guid.cache
[2011/05/21 07:42:09 | 000,000,372 | —- | C] () – C:\Windows\LuckyStreakPoker.ini
[2011/05/19 10:59:20 | 000,000,000 | —- | C] () – C:\Users\Michelle\AppData\Local\{2854FE19-6929-498A-99B3-BABB15E6575B}
[2011/05/17 00:54:25 | 000,095,847 | —- | C] () – C:\Users\Michelle\AppData\Roaming\Talk.dmp
[2011/01/06 01:35:53 | 000,162,763 | —- | C] () – C:\Windows\hpoins28.dat.temp
[2011/01/06 01:35:53 | 000,000,796 | —- | C] () – C:\Windows\hpomdl28.dat.temp
[2010/07/12 02:56:07 | 008,892,928 | —- | C] () – C:\ProgramData\atscie.msi
[2010/04/30 23:52:47 | 000,000,048 | —- | C] () – C:\Windows\TaxACT09.ini
[2010/04/13 02:28:38 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2010/04/13 02:22:52 | 000,982,196 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/04/13 02:22:51 | 000,139,824 | —- | C] () – C:\Windows\System32\igfcg500.bin
[2010/04/13 02:22:51 | 000,097,448 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/04/13 02:22:50 | 000,417,344 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/03/25 19:57:28 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2010/03/23 12:50:52 | 000,023,317 | —- | C] () – C:\Users\Michelle\AppData\Roaming\UserTile.png
[2009/11/13 14:11:20 | 000,001,356 | —- | C] () – C:\Users\Michelle\AppData\Local\d3d9caps.dat
[2009/09/17 00:50:42 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/17 00:50:41 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/17 00:50:19 | 000,041,984 | —- | C] () – C:\Windows\System32\mimefilt.dll
[2009/06/15 21:43:15 | 000,030,208 | —- | C] () – C:\Users\Michelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/15 18:42:46 | 000,000,924 | —- | C] () – C:\Users\Michelle\AppData\Roaming\wklnhst.dat
[2009/05/09 20:42:49 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1576.dll
[2009/05/09 20:42:49 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2009/05/09 20:39:00 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/09 18:30:10 | 000,066,048 | —- | C] () – C:\Windows\System32\STWiz.dll
[2009/05/09 18:30:09 | 000,471,040 | —- | C] () – C:\Windows\System32\PSTImage.dll
[2009/05/09 18:30:09 | 000,385,024 | —- | C] () – C:\Windows\System32\STODD.dll
[2009/05/09 18:30:09 | 000,380,928 | —- | C] () – C:\Windows\System32\STODDRD.dll
[2009/05/09 18:30:09 | 000,266,240 | —- | C] () – C:\Windows\System32\STODDIM.dll
[2009/05/09 18:30:09 | 000,253,952 | —- | C] () – C:\Windows\System32\STODDSC.dll
[2009/05/09 18:30:09 | 000,229,376 | —- | C] () – C:\Windows\System32\STFiles.dll
[2009/05/09 18:30:09 | 000,122,880 | —- | C] () – C:\Windows\System32\STLog.dll
[2009/05/09 18:30:09 | 000,118,784 | —- | C] () – C:\Windows\System32\STCrypto.dll
[2009/05/09 18:30:09 | 000,115,712 | —- | C] () – C:\Windows\System32\STNLS.dll
[2009/05/09 18:30:09 | 000,110,592 | —- | C] () – C:\Windows\System32\PSTVdsDisk.dll
[2009/05/09 18:30:09 | 000,106,496 | —- | C] () – C:\Windows\System32\STPE.dll
[2009/05/09 18:30:09 | 000,098,304 | —- | C] () – C:\Windows\System32\STFileMonitor.dll
[2009/05/09 18:30:09 | 000,094,208 | —- | C] () – C:\Windows\System32\STMsXml.dll
[2009/05/09 18:30:09 | 000,090,112 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2009/05/09 18:30:09 | 000,077,824 | —- | C] () – C:\Windows\System32\STLangXml.dll
[2009/05/09 18:30:09 | 000,073,728 | —- | C] () – C:\Windows\System32\zlib1.dll
[2009/05/09 18:30:09 | 000,069,632 | —- | C] () – C:\Windows\System32\STRegistry.dll
[2009/05/09 18:30:09 | 000,065,536 | —- | C] () – C:\Windows\System32\STProcess.dll
[2009/05/09 18:30:08 | 000,126,976 | —- | C] () – C:\Windows\System32\STWmiM.dll
[2009/05/09 18:30:08 | 000,102,400 | —- | C] () – C:\Windows\System32\STShellVC6.dll
[2009/05/09 18:30:06 | 000,053,248 | —- | C] () – C:\Windows\System32\STCoreXml.dll
[2009/05/09 18:30:05 | 001,118,208 | —- | C] () – C:\Windows\System32\libxml2.dll
[2009/05/09 18:05:24 | 000,006,656 | —- | C] () – C:\Windows\System32\bcmwlrc.dll
[2009/05/09 18:05:23 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/05/09 18:05:22 | 000,026,112 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2009/04/10 13:50:26 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2008/02/03 15:37:35 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 04:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 04:44:53 | 000,379,584 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 02:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 02:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 02:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 02:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 02:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 00:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 00:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/01 23:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/01 23:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2009/06/19 22:38:36 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\acccore
[2011/07/28 03:20:29 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Anarchy
