dpan
Topic Starter
It appears there are multiple versions of svchost.exe running and Norton 360 reports on occasion high memory usage by this process
Here are the text files:
OTL logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS
Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Duane\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Uniblue\RegistryBooster\locale\en\en.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (N360) – C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVENG.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120112.002\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111223.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 89 D0 EB AE BA CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 06 90 AC 10 51 77 11 41 BB D5 A9 4C 86 3C 2E B1 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/12/30 17:36:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/01/05 08:40:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_4_3 [2012/01/13 11:39:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2012/01/13 07:29:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/18 08:32:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:43:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/12/14 17:28:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2010/05/10 09:55:35 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B0BDAFF-C44F-439D-8D11-2E15C3F35CB7}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/13 12:19:08 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:18:55 | 000,000,000 | -H-D | C] – C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2012/01/13 12:18:09 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\PackageAware
[2012/01/13 07:01:43 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Adobe
[2012/01/11 18:44:42 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\NPE
[2012/01/11 11:12:48 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\shannon pics
[2012/01/11 06:14:40 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2012/01/11 06:14:31 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/01/11 06:14:27 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/01/11 06:14:16 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/01/11 06:14:15 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/01/09 00:08:32 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\ceiva
[2012/01/05 08:26:09 | 000,000,000 | —D | C] – C:\bf6cf6c4002208f661226346e13c06b4
[2012/01/01 23:00:11 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\CrashDumps
[2012/01/01 22:37:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/01 22:34:59 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/01/01 22:34:32 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/01/01 22:16:27 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/01/01 22:10:11 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/01/01 22:09:55 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/01 17:12:09 | 000,331,384 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symtdiv.sys
[2012/01/01 17:12:09 | 000,296,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symnets.sys
[2012/01/01 17:12:08 | 000,744,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.sys
[2012/01/01 17:12:08 | 000,516,216 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.sys
[2012/01/01 17:12:08 | 000,340,088 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.sys
[2012/01/01 17:12:08 | 000,136,312 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\Ironx86.sys
[2012/01/01 17:12:08 | 000,050,168 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.sys
[2012/01/01 17:11:39 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360\0501000.01D
[2012/01/01 15:14:16 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2012/01/01 15:12:38 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/12/30 22:26:39 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics 2
[2011/12/30 21:56:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\eds pics
[2011/12/30 10:21:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics
[2011/12/30 09:56:01 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\michaels pics
[2011/12/27 21:21:09 | 000,000,000 | —D | C] – C:\Users\Duane\Documents\Symantec
[2011/12/27 21:15:53 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2011/12/27 21:15:45 | 000,126,584 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/12/27 21:14:36 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360
[2011/12/27 21:14:32 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2011/12/27 21:14:32 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/12/27 19:27:11 | 000,114,688 | —- | C] (RICOH) – C:\Windows\System32\RicohMediadriverVer.dll
[2011/12/27 19:27:10 | 000,090,112 | —- | C] (Sony Corporation) – C:\Windows\System32\snymsico.dll
[2011/12/27 19:27:10 | 000,048,128 | —- | C] (REDC) – C:\Windows\System32\drivers\rimmptsk.sys
[2011/12/27 19:27:10 | 000,044,544 | —- | C] (REDC) – C:\Windows\System32\drivers\rimsptsk.sys
[2011/12/27 19:27:10 | 000,038,400 | —- | C] (REDC) – C:\Windows\System32\drivers\rixdptsk.sys
[2011/12/27 19:27:09 | 000,172,032 | —- | C] (Ricoh Company,Ltd) – C:\Windows\System32\rixdicon.dll
[2011/12/27 18:51:26 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\ElevatedDiagnostics
[2011/12/27 17:58:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/12/27 17:58:22 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/12/19 08:42:19 | 001,393,736 | —- | C] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:35:30 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Google
[2011/12/14 20:31:16 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/14 20:30:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Apps
[2011/12/14 20:30:22 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Deployment
[2011/12/14 19:29:24 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 17:29:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/14 17:28:03 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/12/14 16:58:08 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 16:58:07 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 16:58:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/12/14 16:58:04 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/12/14 16:58:04 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/12/14 16:58:04 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/12/14 16:57:54 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 16:57:00 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 16:56:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 16:56:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/14 16:56:21 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/12/14 16:56:21 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
========== Files - Modified Within 30 Days ==========
[2012/01/13 12:36:02 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | M] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 11:42:08 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.001
