ladyixnay
Topic Starter
My PC is starting up very slow and shutting down very slow, then drags some while in use. I am posting my OTL scan… My PC info under my member info to the left. thanks for the help.
OTL logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sprint\Sprint SmartView\SwiApiMuxCdma.exe (Sierra Wireless, Inc.)
PRC - C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
PRC - C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
PRC - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Sprint\Sprint SmartView\Pac.dll ()
MOD - C:\Program Files\Sprint\Sprint SmartView\Eap.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (SmithMicro Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (RMCAST) – C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys ()
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\EG1032xp.sys (Linksys, A Division of Cisco Systems, Inc )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Amy\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://amyost.homestead.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 25 EF 16 03 EF EA CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://amyost.homestead.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/02 11:35:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\MSBuild\Mozilla Firefox\components [2012/01/15 17:53:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\MSBuild\Mozilla Firefox\plugins [2011/09/15 05:30:24 | 000,000,000 | —D | M]
[2010/05/03 20:07:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Extensions
[2012/01/15 17:53:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions
[2012/01/15 17:53:54 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gears.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Amy\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Scorpion Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnlfhfpojmehjcdldbclpgfclmdodpin\1_0\
CHR - Extension: Mahjongg Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccklcogklfjbajdeimbknkplphkjbkhb\1_0\
CHR - Extension: Earthquake Alert = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceddfjkhemabgponojbabonhjpclgaja\0.4_0\
CHR - Extension: Solitaire Card Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp\1.0.0.2_0\
CHR - Extension: Super Mario = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnkjbdmdgifgkcenpllpepgcgllapgpm\1_0\
CHR - Extension: Solitairey = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp\2.2.4_0\
CHR - Extension: Games.com = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eciiciccngmnpknipagfcpdbpbejladh\0.0.0.3_0\
CHR - Extension: Namco Mahjong Butterfly = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdpljegkclkedmcmfpdfgomeoojlajaa\1.104_0\
CHR - Extension: World of Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn\1.0.1_0\
CHR - Extension: Farty mcFart = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijghjfglokjbecncjijjocbmcbbhgpkc\1.2_0\
CHR - Extension: HuffingtonPost NewsGlide = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjialelnkjdomiblmnpcpjongleegef\0.3.2_0\
CHR - Extension: Just Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcbhedoainjipdhgimhhajobmblbaopf\2.1_0\
CHR - Extension: Google Maps = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.3_0\
CHR - Extension: Word\u00B2 = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: US Cities = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbljbaeppeadkjipnapacpommhijhbel\1_0\
CHR - Extension: Google Books = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\0.0.0.6_0\
CHR - Extension: Word Scramble II = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnoadpilbdgjcffnbflkahalmfflpdh\1_0\
CHR - Extension: Typing Game = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mobfbeogeanchbdhboilncgnkfkibjjg\1.0.3.0_0\
CHR - Extension: Mahjong Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\neojceinbonpjjcokpokpeobkhcpiloc\1.0.0.1_0\
CHR - Extension: Demon Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhmiblkonfdnknhmhegmeddkmljlnjbd\1_0\
CHR - Extension: Heavy Jumble = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolnangifendohpjiagboafdlkfhbaml\1_0\
CHR - Extension: Puzzle Games from Big Fish Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\npolkgeaiepngllaancmiflhecgfdhnj\1.1_0\
CHR - Extension: Reversi = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhjkapjdlmmadkepnmlkpadnnnnoebm\0.0.0.3_0\
CHR - Extension: Draw My Thing = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odpjeimbfolekeldhfddmbemmpiffkch\1.0_0\
CHR - Extension: Mysteriez! = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\phhpkfchfjfeicikkkajdojpjkapdpnd\1.0.1_0\
CHR - Extension: Gmail = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/12/03 22:02:04 | 000,438,048 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15093 more lines…
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [RDVCHG] C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
O4 - HKLM..\Run: [Sprint SmartView] C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{28AB4157-57D1-4951-820D-BE2B23AC05C4}: NameServer = 68.28.137.132 68.28.138.132
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/17 00:10:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/16 13:50:06 | 000,000,000 | —D | C] – C:\ProgramData\RegCure