[2010/06/22 04:20:57 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Awem
[2010/03/22 12:25:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\AzuazGames
[2011/11/16 02:00:17 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\C4amH5sWJdLgZhX
[2010/05/01 09:58:24 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/03/29 02:48:54 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Dekovir
[2011/11/16 02:27:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\e7fRLTXYCkVzNx0
[2011/11/15 21:51:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\eibD3pnG4Q6KfLg
[2009/06/26 23:15:07 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Farm Mania
[2011/11/16 02:00:18 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\felOBtzP0c1v2n4
[2011/11/12 22:05:36 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\FreeAudioPack
[2009/08/17 21:16:50 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\funkitron
[2011/05/14 00:25:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Goodsol
[2011/11/15 21:20:30 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\HWf9XYkrNAci3GQ
[2011/12/08 19:40:45 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iolo
[2011/05/19 00:18:22 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iWin
[2011/11/15 21:51:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\jXqjYeIzOt
[2011/11/15 21:20:24 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\KFG5sJ6dE8RTjCl
[2011/01/08 12:51:17 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Local
[2010/06/21 22:46:21 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Ludia
[2011/07/25 22:59:02 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Media Get LLC
[2010/05/30 00:50:54 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Motion Technologies
[2011/05/14 04:06:03 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\MusicNet
[2011/05/17 00:34:06 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\NCH Swift Sound
[2011/01/10 22:46:28 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\PCDr
[2010/03/23 12:50:52 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\PeerNetworking
[2010/06/22 03:25:38 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Quirky Games
[2010/03/25 19:57:40 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Silverback Productions
[2011/03/19 05:58:13 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Smith Micro
[2010/09/17 18:28:04 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Software602
[2009/06/15 18:42:51 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Template
[2011/05/17 03:02:01 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Uniblue
[2010/05/29 20:40:57 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Wildfire
[2009/08/29 00:10:31 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\WildTangentv1005
[2010/07/21 22:16:32 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Winv1000
[2010/07/25 21:19:50 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\YoudaGames
[2010/03/29 02:48:53 | 000,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Zylom
[2012/01/08 09:07:49 | 000,000,334 | —- | M] () – C:\Windows\Tasks\DriverScanner.job
[2012/01/02 19:04:04 | 000,000,396 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2012/01/05 17:56:16 | 000,000,370 | —- | M] () – C:\Windows\Tasks\RegCure Startup.job
[2012/01/02 09:31:20 | 000,000,378 | —- | M] () – C:\Windows\Tasks\RegCure.job
[2012/01/08 15:58:57 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/04 03:12:47 | 000,000,428 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{36208B43-B2D5-4E48-941E-647F85B3C819}.job
[2011/01/04 03:08:00 | 000,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A4669C00-D109-4B35-ACB9-2A389274988B}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 13:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 22:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 13:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/05/09 20:43:00 | 000,003,462 | RH– | M] () – C:\dell.sdr
[2010/03/03 12:41:02 | 000,096,264 | —- | M] (Microsoft Corporation) – C:\GameuxInstallHelper.dll
[2012/01/08 15:59:52 | 3177,594,880 | -HS- | M] () – C:\hiberfil.sys
[2010/05/16 14:58:31 | 000,304,152 | —- | M] () – C:\img2-001.raw
[2010/05/17 23:59:44 | 000,921,624 | —- | M] () – C:\img2-002.raw
[2009/07/21 04:15:42 | 000,304,152 | —- | M] () – C:\img2-003.raw
[2010/05/18 00:13:17 | 000,057,624 | —- | M] () – C:\img2-016.raw
[2010/08/18 01:28:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/06/19 22:38:16 | 000,000,367 | -H– | M] () – C:\IPH.PH