[2012/01/13 11:41:42 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:22 | 000,371,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/13 11:39:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2012/01/13 07:53:10 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/12 19:53:56 | 000,001,726 | -H– | M] () – C:\Users\Duane\Documents\Default.rdp
[2012/01/12 11:51:18 | 244,283,466 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/01/11 20:55:22 | 000,116,527 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/11 19:02:34 | 002,262,806 | —- | M] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/11 13:58:28 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.dat
[2012/01/09 19:10:59 | 000,607,406 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/09 19:10:59 | 000,105,014 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/09 00:14:14 | 000,007,168 | —- | M] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 12:51:02 | 002,256,051 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/08 10:50:46 | 000,880,042 | —- | M] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 10:50:46 | 000,827,589 | —- | M] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 10:50:46 | 000,637,889 | —- | M] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/02 01:01:22 | 000,001,356 | —- | M] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2012/01/01 22:37:23 | 000,001,624 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:18:27 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/01/01 17:13:01 | 000,126,584 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2012/01/01 17:13:01 | 000,007,468 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2012/01/01 17:13:01 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2012/01/01 13:01:01 | 000,001,940 | —- | M] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/26 11:05:42 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/19 08:42:23 | 001,393,736 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:06:45 | 000,000,903 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:46 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/12/14 19:29:46 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/12/14 19:29:24 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:29:22 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 19:19:11 | 000,000,206 | —- | M] () – C:\Windows\System32\MRT.INI
========== Files Created - No Company Name ==========
[2012/01/13 12:19:13 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | C] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 07:53:09 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 20:55:21 | 000,116,527 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/08 12:51:32 | 000,880,042 | —- | C] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 12:51:32 | 000,827,589 | —- | C] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 12:51:32 | 000,637,889 | —- | C] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/08 12:51:01 | 002,256,051 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/01 22:37:22 | 000,001,624 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:17:03 | 002,262,806 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/01 17:12:09 | 000,000,000 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.cat
[2012/01/01 17:11:42 | 000,003,373 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.inf
[2012/01/01 17:11:42 | 000,002,792 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.inf
[2012/01/01 17:11:42 | 000,001,474 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNetV.inf
[2012/01/01 17:11:42 | 000,001,446 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.inf
[2012/01/01 17:11:42 | 000,001,389 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.inf
[2012/01/01 17:11:42 | 000,001,383 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.inf
[2012/01/01 17:11:42 | 000,000,742 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Iron.inf
[2012/01/01 17:11:39 | 000,007,877 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\symnetv.cat
[2012/01/01 17:11:39 | 000,007,528 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\iron.cat
[2012/01/01 17:11:39 | 000,007,458 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.cat
[2012/01/01 17:11:39 | 000,007,456 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.cat
[2012/01/01 17:11:39 | 000,007,454 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.cat
[2012/01/01 17:11:39 | 000,007,450 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.cat
[2012/01/01 17:11:39 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\isolate.ini
[2011/12/30 09:57:21 | 000,007,168 | —- | C] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/28 00:05:46 | 000,001,940 | —- | C] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/27 21:15:45 | 000,007,468 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/12/27 21:15:45 | 000,000,806 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/12/27 21:15:13 | 000,002,100 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/14 20:31:45 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/14 20:31:41 | 000,000,880 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/14 20:06:45 | 000,000,903 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:22 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:19:11 | 000,000,206 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/09/16 18:58:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/09/12 15:39:41 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/12 15:39:40 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/11 08:56:35 | 000,001,356 | —- | C] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2010/01/24 17:38:13 | 000,420,405 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/01/24 17:38:13 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/01/24 17:15:45 | 000,238,023 | —- | C] () – C:\Windows\hpoins21.dat
[2010/01/24 17:15:45 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat
[2010/01/07 18:47:45 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/01 15:01:46 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2009/12/31 13:32:11 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/12/30 12:21:29 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/12/19 20:46:27 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.001
[2009/12/19 20:46:25 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2006/11/02 06:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:37 | 000,371,864 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:33:01 | 000,607,406 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,105,014 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 16:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
========== LOP Check ==========
[2010/09/18 08:40:59 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Canon