[2011/12/30 21:24:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
[2011/12/22 21:47:37 | 000,204,496 | —- | C] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
========== Files - Modified Within 30 Days ==========
[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/17 00:03:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/16 23:58:36 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:58:26 | 000,002,385 | —- | M] () – C:\Users\Amy\Desktop\Google Chrome.lnk
[2012/01/16 23:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:34:34 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/16 23:34:34 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/16 23:28:02 | 000,000,499 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2012/01/16 23:26:09 | 000,001,072 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/01/16 23:25:59 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/16 23:22:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2012/01/16 14:39:28 | 000,007,661 | —- | M] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2012/01/15 21:55:21 | 281,428,358 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
[2011/12/18 06:57:09 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
========== Files Created - No Company Name ==========
[2012/01/16 23:38:45 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:38:44 | 000,000,848 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/15 21:55:21 | 281,428,358 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/03 22:52:19 | 000,000,115 | —- | C] () – C:\Windows\wininit.ini
[2011/10/21 11:40:56 | 000,000,000 | —- | C] () – C:\Users\Amy\AppData\Local\{818FCAC6-A463-44AD-8B14-F719C1C3D1D7}
[2011/05/22 20:42:38 | 000,331,776 | —- | C] () – C:\Windows\System32\TwcToolbarIe7.dll
[2011/05/22 20:42:38 | 000,098,304 | —- | C] () – C:\Windows\System32\TwcToolbarBho.dll
[2011/05/20 01:28:24 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/05/20 01:26:33 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/04/14 17:03:40 | 000,003,565 | —- | C] () – C:\Windows\System32\RDDlg.dat
[2010/11/20 18:11:32 | 000,001,072 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/11/09 12:36:02 | 000,012,288 | —- | C] () – C:\Users\Amy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/22 14:31:43 | 000,000,035 | —- | C] () – C:\Windows\A5W.INI
[2010/07/22 11:48:30 | 000,007,661 | —- | C] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2010/06/08 15:36:06 | 000,037,248 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2009/07/13 23:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 000,268,184 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 18:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[1997/11/10 14:18:48 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
========== LOP Check ==========
[2010/11/05 20:52:18 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\acccore
[2010/10/20 05:18:40 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\AVG10
[2010/05/03 13:30:28 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Bytemobile
[2010/05/21 12:38:52 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Pogo Games
[2011/01/29 23:27:13 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\RegistryKeys
[2010/11/23 21:44:58 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sierra Wireless
[2010/11/23 21:55:14 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sprint
[2011/01/17 12:59:51 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\SystemRequirementsLab
[2010/05/03 19:52:29 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WeatherBug
[2010/08/07 20:35:26 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WinPatrol
[2010/06/23 23:24:42 | 000,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(58).TXT
[2011/12/12 06:34:59 | 000,032,616 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/02/10 06:00:11 | 000,229,148 | —- | M] () – C:\aaw7boot.log
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/02/11 14:09:42 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/05/03 16:58:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2010/05/03 16:58:47 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/02/01 18:41:06 | 000,011,187 | —- | M] () – C:\ComboFix.txt
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/06 15:57:53 | 000,000,006 | —- | M] () – C:\dialogInfo.res
[2011/05/18 22:57:10 | 007,643,508 | —- | M] () – C:\drivers.log
[2010/05/03 13:16:42 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/05 20:51:36 | 000,000,808 | -H– | M] () – C:\IPH.PH
[2010/05/01 09:13:14 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/06/18 20:36:23 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/18 20:36:23 | 000,250,032 | RHS- | M] () – C:\ntldr
[2012/01/16 23:22:36 | 2145,177,600 | -HS- | M] () – C:\pagefile.sys
[2009/06/18 20:54:22 | 000,000,575 | —- | M] () – C:\RHDSetup.log
[2009/06/19 02:06:53 | 000,000,005 | —- | M] () – C:\testfile.txt
[2010/05/03 13:16:43 | 000,000,000 | RHS- | M] () – C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 07:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2010/09/20 10:45:44 | 000,016,591 | —- | M] () – C:\Windows\system32\bg_bottom.jpg
[2011/04/11 15:37:04 | 000,023,992 | —- | M] () – C:\Windows\system32\bg_top.jpg
[2010/11/08 10:29:06 | 000,040,726 | —- | M] () – C:\Windows\system32\image_animation.jpg