[2010/08/18 01:28:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/01/08 15:59:51 | 3493,470,208 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 04:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 04:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 04:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/26 14:01:11 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 13:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/01/20 18:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 18:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 10:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/09/02 00:08:13 | 000,001,610 | -H– | M] () – C:\Users\Michelle\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2008/01/20 18:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 19:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 19:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 19:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 02:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 02:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/18 11:13:56 | 000,000,452 | -HS- | M] () – C:\Users\Michelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/01/08 10:05:26 | 000,453,424 | —- | M] (Microsoft Corporation) – C:\Users\Michelle\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/01/08 11:50:50 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2009/04/10 13:50:26 | 000,013,023 | —- | M] () – C:\Windows\VX3000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-23 07:18:23
< >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\$NtUninstallKB41128$] -> -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Application Data] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Cookies] -> Error: Cannot create file handle -> Unknown point type
[C:\Windows\System32\config\systemprofile\Local Settings] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 368 bytes -> C:\Windows\System32\drivers\fyyxiial.sys:changelist
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:93F3E4C9
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3DBE30A1
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AB03533D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:207D7AF7
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:90C12AC3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:30E15544
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3939CF5F
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:1DEF8447
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:AA199F0F
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E0E19514
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:972E051C
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5154845A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:30F93CC3
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DF30C7A6
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:59846E5E
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:E98B604F
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:E025AEA1
< End of report >
Here's the result of the Extras.txt scan:
OTL Extras logfile created on: 1/8/2012 4:05:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Michelle\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 60.95% Memory free
6.12 Gb Paging File | 5.03 Gb Available in Paging File | 82.30% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 25.97 Gb Free Space | 19.33% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 4.12 Gb Free Space | 28.11% Space Free | Partition Type: NTFS
Computer Name: MICHELLE | User Name: Michelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = 1Xu] – "C:\Users\Michelle\AppData\Local\yvd.exe" -a "%1" %*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{015B087C-9436-4103-813D-3E5F8825C8F1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{034FE0A9-EFC9-4539-AAE7-88F03C50D4FC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{06BF8E0E-2817-4CD7-8293-A1C2DEE8C449}" = lport=139 | protocol=6 | dir=in | app=system |
"{08B9D8B4-190C-4381-BD99-1E08AFD287A5}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{0A483666-F3AA-4656-899F-EDC9DFACE8AE}" = lport=4100 | protocol=17 | dir=in | name=upnp router control port |
"{10C2C10E-E3F8-448C-9207-3CA703E92933}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{12BA6350-EB12-4E4A-88AE-6DB3AD8628D1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{13241885-51E4-494C-9A9E-8535F7697B70}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{17A907C3-9DFD-4B2B-BC79-E9B447C02E5B}" = rport=2869 | protocol=6 | dir=out | app=system |
"{20E8D1F1-BFA0-4798-88A2-D7B147F95959}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{243E21B7-E291-450C-9862-D2C27C3B18DD}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{26583938-AFEA-45FB-AA4E-4EEDB5B655A1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{2D843BB9-E8F4-4632-91C5-C05F5DB20366}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3194E9F1-4F63-44E2-B4BA-63BF9E92B382}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3EFD0E73-DABD-49AC-A886-73F58B72357E}" = lport=445 | protocol=6 | dir=in | app=system |
"{3FAB4027-4FA7-40E1-A607-D5879DAE3F5E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4064080D-7660-4D3A-83C1-BAC60A393458}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4A5053DC-DB3F-4AD5-958A-6E7745D1C8F4}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4B73944E-01F4-4385-97B0-E405E788EA28}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D87539B-0A6E-4619-BE8E-766273646E7B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{4E9B29CD-EB90-4C12-9A15-AF4487041836}" = rport=138 | protocol=17 | dir=out | app=system |