[2012/01/13 12:19:08 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2012/01/13 11:37:07 | 000,032,598 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/12/19 19:48:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2010/01/11 15:25:16 | 000,000,349 | -H– | M] () – C:\IPH.PH
[2012/01/13 11:38:54 | 1386,082,304 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/09/17 19:03:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/21 23:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD91.DLL
[2007/05/21 23:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP91.DLL
[2008/01/18 22:34:30 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/09/12 13:47:14 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/29 11:46:46 | 000,000,547 | -HS- | M] () – C:\Users\Duane\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/18 06:54:45 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Duane\Desktop\ATF-Cleaner.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-12 01:12:46
< End of report >
OTL Extras logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS
Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.bat [@ = batfile] – Reg Error: Key error. File not found
.cmd [@ = cmdfile] – Reg Error: Key error. File not found
.com [@ = comfile] – Reg Error: Key error. File not found
.exe [@ = exefile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1BE1AF03-D816-4807-98AC-2DB11D6B93CA}" = rport=137 | protocol=17 | dir=out | app=system |
"{21302A75-EDDC-4E8B-B910-CB2A4B1AEDF8}" = lport=138 | protocol=17 | dir=in | app=system |
"{21E7897C-3043-4708-A1D6-90AB5D565EEE}" = lport=139 | protocol=6 | dir=in | app=system |
"{2EE996EF-9717-44A6-A8BD-1CC2CBF48326}" = rport=138 | protocol=17 | dir=out | app=system |
"{2EF90D85-5B86-4F80-B415-82FD636C96C2}" = lport=137 | protocol=17 | dir=in | app=system |
"{44AFB042-5C3F-4E6F-A6A9-98219D8A6A64}" = rport=139 | protocol=6 | dir=out | app=system |
"{4822F8A4-EA13-49C5-AB09-7135D0AA76F5}" = lport=445 | protocol=6 | dir=in | app=system |
"{64C990DD-F2CB-4F9D-90A5-E3C85EA0239B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{6E49CEF3-185B-4FA1-9AFA-A7378567C46F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{E6DD69B4-C281-4AA0-877F-334AF7D380A2}" = rport=445 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D14F5BA-63C8-4701-93AC-1824F01C9B31}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{14AC5A94-7BD9-429E-BFB7-6CED04AAAFD1}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{305CED5F-4C7F-4475-A5F2-ADAB5DEB8244}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{7A6325AF-4DDC-4DB1-AD9B-C6A45143BC64}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7B49D2B3-8EEC-4086-995C-AA01967EC590}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{8A22F7FF-CDF1-44E6-8ED8-DA22CD021E86}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{989B7E54-EB26-43ED-9FF6-043E5209AC29}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{9DCC21E5-FB96-445E-AE92-DE6A826FA955}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{AD0C7DEC-0370-458C-ABCC-87997330D087}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B34AC80C-C2EB-4668-9A61-CDAAFF1C4008}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{EC001DD3-6049-42FB-9AE4-ADE79A28D80E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"TCP Query User{5F8F37A1-98AC-4CB5-8137-0577B0443573}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{9282021A-FEE3-41C8-BF9C-CAE8ECF1F877}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=6 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{90F25616-32BE-4B18-AF45-CBC0976DC472}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=17 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{DAEBDEDC-1899-4B2F-8DFB-13BC7F43DC4A}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series" = Canon MP970 series
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 30
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.7
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5CC2EF8-20A4-4366-A681-3FE849E65809}" = RICOH Media Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Canon MP970 series User Registration" = Canon MP970 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.7.3.1894
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WinLiveSuite" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9782
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9782
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10796
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10796
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11794
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11794
Error - 3/26/2011 1:15:05 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ Media Center Events ]
Error - 11/1/2010 9:45:58 PM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 6/19/2011 2:01:28 AM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.
[ System Events ]
Error - 1/2/2012 2:44:42 PM | Computer Name = ShannonOConner | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.105 for the Network Card with network
address 001A73143DA0 has been denied by the DHCP server 192.168.10.1 (The DHCP
Server sent a DHCPNACK message).
Error - 1/5/2012 10:40:36 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:35:39 AM on 1/5/2012 was unexpected.
Error - 1/5/2012 8:53:38 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/10/2012 8:53:02 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:31:48 PM on 1/9/2012 was unexpected.
Error - 1/10/2012 2:28:46 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/11/2012 12:59:02 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7031
Description =
Error - 1/11/2012 1:26:16 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:23:38 AM on 1/11/2012 was unexpected.
Error - 1/11/2012 8:29:31 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/12/2012 1:51:55 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:49:19 AM on 1/12/2012 was unexpected.
Error - 1/12/2012 8:32:59 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:50:42 PM, on 1/13/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 8795 bytes
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 13:53:20.76 on Fri 01/13/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1022.153 [GMT -6:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2012-1-1 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2012-1-1 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111223.001\BHDrvx86.sys [2011-11-30 820344]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20120112.002\IDSvix86.sys [2012-1-12 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2012-1-1 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2012-1-1 331384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-9-12 21504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-27 106104]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-9-12 20464]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2006-12-18 43904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
.
=============== Created Last 30 ================
.