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 13:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/11/23 19:48:34 | 000,001,654 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2011/04/26 11:45:20 | 000,058,368 | —- | M] () – C:\Windows\system32\Thumbs.db
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/20 05:57:02 | 000,000,221 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/25 17:49:02 | 000,229,672 | —- | M] () – C:\Users\Amy\Desktop\CrucialScan(1).exe
[2011/08/07 09:39:24 | 000,589,656 | —- | M] (Google Inc.) – C:\Users\Amy\Desktop\GoogleEarthPluginSetup.exe
[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-24 12:34:17
========== Alternate Data Streams ==========
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:D09AEE3D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:72F57408
< End of report >
OTL Extras logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile]
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe" = C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4647BF57-21C4-4BC8-BA1B-E57A30EE1D31}" = Sprint SmartView
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70DECFBF-9119-4434-B2D3-A3C283D15E45}" = WeatherBug
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112930333}" = Lottso! Deluxe
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4B1B985-F308-4DBA-BFD7-CCCB8839234B}" = HP Deskjet 1000 J110 series Basic Device Software
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AI RoboForm" = AI RoboForm (All Users)
"AIM_7" = AIM 7
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"DirectXMediaRuntime" = DirectX Media Runtime 5.1
"ESET Online Scanner" = ESET Online Scanner v3
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Merriam-Webster's Reference Library" = Merriam-Webster's Reference Library
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"SystemRequirementsLab" = System Requirements Lab
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"727d1ea1876aa06e" = WowAceUpdater
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/15/2012 10:53:32 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7042
Description =
Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 9002
Description =
Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 1/15/2012 10:53:39 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 1/15/2012 10:53:42 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 1/15/2012 8:51:18 PM | Computer Name = Amy-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 81c Start
Time: 01ccd3e861bf3210 Termination Time: 47 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 1/16/2012 11:46:09 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Sprint\Sprint
SmartView\OemDriverManager64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 1/16/2012 11:48:53 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
[ Media Center Events ]
Error - 5/21/2011 5:53:21 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:20 AM - Error connecting to the internet. 5:53:20 AM - Unable
to contact server..
Error - 5/21/2011 5:54:01 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:30 AM - Error connecting to the internet. 5:53:30 AM - Unable
to contact server..
Error - 5/23/2011 10:18:37 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:36 AM - Error connecting to the internet. 10:18:37 AM - Unable
to contact server..
Error - 5/23/2011 10:18:47 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:42 AM - Error connecting to the internet. 10:18:42 AM - Unable
to contact server..
Error - 5/31/2011 10:37:43 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:43 AM - Error connecting to the internet. 10:37:43 AM - Unable
to contact server..
Error - 5/31/2011 10:37:54 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:48 AM - Error connecting to the internet. 10:37:48 AM - Unable
to contact server..
Error - 6/3/2011 10:38:23 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:23 AM - Error connecting to the internet. 10:38:23 AM - Unable
to contact server..
Error - 6/3/2011 10:38:41 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:28 AM - Error connecting to the internet. 10:38:28 AM - Unable
to contact server..
Error - 7/16/2011 7:46:22 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 7:46:17 AM - Error connecting to the internet. 7:46:17 AM - Unable
to contact server..
Error - 8/5/2011 9:59:49 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 9:59:48 AM - Error connecting to the internet. 9:59:48 AM - Unable
to contact server..
[ System Events ]
Error - 1/16/2012 11:10:36 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.
Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = DCOM | ID = 10005
Description =
Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053
Error - 1/16/2012 11:58:48 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/16/2012 11:59:07 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:09:56 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/17/2012 12:09:58 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:14:31 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/17/2012 12:14:34 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:26:13 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
< End of report >
OTL logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sprint\Sprint SmartView\SwiApiMuxCdma.exe (Sierra Wireless, Inc.)