"{564B92C4-20A1-41F3-8224-E0E705C19493}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{5BD62A44-6211-4291-A5DA-B4D78F2EB4CB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{60F2CADE-32FA-4A61-ADCA-4F5CA8CDE59F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{6391091D-C3BA-4EC0-9EC7-4C773156954F}" = lport=445 | protocol=6 | dir=in | app=system |
"{6BFD54E1-E4B8-4465-B911-12F25F159954}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6E9276F2-04E8-409E-A13E-F5D75837A81B}" = lport=138 | protocol=17 | dir=in | app=system |
"{74E378AA-0F11-4FAC-9492-DD8F26374884}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8405560B-ED09-42B3-9A8A-ADC15C7A6903}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8E41856F-7B24-41FC-9148-92379DC01C85}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8EB2E02D-DE3C-4A65-A299-B39C3874D9FF}" = rport=445 | protocol=6 | dir=out | app=system |
"{8FDFB95F-99E9-418A-B72B-E5F44E1CDDEC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{90ECF05B-183C-4F2D-BFE0-622F2F0D5DBD}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{92493B5A-C1A6-460A-9FD1-042BAD72EAA7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{98AF3867-0940-4ACA-9868-B416457B09E9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A122A609-C991-444A-ADB9-3102E08501F0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A2DD7D74-B7DB-4F6B-8327-E24EBA84D000}" = rport=137 | protocol=17 | dir=out | app=system |
"{AA47A43A-A9FD-43FC-9689-D6EF458725BF}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{AAFB824B-D1EC-49E5-B1A7-F8F3E76BDBF3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AB9F1D53-E57F-4CDC-90A2-7A39554EC06B}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{ABACFBB3-8540-48D6-9AEB-5D792653DE5C}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{AE0CE16B-BC1C-4A52-98D7-E31CC024EABB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{B5010FB2-B33A-4D90-8793-C84D035E7449}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BBB86563-A2A0-4EA5-9173-ECF31AAB7A9B}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{BEDB36B6-11BA-4306-AAAA-36FDF2060A3B}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{C168DF99-A8CA-4F98-B835-79C250039713}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C28385EF-BA3C-49D4-9AE5-A848D0301DD6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C34B5637-452B-417C-A294-AB7B7E1F78EE}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CD3D7DE0-2D07-4FAE-923A-8B7111238E6B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D573C6B9-045B-49B1-8460-5976616E8BF0}" = lport=137 | protocol=17 | dir=in | app=system |
"{E72921DF-58B0-43D1-A327-CE08271DF8AA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{EC54F4AD-227B-478A-B2E2-39F1920BADAF}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{EF44DBFE-4751-4B11-8C9D-46A8867EAD09}" = rport=139 | protocol=6 | dir=out | app=system |
"{F5507CE4-0F05-44FF-AE62-85B2EEF36882}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FC42B436-BBE1-4AB4-8E74-C0CE07D0C765}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{040ED978-B5B2-44B8-B739-6558D702F76E}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{09203817-354E-46FC-AC2E-ED47FC77A028}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{101A3AA6-29BC-4D3B-B4A1-F3BB8342FB9C}" = protocol=6 | dir=in | app=c:\program files\pazera toolbar\toolbarupdate.exe |
"{1051D100-B383-44BD-99D0-4FA20A2F4294}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{11318AFC-8099-4A59-AA38-6969437E453D}" = protocol=17 | dir=in | app=c:\program files\pazera toolbar\toolbarupdate.exe |
"{163C1C3E-F92F-45E4-A428-03F714FCA808}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{1F0A8761-9F26-4130-A3C1-CF0B5BC999A1}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{2506C2D2-45FF-4CA2-8366-0321ABC28352}" = protocol=6 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{2906AE94-D8AC-4672-9425-97BA6762F952}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{29EC4245-648B-4564-A624-89798A31FAE5}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{2B5F2F2E-FAB5-4000-9BC3-C3608C266B56}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2B71B8C5-8723-4C91-8404-8D469D254A46}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{2BE28BE1-BD68-427D-8308-A8985BB1B71B}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{318C8921-BACE-44BD-B13E-40E08E0B14E9}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{355DBE26-F5A8-4B1A-8BE3-DB9FC3018BAD}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{35CA311F-20ED-4562-A558-3DCC114A0F8F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{3905B407-FAA0-4D58-9990-8B93C9351264}" = protocol=6 | dir=out | app=system |