2012-01-13 18:19:08 ——– d—–w- c:\users\duane\appdata\roaming\Uniblue
2012-01-13 18:18:55 ——– dc-h–w- c:\progra~2\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2012-01-13 18:18:54 ——– d—–w- c:\program files\Uniblue
2012-01-13 18:18:09 ——– d—–w- c:\users\duane\appdata\local\PackageAware
2012-01-13 13:01:43 ——– d—–w- c:\users\duane\appdata\local\Adobe
2012-01-12 01:04:31 9728 —-a-w- c:\windows\system32\lsass.exe
2012-01-12 01:04:31 72704 —-a-w- c:\windows\system32\secur32.dll
2012-01-12 01:04:31 440192 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 01:04:31 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-01-12 01:04:31 278528 —-a-w- c:\windows\system32\schannel.dll
2012-01-12 01:04:31 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-01-12 00:44:42 ——– d—–w- c:\users\duane\appdata\local\NPE
2012-01-11 12:14:40 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-01-11 12:14:40 189952 —-a-w- c:\windows\system32\winmm.dll
2012-01-11 12:14:36 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 12:14:31 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-11 12:14:27 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-11 12:14:21 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-01-11 12:14:16 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 12:14:15 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-05 14:26:09 ——– d—–w- C:\bf6cf6c4002208f661226346e13c06b4
2012-01-02 05:00:11 ——– d—–w- c:\users\duane\appdata\local\CrashDumps
2012-01-02 04:34:59 ——– d—–w- c:\program files\iPod
2012-01-02 04:34:32 ——– d—–w- c:\program files\iTunes
2012-01-02 04:16:27 ——– d—–w- c:\program files\Bonjour
2012-01-01 23:13:16 27888 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-01-01 23:12:09 331384 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys
2012-01-01 23:12:09 296568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2012-01-01 23:12:08 744568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys
2012-01-01 23:12:08 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2012-01-01 23:12:08 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2012-01-01 23:12:08 340088 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys
2012-01-01 23:12:08 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys
2012-01-01 23:11:39 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D
2012-01-01 21:12:38 ——– d—–w- c:\program files\HP
2011-12-28 03:15:53 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2011-12-28 03:15:45 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-28 03:15:35 ——– d—–w- c:\program files\Symantec
2011-12-28 03:15:35 ——– d—–w- c:\program files\common files\Symantec Shared
2011-12-28 03:14:36 ——– d—–w- c:\windows\system32\drivers\N360
2011-12-28 03:14:32 ——– d—–w- c:\program files\Norton 360
2011-12-28 03:14:18 ——– d—–w- c:\program files\NortonInstaller
2011-12-28 03:14:18 ——– d—–w- c:\progra~2\NortonInstaller
2011-12-28 01:27:11 114688 —-a-w- c:\windows\system32\RicohMediadriverVer.dll
2011-12-28 01:27:10 90112 —-a-w- c:\windows\system32\snymsico.dll
2011-12-28 01:27:10 48128 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2011-12-28 01:27:10 44544 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2011-12-28 01:27:10 38400 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2011-12-28 01:27:09 172032 —-a-w- c:\windows\system32\rixdicon.dll
2011-12-28 00:51:26 ——– d—–w- c:\users\duane\appdata\local\ElevatedDiagnostics
2011-12-27 23:58:22 ——– d—–w- c:\progra~2\Norton
2011-12-27 21:22:10 6823496 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{7579a660-a0ec-4a5b-8cc3-67ad7ce68772}\mpengine.dll
2011-12-19 14:42:19 1393736 —-a-w- c:\users\duane\gotomypc_626.exe
2011-12-17 00:01:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-15 02:30:23 ——– d—–w- c:\users\duane\appdata\local\Apps
2011-12-15 02:30:22 ——– d—–w- c:\users\duane\appdata\local\Deployment
2011-12-14 22:58:08 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 22:58:07 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 22:58:04 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-12-14 22:58:04 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-12-14 22:58:04 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-12-14 22:58:04 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-12-14 22:57:57 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-12-14 22:57:56 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-12-14 22:57:56 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-12-14 22:57:54 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 22:57:53 6144 —-a-w- c:\program files\internet explorer\iecompat.dll
2011-12-14 22:57:24 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-14 22:57:00 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 22:56:54 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-14 22:56:47 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-14 22:56:21 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-12-14 22:56:21 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-12-14 22:56:21 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-12-14 22:56:21 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-12-14 22:54:25 707584 —-a-w- c:\program files\common files\system\wab32.dll
.
==================== Find3M ====================
.