PRC - C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
PRC - C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
PRC - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Sprint\Sprint SmartView\Pac.dll ()
MOD - C:\Program Files\Sprint\Sprint SmartView\Eap.dll ()
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (SmithMicro Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (RMCAST) – C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys ()
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\EG1032xp.sys (Linksys, A Division of Cisco Systems, Inc )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Amy\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://amyost.homestead.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 25 EF 16 03 EF EA CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://amyost.homestead.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/02 11:35:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\MSBuild\Mozilla Firefox\components [2012/01/15 17:53:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\MSBuild\Mozilla Firefox\plugins [2011/09/15 05:30:24 | 000,000,000 | —D | M]
[2010/05/03 20:07:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Extensions
[2012/01/15 17:53:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions
[2012/01/15 17:53:54 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gears.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Amy\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Scorpion Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnlfhfpojmehjcdldbclpgfclmdodpin\1_0\
CHR - Extension: Mahjongg Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccklcogklfjbajdeimbknkplphkjbkhb\1_0\
CHR - Extension: Earthquake Alert = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceddfjkhemabgponojbabonhjpclgaja\0.4_0\
CHR - Extension: Solitaire Card Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp\1.0.0.2_0\
CHR - Extension: Super Mario = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnkjbdmdgifgkcenpllpepgcgllapgpm\1_0\
CHR - Extension: Solitairey = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp\2.2.4_0\
CHR - Extension: Games.com = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eciiciccngmnpknipagfcpdbpbejladh\0.0.0.3_0\
CHR - Extension: Namco Mahjong Butterfly = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdpljegkclkedmcmfpdfgomeoojlajaa\1.104_0\
CHR - Extension: World of Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn\1.0.1_0\
CHR - Extension: Farty mcFart = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijghjfglokjbecncjijjocbmcbbhgpkc\1.2_0\
CHR - Extension: HuffingtonPost NewsGlide = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjialelnkjdomiblmnpcpjongleegef\0.3.2_0\
CHR - Extension: Just Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcbhedoainjipdhgimhhajobmblbaopf\2.1_0\
CHR - Extension: Google Maps = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.3_0\
CHR - Extension: Word\u00B2 = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: US Cities = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbljbaeppeadkjipnapacpommhijhbel\1_0\
CHR - Extension: Google Books = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\0.0.0.6_0\
CHR - Extension: Word Scramble II = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnoadpilbdgjcffnbflkahalmfflpdh\1_0\
CHR - Extension: Typing Game = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mobfbeogeanchbdhboilncgnkfkibjjg\1.0.3.0_0\
CHR - Extension: Mahjong Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\neojceinbonpjjcokpokpeobkhcpiloc\1.0.0.1_0\
CHR - Extension: Demon Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhmiblkonfdnknhmhegmeddkmljlnjbd\1_0\
CHR - Extension: Heavy Jumble = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolnangifendohpjiagboafdlkfhbaml\1_0\
CHR - Extension: Puzzle Games from Big Fish Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\npolkgeaiepngllaancmiflhecgfdhnj\1.1_0\
CHR - Extension: Reversi = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhjkapjdlmmadkepnmlkpadnnnnoebm\0.0.0.3_0\
CHR - Extension: Draw My Thing = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odpjeimbfolekeldhfddmbemmpiffkch\1.0_0\
CHR - Extension: Mysteriez! = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\phhpkfchfjfeicikkkajdojpjkapdpnd\1.0.1_0\
CHR - Extension: Gmail = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/12/03 22:02:04 | 000,438,048 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15093 more lines…
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [RDVCHG] C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
O4 - HKLM..\Run: [Sprint SmartView] C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{28AB4157-57D1-4951-820D-BE2B23AC05C4}: NameServer = 68.28.137.132 68.28.138.132
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/17 00:10:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/16 13:50:06 | 000,000,000 | —D | C] – C:\ProgramData\RegCure
[2011/12/30 21:24:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
[2011/12/22 21:47:37 | 000,204,496 | —- | C] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
========== Files - Modified Within 30 Days ==========