"{3A7CCB8A-4375-4E27-99AD-B41EA30932ED}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{4292D5F5-069D-478F-B1AB-70348B42C827}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{5028CAA2-2981-4039-B981-E3FEDDAC312E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{517ACF21-F4A5-48F1-88E4-6BBB2D8723D1}" = protocol=17 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{555E3503-BE8E-4524-839A-D796203BC07F}" = protocol=6 | dir=out | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{5A8125C7-BFF1-413D-B9AA-CC333D2D31CB}" = protocol=17 | dir=in | app=c:\program files\pazera toolbar\troubleshooter.exe |
"{5C99C0DF-5451-4052-98E7-A254C23E4661}" = protocol=6 | dir=in | app=c:\program files\iwin games\webupdater.exe |
"{63B39D41-2C5C-4D4A-903D-37B97DA8F1FC}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6A593194-161E-4E90-A980-E8952E2780B3}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6D31CFAB-426D-4B28-AD81-3346B59B405A}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{6E814D74-5A65-4554-8D32-05DDD43E3E65}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{76FE9928-103B-4226-8558-A3B1A17568F3}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{7A519F29-C8F0-40FA-8929-C06C235030C9}" = protocol=6 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{8BE93F1D-DD06-4FEE-8525-CA69DAD87F95}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{93930D0D-F6AD-4BE1-B235-D5EC49D331DA}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{94630CCA-A46F-41E7-9574-424938ED5DF2}" = protocol=17 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{96C7EAAF-4AEE-489B-B805-87B737B22979}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{9C9C9383-C85C-4A79-BCDA-F505ABC1ACAB}" = protocol=17 | dir=in | app=c:\program files\iwin games\iwingames.exe |
"{A97D5FB6-C4DB-457B-B20E-F6A04B618E8C}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{AA1FDC16-A1FE-49A9-ABA8-62F6959B79D7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AB1C0BE0-3638-4BC3-B0F8-0DA829EF9E25}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{AB7F5A79-9936-4D56-A8B6-0438726040CB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{AC355751-EFF3-4BCD-91B9-29075C976AB6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{ACD7E04A-D3A9-4026-9719-99AE342AD071}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{B0C263FB-75E6-4A15-80C8-6A3666F6BF58}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD3D4A6E-CED3-4EB4-A05E-1A30054190B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BE4B0799-F385-435E-BA01-5EA649D13B85}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{C1BC1FFA-45B1-41B7-B768-53777DDAF9CA}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{C24E5B05-2AC3-49B2-8A6D-738511F74544}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{C95C6F4D-A000-4470-B48B-2EBB7707975D}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{CB5B4EE4-F1E2-4FC6-9B40-F26EBEF8C1A4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D150DF88-1924-4732-9684-1198A5DED8D0}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{D598B05B-81C6-421B-B719-B33AE5F52FEE}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{D80830B4-D3D5-4447-8F89-02C94FC76A4D}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{D82300B3-C39D-4D87-831A-751ED1026570}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{DA2F5892-5CB9-4DFF-B5CC-A500398E5164}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{DABFC7BC-6E17-49F1-AB3E-5E2F787D44FA}" = protocol=6 | dir=in | app=c:\program files\pazera toolbar\troubleshooter.exe |
"{DAF56F22-EFD7-469A-8E0F-0745A6BE2F71}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{E55496F5-16B6-43BF-B200-518E44786044}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E7EDBC97-FA1E-4A5B-86E1-AF55216001BB}" = protocol=6 | dir=in | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{F55BDD11-6851-4B86-B1F6-1B17D9F8F0AA}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{F8C5CFD1-CC55-4D94-A38A-47B155943286}" = protocol=6 | dir=out | app=system |
"{F97927DF-7D9B-44F1-A189-573F4508728E}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{FBBED9FE-9F9F-4197-A368-D119EABA6AFA}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{FE6433A9-CD36-43C5-9D08-9EB615877760}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{FE9DF07C-6418-445D-852C-031AF50A9393}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"TCP Query User{14C9FEC2-594E-48FA-BC5B-1536C3780117}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"TCP Query User{4856E0FC-C15D-440F-AEE1-BE7FD03CEE38}C:\program files\nch swift sound\talk\talk.exe" = protocol=6 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"TCP Query User{49B8C274-9170-41B5-BBCD-33C461D5A38F}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"TCP Query User{52E27ADD-BF2C-4340-A0C4-80D23F0688E9}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{57533EDB-DB87-41E8-9790-44E742B01FEE}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{676BA86A-FF84-4627-9007-349B61F5F2C3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{82A9A12A-3113-41B8-AE57-769B4A78528A}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{8F613C3E-F96B-4262-A578-9B1CC5E6A92B}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{9A60AC5D-06AF-43DE-8CA6-4BA5C3C954DB}C:\program