2011-11-15 20:29:56 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-10 11:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 13:58:59.50 ===============
Here are the text files:
OTL logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS
Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Duane\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Uniblue\RegistryBooster\locale\en\en.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (N360) – C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVENG.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120112.002\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111223.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 89 D0 EB AE BA CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 06 90 AC 10 51 77 11 41 BB D5 A9 4C 86 3C 2E B1 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/12/30 17:36:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/01/05 08:40:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_4_3 [2012/01/13 11:39:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2012/01/13 07:29:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/18 08:32:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:43:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/12/14 17:28:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2010/05/10 09:55:35 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B0BDAFF-C44F-439D-8D11-2E15C3F35CB7}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/13 12:19:08 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:18:55 | 000,000,000 | -H-D | C] – C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2012/01/13 12:18:09 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\PackageAware
[2012/01/13 07:01:43 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Adobe
[2012/01/11 18:44:42 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\NPE
[2012/01/11 11:12:48 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\shannon pics
[2012/01/11 06:14:40 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2012/01/11 06:14:31 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/01/11 06:14:27 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/01/11 06:14:16 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/01/11 06:14:15 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/01/09 00:08:32 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\ceiva
[2012/01/05 08:26:09 | 000,000,000 | —D | C] – C:\bf6cf6c4002208f661226346e13c06b4
[2012/01/01 23:00:11 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\CrashDumps
[2012/01/01 22:37:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/01 22:34:59 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/01/01 22:34:32 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/01/01 22:16:27 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/01/01 22:10:11 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/01/01 22:09:55 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/01 17:12:09 | 000,331,384 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symtdiv.sys
[2012/01/01 17:12:09 | 000,296,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symnets.sys
[2012/01/01 17:12:08 | 000,744,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.sys
[2012/01/01 17:12:08 | 000,516,216 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.sys
[2012/01/01 17:12:08 | 000,340,088 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.sys
[2012/01/01 17:12:08 | 000,136,312 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\Ironx86.sys
[2012/01/01 17:12:08 | 000,050,168 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.sys
[2012/01/01 17:11:39 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360\0501000.01D
[2012/01/01 15:14:16 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2012/01/01 15:12:38 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/12/30 22:26:39 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics 2
[2011/12/30 21:56:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\eds pics
[2011/12/30 10:21:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics
[2011/12/30 09:56:01 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\michaels pics
[2011/12/27 21:21:09 | 000,000,000 | —D | C] – C:\Users\Duane\Documents\Symantec
[2011/12/27 21:15:53 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2011/12/27 21:15:45 | 000,126,584 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/12/27 21:14:36 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360
[2011/12/27 21:14:32 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2011/12/27 21:14:32 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/12/27 19:27:11 | 000,114,688 | —- | C] (RICOH) – C:\Windows\System32\RicohMediadriverVer.dll
[2011/12/27 19:27:10 | 000,090,112 | —- | C] (Sony Corporation) – C:\Windows\System32\snymsico.dll
[2011/12/27 19:27:10 | 000,048,128 | —- | C] (REDC) – C:\Windows\System32\drivers\rimmptsk.sys
[2011/12/27 19:27:10 | 000,044,544 | —- | C] (REDC) – C:\Windows\System32\drivers\rimsptsk.sys
[2011/12/27 19:27:10 | 000,038,400 | —- | C] (REDC) – C:\Windows\System32\drivers\rixdptsk.sys
[2011/12/27 19:27:09 | 000,172,032 | —- | C] (Ricoh Company,Ltd) – C:\Windows\System32\rixdicon.dll
[2011/12/27 18:51:26 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\ElevatedDiagnostics
[2011/12/27 17:58:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/12/27 17:58:22 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/12/19 08:42:19 | 001,393,736 | —- | C] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:35:30 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Google
[2011/12/14 20:31:16 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/14 20:30:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Apps
[2011/12/14 20:30:22 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Deployment
[2011/12/14 19:29:24 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 17:29:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/14 17:28:03 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/12/14 16:58:08 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 16:58:07 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 16:58:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/12/14 16:58:04 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/12/14 16:58:04 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/12/14 16:58:04 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/12/14 16:57:54 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 16:57:00 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 16:56:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 16:56:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/14 16:56:21 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/12/14 16:56:21 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
========== Files - Modified Within 30 Days ==========
[2012/01/13 12:36:02 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | M] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 11:42:08 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.001