[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/17 00:03:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/16 23:58:36 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:58:26 | 000,002,385 | —- | M] () – C:\Users\Amy\Desktop\Google Chrome.lnk
[2012/01/16 23:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:34:34 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/16 23:34:34 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/16 23:28:02 | 000,000,499 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2012/01/16 23:26:09 | 000,001,072 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/01/16 23:25:59 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/16 23:22:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2012/01/16 14:39:28 | 000,007,661 | —- | M] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2012/01/15 21:55:21 | 281,428,358 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
[2011/12/18 06:57:09 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
========== Files Created - No Company Name ==========
[2012/01/16 23:38:45 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:38:44 | 000,000,848 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/15 21:55:21 | 281,428,358 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/03 22:52:19 | 000,000,115 | —- | C] () – C:\Windows\wininit.ini
[2011/10/21 11:40:56 | 000,000,000 | —- | C] () – C:\Users\Amy\AppData\Local\{818FCAC6-A463-44AD-8B14-F719C1C3D1D7}
[2011/05/22 20:42:38 | 000,331,776 | —- | C] () – C:\Windows\System32\TwcToolbarIe7.dll
[2011/05/22 20:42:38 | 000,098,304 | —- | C] () – C:\Windows\System32\TwcToolbarBho.dll
[2011/05/20 01:28:24 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/05/20 01:26:33 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/04/14 17:03:40 | 000,003,565 | —- | C] () – C:\Windows\System32\RDDlg.dat
[2010/11/20 18:11:32 | 000,001,072 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/11/09 12:36:02 | 000,012,288 | —- | C] () – C:\Users\Amy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/22 14:31:43 | 000,000,035 | —- | C] () – C:\Windows\A5W.INI
[2010/07/22 11:48:30 | 000,007,661 | —- | C] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2010/06/08 15:36:06 | 000,037,248 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2009/07/13 23:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 000,268,184 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 18:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[1997/11/10 14:18:48 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
========== LOP Check ==========
[2010/11/05 20:52:18 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\acccore
[2010/10/20 05:18:40 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\AVG10
[2010/05/03 13:30:28 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Bytemobile
[2010/05/21 12:38:52 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Pogo Games
[2011/01/29 23:27:13 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\RegistryKeys
[2010/11/23 21:44:58 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sierra Wireless
[2010/11/23 21:55:14 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sprint
[2011/01/17 12:59:51 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\SystemRequirementsLab
[2010/05/03 19:52:29 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WeatherBug
[2010/08/07 20:35:26 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WinPatrol
[2010/06/23 23:24:42 | 000,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(58).TXT
[2011/12/12 06:34:59 | 000,032,616 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/02/10 06:00:11 | 000,229,148 | —- | M] () – C:\aaw7boot.log
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/02/11 14:09:42 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/05/03 16:58:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2010/05/03 16:58:47 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/02/01 18:41:06 | 000,011,187 | —- | M] () – C:\ComboFix.txt
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/06 15:57:53 | 000,000,006 | —- | M] () – C:\dialogInfo.res
[2011/05/18 22:57:10 | 007,643,508 | —- | M] () – C:\drivers.log
[2010/05/03 13:16:42 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/05 20:51:36 | 000,000,808 | -H– | M] () – C:\IPH.PH
[2010/05/01 09:13:14 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/06/18 20:36:23 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/18 20:36:23 | 000,250,032 | RHS- | M] () – C:\ntldr
[2012/01/16 23:22:36 | 2145,177,600 | -HS- | M] () – C:\pagefile.sys
[2009/06/18 20:54:22 | 000,000,575 | —- | M] () – C:\RHDSetup.log
[2009/06/19 02:06:53 | 000,000,005 | —- | M] () – C:\testfile.txt
[2010/05/03 13:16:43 | 000,000,000 | RHS- | M] () – C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 07:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2010/09/20 10:45:44 | 000,016,591 | —- | M] () – C:\Windows\system32\bg_bottom.jpg
[2011/04/11 15:37:04 | 000,023,992 | —- | M] () – C:\Windows\system32\bg_top.jpg
[2010/11/08 10:29:06 | 000,040,726 | —- | M] () – C:\Windows\system32\image_animation.jpg