files\nch swift sound\talk\talk.exe" = protocol=6 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"TCP Query User{A76625DA-3212-4271-8868-568D92E7EFB7}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{D94E60D0-C1A7-4727-9EDA-32E05AE6E13F}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{E1D7A377-FE87-49ED-B2B9-3BA0F519807A}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F599A68B-E118-4103-BFB3-D515863D4CF8}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{0BC2D0B6-3780-4765-A9EA-EDD1D77B2FDF}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{1F100206-6D15-4C20-9FEE-C5AC40512394}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"UDP Query User{3C19332F-4622-4013-94D5-EB69FF7A1AA6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{6491FCED-1DDB-4093-8F7B-F5D9263959C9}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7AE896A1-8307-427A-BCE8-F701425C5DBA}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{97846F5D-7A5F-4135-B588-F31A59381A00}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{ADF65486-37B3-4FB4-8BD8-D7E8130626E0}C:\users\michelle\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\michelle\appdata\local\mediaget2\mediaget.exe |
"UDP Query User{CE7F4610-7BC5-439D-8850-397A21576F94}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{D5AFEB82-D3F9-4549-8A60-1CA47DA7C418}C:\program files\nch swift sound\talk\talk.exe" = protocol=17 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"UDP Query User{D83B3157-49B0-4EAE-8BA7-2430E703A8F4}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{DD1E92D3-0E80-46D2-9773-7F8D2711B3F3}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{F388ED51-02E6-4300-AEB5-BDD4B4956643}C:\program files\nch swift sound\talk\talk.exe" = protocol=17 | dir=in | app=c:\program files\nch swift sound\talk\talk.exe |
"UDP Query User{F90B1FC2-6110-4416-A075-C8F86BB75975}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{053C30EA-D4C6-47A0-8537-8D231D9BE873}" = DELL0703
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22443966-38F8-8A4D-AA16-0FBFA246881F}" = Acrobat.com
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C4B0182-8B51-46A1-89A3-FC16CA885688}" = Force ASPI GUI
"{2E661193-B28F-4D59-A534-9E0D294B39F8}" = DVD Copy Plus
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{32C74893-0243-4235-A6F3-201F0E5D2C03}" = Print2PDF
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1" = System Checkup 3.0
"{4B719A70-F14A-4f5c-90B5-346B24B7FFF1}" = Windows 7 Upgrade Advisor
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-dell" = WildTangent Games App (Dell Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7B08D306-7266-4647-A926-2F78817ED1E0}" = Microsoft Corporation
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC2BA148-EE9C-4F1A-AFCE-F38C2C71D29B}" = Mobile Broadband Generic Drivers
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}" = Microsoft LifeCam
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}" = Windows Vista Upgrade Advisor
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.22beta
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Aqua Bubble 2_is1" = Aqua Bubble 2
"avast" = avast! Free Antivirus
"Best Game Hits 3" = Best Games Hits 3
"BFG-Brain Training for Dummies" = Brain Training for Dummies
"BFGC" = Big Fish Games: Game Manager
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"CardWorks" = CardWorks Business Card Software
"ClassicCard" = Parker Brothers Classic Card Games
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Dock" = Dell Dock
"DivX Setup.divx.com" = DivX Setup
"DVD Flick_is1" = DVD Flick [removed]
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ExpressBurn" = Express Burn Disc Burning Software
"FLAC" = FLAC 1.2.1b (remove only)
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.1
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"HDMI" = Intel® Graphics Media Accelerator Driver
"Info Center_is1" = Info Center 1.0.0.7
"iWinArcade" = iWin Games (remove only)
"Jewel Quest Mysteries: The Seventh Gate Collector's Edition" = Jewel Quest Mysteries: The Seventh Gate Collector's Edition (remove only)
"Jewel Quest Solitaire II" = Jewel Quest Solitaire II (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"My Lockbox_is1" = My Lockbox 2.1
"PhotoPad" = PhotoPad Image Editor
"RegCure" = RegCure
"RegistryCleaner" = Registry Cleaner 2.1
"ST6UNST #1" = Jomrati
"TaxACT 2009" = TaxACT 2009
"TVWiz" = Intel® TV Wizard
"Veer® Images add-in" = Veer® Images add-in
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 5.9.4
"Zuma's Revenge!" = Zuma's Revenge!
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"f031ef6ac137efc5" = Dell Driver Download Manager - 1
"MediaGet" = MediaGet
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Thank you in advance for your advice/assistance…Michelle.