[2012/01/13 11:41:42 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:22 | 000,371,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/13 11:39:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2012/01/13 07:53:10 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/12 19:53:56 | 000,001,726 | -H– | M] () – C:\Users\Duane\Documents\Default.rdp
[2012/01/12 11:51:18 | 244,283,466 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/01/11 20:55:22 | 000,116,527 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/11 19:02:34 | 002,262,806 | —- | M] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/11 13:58:28 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.dat
[2012/01/09 19:10:59 | 000,607,406 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/09 19:10:59 | 000,105,014 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/09 00:14:14 | 000,007,168 | —- | M] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 12:51:02 | 002,256,051 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/08 10:50:46 | 000,880,042 | —- | M] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 10:50:46 | 000,827,589 | —- | M] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 10:50:46 | 000,637,889 | —- | M] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/02 01:01:22 | 000,001,356 | —- | M] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2012/01/01 22:37:23 | 000,001,624 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:18:27 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/01/01 17:13:01 | 000,126,584 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2012/01/01 17:13:01 | 000,007,468 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2012/01/01 17:13:01 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2012/01/01 13:01:01 | 000,001,940 | —- | M] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/26 11:05:42 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/19 08:42:23 | 001,393,736 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:06:45 | 000,000,903 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:46 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/12/14 19:29:46 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/12/14 19:29:24 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:29:22 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 19:19:11 | 000,000,206 | —- | M] () – C:\Windows\System32\MRT.INI
========== Files Created - No Company Name ==========
[2012/01/13 12:19:13 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | C] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 07:53:09 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 20:55:21 | 000,116,527 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/08 12:51:32 | 000,880,042 | —- | C] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 12:51:32 | 000,827,589 | —- | C] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 12:51:32 | 000,637,889 | —- | C] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/08 12:51:01 | 002,256,051 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/01 22:37:22 | 000,001,624 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:17:03 | 002,262,806 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/01 17:12:09 | 000,000,000 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.cat
[2012/01/01 17:11:42 | 000,003,373 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.inf
[2012/01/01 17:11:42 | 000,002,792 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.inf
[2012/01/01 17:11:42 | 000,001,474 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNetV.inf
[2012/01/01 17:11:42 | 000,001,446 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.inf
[2012/01/01 17:11:42 | 000,001,389 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.inf
[2012/01/01 17:11:42 | 000,001,383 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.inf
[2012/01/01 17:11:42 | 000,000,742 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Iron.inf
[2012/01/01 17:11:39 | 000,007,877 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\symnetv.cat
[2012/01/01 17:11:39 | 000,007,528 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\iron.cat
[2012/01/01 17:11:39 | 000,007,458 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.cat
[2012/01/01 17:11:39 | 000,007,456 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.cat
[2012/01/01 17:11:39 | 000,007,454 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.cat
[2012/01/01 17:11:39 | 000,007,450 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.cat
[2012/01/01 17:11:39 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\isolate.ini
[2011/12/30 09:57:21 | 000,007,168 | —- | C] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/28 00:05:46 | 000,001,940 | —- | C] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/27 21:15:45 | 000,007,468 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/12/27 21:15:45 | 000,000,806 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/12/27 21:15:13 | 000,002,100 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/14 20:31:45 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/14 20:31:41 | 000,000,880 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/14 20:06:45 | 000,000,903 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:22 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:19:11 | 000,000,206 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/09/16 18:58:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/09/12 15:39:41 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/12 15:39:40 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/11 08:56:35 | 000,001,356 | —- | C] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2010/01/24 17:38:13 | 000,420,405 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/01/24 17:38:13 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/01/24 17:15:45 | 000,238,023 | —- | C] () – C:\Windows\hpoins21.dat
[2010/01/24 17:15:45 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat
[2010/01/07 18:47:45 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/01 15:01:46 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2009/12/31 13:32:11 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/12/30 12:21:29 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/12/19 20:46:27 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.001
[2009/12/19 20:46:25 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2006/11/02 06:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:37 | 000,371,864 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:33:01 | 000,607,406 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,105,014 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 16:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
========== LOP Check ==========
[2010/09/18 08:40:59 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Canon