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/11/28 13:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/11/23 19:48:34 | 000,001,654 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2011/04/26 11:45:20 | 000,058,368 | —- | M] () – C:\Windows\system32\Thumbs.db
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/20 05:57:02 | 000,000,221 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/25 17:49:02 | 000,229,672 | —- | M] () – C:\Users\Amy\Desktop\CrucialScan(1).exe
[2011/08/07 09:39:24 | 000,589,656 | —- | M] (Google Inc.) – C:\Users\Amy\Desktop\GoogleEarthPluginSetup.exe
[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-24 12:34:17
========== Alternate Data Streams ==========
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:D09AEE3D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:72F57408
< End of report >
OTL Extras logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS
Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile]
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe" = C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4647BF57-21C4-4BC8-BA1B-E57A30EE1D31}" = Sprint SmartView
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70DECFBF-9119-4434-B2D3-A3C283D15E45}" = WeatherBug
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112930333}" = Lottso! Deluxe
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4B1B985-F308-4DBA-BFD7-CCCB8839234B}" = HP Deskjet 1000 J110 series Basic Device Software
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AI RoboForm" = AI RoboForm (All Users)
"AIM_7" = AIM 7
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"DirectXMediaRuntime" = DirectX Media Runtime 5.1
"ESET Online Scanner" = ESET Online Scanner v3
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Merriam-Webster's Reference Library" = Merriam-Webster's Reference Library
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"SystemRequirementsLab" = System Requirements Lab
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"727d1ea1876aa06e" = WowAceUpdater
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/15/2012 10:53:32 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7042
Description =
Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 9002
Description =
Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 1/15/2012 10:53:39 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 1/15/2012 10:53:42 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 1/15/2012 8:51:18 PM | Computer Name = Amy-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 81c Start
Time: 01ccd3e861bf3210 Termination Time: 47 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 1/16/2012 11:46:09 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Sprint\Sprint
SmartView\OemDriverManager64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 1/16/2012 11:48:53 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
[ Media Center Events ]
Error - 5/21/2011 5:53:21 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:20 AM - Error connecting to the internet. 5:53:20 AM - Unable
to contact server..
Error - 5/21/2011 5:54:01 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:30 AM - Error connecting to the internet. 5:53:30 AM - Unable
to contact server..
Error - 5/23/2011 10:18:37 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:36 AM - Error connecting to the internet. 10:18:37 AM - Unable
to contact server..
Error - 5/23/2011 10:18:47 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:42 AM - Error connecting to the internet. 10:18:42 AM - Unable
to contact server..
Error - 5/31/2011 10:37:43 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:43 AM - Error connecting to the internet. 10:37:43 AM - Unable
to contact server..
Error - 5/31/2011 10:37:54 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:48 AM - Error connecting to the internet. 10:37:48 AM - Unable
to contact server..
Error - 6/3/2011 10:38:23 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:23 AM - Error connecting to the internet. 10:38:23 AM - Unable
to contact server..
Error - 6/3/2011 10:38:41 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:28 AM - Error connecting to the internet. 10:38:28 AM - Unable
to contact server..
Error - 7/16/2011 7:46:22 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 7:46:17 AM - Error connecting to the internet. 7:46:17 AM - Unable
to contact server..
Error - 8/5/2011 9:59:49 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 9:59:48 AM - Error connecting to the internet. 9:59:48 AM - Unable
to contact server..
[ System Events ]
Error - 1/16/2012 11:10:36 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.
Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = DCOM | ID = 10005
Description =
Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053
Error - 1/16/2012 11:58:48 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/16/2012 11:59:07 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:09:56 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/17/2012 12:09:58 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:14:31 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058
Error - 1/17/2012 12:14:34 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 1/17/2012 12:26:13 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
< End of report >