[2012/01/13 12:19:08 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2012/01/13 11:37:07 | 000,032,598 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/12/19 19:48:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2010/01/11 15:25:16 | 000,000,349 | -H– | M] () – C:\IPH.PH
[2012/01/13 11:38:54 | 1386,082,304 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/09/17 19:03:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/21 23:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD91.DLL
[2007/05/21 23:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP91.DLL
[2008/01/18 22:34:30 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/09/12 13:47:14 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/29 11:46:46 | 000,000,547 | -HS- | M] () – C:\Users\Duane\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/18 06:54:45 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Duane\Desktop\ATF-Cleaner.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-12 01:12:46
< End of report >
OTL Extras logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS
Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.bat [@ = batfile] – Reg Error: Key error. File not found
.cmd [@ = cmdfile] – Reg Error: Key error. File not found
.com [@ = comfile] – Reg Error: Key error. File not found
.exe [@ = exefile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1BE1AF03-D816-4807-98AC-2DB11D6B93CA}" = rport=137 | protocol=17 | dir=out | app=system |
"{21302A75-EDDC-4E8B-B910-CB2A4B1AEDF8}" = lport=138 | protocol=17 | dir=in | app=system |
"{21E7897C-3043-4708-A1D6-90AB5D565EEE}" = lport=139 | protocol=6 | dir=in | app=system |
"{2EE996EF-9717-44A6-A8BD-1CC2CBF48326}" = rport=138 | protocol=17 | dir=out | app=system |
"{2EF90D85-5B86-4F80-B415-82FD636C96C2}" = lport=137 | protocol=17 | dir=in | app=system |
"{44AFB042-5C3F-4E6F-A6A9-98219D8A6A64}" = rport=139 | protocol=6 | dir=out | app=system |
"{4822F8A4-EA13-49C5-AB09-7135D0AA76F5}" = lport=445 | protocol=6 | dir=in | app=system |
"{64C990DD-F2CB-4F9D-90A5-E3C85EA0239B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{6E49CEF3-185B-4FA1-9AFA-A7378567C46F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{E6DD69B4-C281-4AA0-877F-334AF7D380A2}" = rport=445 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D14F5BA-63C8-4701-93AC-1824F01C9B31}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{14AC5A94-7BD9-429E-BFB7-6CED04AAAFD1}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{305CED5F-4C7F-4475-A5F2-ADAB5DEB8244}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{7A6325AF-4DDC-4DB1-AD9B-C6A45143BC64}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7B49D2B3-8EEC-4086-995C-AA01967EC590}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{8A22F7FF-CDF1-44E6-8ED8-DA22CD021E86}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{989B7E54-EB26-43ED-9FF6-043E5209AC29}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{9DCC21E5-FB96-445E-AE92-DE6A826FA955}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{AD0C7DEC-0370-458C-ABCC-87997330D087}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B34AC80C-C2EB-4668-9A61-CDAAFF1C4008}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{EC001DD3-6049-42FB-9AE4-ADE79A28D80E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"TCP Query User{5F8F37A1-98AC-4CB5-8137-0577B0443573}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{9282021A-FEE3-41C8-BF9C-CAE8ECF1F877}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=6 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{90F25616-32BE-4B18-AF45-CBC0976DC472}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=17 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{DAEBDEDC-1899-4B2F-8DFB-13BC7F43DC4A}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series" = Canon MP970 series
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 30
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.7
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5CC2EF8-20A4-4366-A681-3FE849E65809}" = RICOH Media Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Canon MP970 series User Registration" = Canon MP970 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.7.3.1894
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WinLiveSuite" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9782
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9782
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10796
Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10796
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11794
Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11794
Error - 3/26/2011 1:15:05 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ Media Center Events ]
Error - 11/1/2010 9:45:58 PM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 6/19/2011 2:01:28 AM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.
[ System Events ]
Error - 1/2/2012 2:44:42 PM | Computer Name = ShannonOConner | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.105 for the Network Card with network
address 001A73143DA0 has been denied by the DHCP server 192.168.10.1 (The DHCP
Server sent a DHCPNACK message).
Error - 1/5/2012 10:40:36 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:35:39 AM on 1/5/2012 was unexpected.
Error - 1/5/2012 8:53:38 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/10/2012 8:53:02 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:31:48 PM on 1/9/2012 was unexpected.
Error - 1/10/2012 2:28:46 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/11/2012 12:59:02 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7031
Description =
Error - 1/11/2012 1:26:16 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:23:38 AM on 1/11/2012 was unexpected.
Error - 1/11/2012 8:29:31 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
Error - 1/12/2012 1:51:55 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:49:19 AM on 1/12/2012 was unexpected.
Error - 1/12/2012 8:32:59 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:50:42 PM, on 1/13/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 8795 bytes
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 13:53:20.76 on Fri 01/13/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1022.153 [GMT -6:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2012-1-1 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2012-1-1 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111223.001\BHDrvx86.sys [2011-11-30 820344]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20120112.002\IDSvix86.sys [2012-1-12 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2012-1-1 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2012-1-1 331384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-9-12 21504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-27 106104]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-9-12 20464]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2006-12-18 43904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
.
=============== Created Last 30 ================
.
2012-01-13 18:19:08 ——– d—–w- c:\users\duane\appdata\roaming\Uniblue
2012-01-13 18:18:55 ——– dc-h–w- c:\progra~2\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2012-01-13 18:18:54 ——– d—–w- c:\program files\Uniblue
2012-01-13 18:18:09 ——– d—–w- c:\users\duane\appdata\local\PackageAware
2012-01-13 13:01:43 ——– d—–w- c:\users\duane\appdata\local\Adobe
2012-01-12 01:04:31 9728 —-a-w- c:\windows\system32\lsass.exe
2012-01-12 01:04:31 72704 —-a-w- c:\windows\system32\secur32.dll
2012-01-12 01:04:31 440192 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 01:04:31 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-01-12 01:04:31 278528 —-a-w- c:\windows\system32\schannel.dll
2012-01-12 01:04:31 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-01-12 00:44:42 ——– d—–w- c:\users\duane\appdata\local\NPE
2012-01-11 12:14:40 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-01-11 12:14:40 189952 —-a-w- c:\windows\system32\winmm.dll
2012-01-11 12:14:36 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 12:14:31 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-11 12:14:27 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-11 12:14:21 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-01-11 12:14:16 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 12:14:15 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-05 14:26:09 ——– d—–w- C:\bf6cf6c4002208f661226346e13c06b4
2012-01-02 05:00:11 ——– d—–w- c:\users\duane\appdata\local\CrashDumps
2012-01-02 04:34:59 ——– d—–w- c:\program files\iPod
2012-01-02 04:34:32 ——– d—–w- c:\program files\iTunes
2012-01-02 04:16:27 ——– d—–w- c:\program files\Bonjour
2012-01-01 23:13:16 27888 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-01-01 23:12:09 331384 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys
2012-01-01 23:12:09 296568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2012-01-01 23:12:08 744568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys
2012-01-01 23:12:08 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2012-01-01 23:12:08 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2012-01-01 23:12:08 340088 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys
2012-01-01 23:12:08 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys
2012-01-01 23:11:39 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D
2012-01-01 21:12:38 ——– d—–w- c:\program files\HP
2011-12-28 03:15:53 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2011-12-28 03:15:45 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-28 03:15:35 ——– d—–w- c:\program files\Symantec
2011-12-28 03:15:35 ——– d—–w- c:\program files\common files\Symantec Shared
2011-12-28 03:14:36 ——– d—–w- c:\windows\system32\drivers\N360
2011-12-28 03:14:32 ——– d—–w- c:\program files\Norton 360
2011-12-28 03:14:18 ——– d—–w- c:\program files\NortonInstaller
2011-12-28 03:14:18 ——– d—–w- c:\progra~2\NortonInstaller
2011-12-28 01:27:11 114688 —-a-w- c:\windows\system32\RicohMediadriverVer.dll
2011-12-28 01:27:10 90112 —-a-w- c:\windows\system32\snymsico.dll
2011-12-28 01:27:10 48128 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2011-12-28 01:27:10 44544 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2011-12-28 01:27:10 38400 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2011-12-28 01:27:09 172032 —-a-w- c:\windows\system32\rixdicon.dll
2011-12-28 00:51:26 ——– d—–w- c:\users\duane\appdata\local\ElevatedDiagnostics
2011-12-27 23:58:22 ——– d—–w- c:\progra~2\Norton
2011-12-27 21:22:10 6823496 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{7579a660-a0ec-4a5b-8cc3-67ad7ce68772}\mpengine.dll
2011-12-19 14:42:19 1393736 —-a-w- c:\users\duane\gotomypc_626.exe
2011-12-17 00:01:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-15 02:30:23 ——– d—–w- c:\users\duane\appdata\local\Apps
2011-12-15 02:30:22 ——– d—–w- c:\users\duane\appdata\local\Deployment
2011-12-14 22:58:08 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 22:58:07 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 22:58:04 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-12-14 22:58:04 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-12-14 22:58:04 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-12-14 22:58:04 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-12-14 22:57:57 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-12-14 22:57:56 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-12-14 22:57:56 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-12-14 22:57:54 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 22:57:53 6144 —-a-w- c:\program files\internet explorer\iecompat.dll
2011-12-14 22:57:24 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-14 22:57:00 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 22:56:54 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-14 22:56:47 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-14 22:56:21 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-12-14 22:56:21 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-12-14 22:56:21 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-12-14 22:56:21 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-12-14 22:54:25 707584 —-a-w- c:\program files\common files\system\wab32.dll
.
==================== Find3M ====================
.
2011-11-15 20:29:56 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-10 11:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 13:58:59.50 ===============