michaeldhill8
Topic Starter
I ran the steps in the Google Redirect forum. None of the fixes worked. Therefore I could really use some more help. I started from scratch from the "Getting Started" forum. Here are the results from OTL. This first one is from the OTL.txt, the second is from Extras.txt.
OTL logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS
Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\hillmd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Windows\System32\SProtector.exe (Sophos Plc)
PRC - C:\Windows\System32\SimonPro.exe (Sophos Plc)
PRC - C:\Windows\System32\Simba.exe (Sophos Plc)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\dloclientu.exe (Symantec Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited)
PRC - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Users\hillmd\AppData\Roaming\CognosRCP\rcp\cognosrcp.exe (IBM Cognos ULC)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndlaunch.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
PRC - C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
PRC - C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\lotus\notes\nsl.exe (IBM Corp)
PRC - C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll ()
MOD - C:\Windows\System32\IccLibDll.dll ()
MOD - C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
MOD - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNBELinkern.dll ()
MOD - C:\Windows\System32\sptbasen.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
========== Win32 Services (SafeList) ==========
SRV - (oracle_load_balancer_60_client-forms6i) – %systemroot%\system32\atimpab.dll File not found
SRV - (nvstor64) – %systemroot%\system32\vxsvc.dll File not found
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (SophosSGPPS) – C:\Windows\System32\SProtector.exe (Sophos Plc)
SRV - (SDBAgent) – C:\Program Files\Sophos\SafeGuard PortProtector Client\SDBAgent.exe (Sophos Plc)
SRV - (McAfee SiteAdvisor Enterprise Service) – C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (SAService) – C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
SRV - (DLOChangeJournalSvc) – C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (CxAudMsg) – C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
SRV - (TPHKLOAD) – C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (SGNAuthService) – C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEDevCtl) SafeGuard® – C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEFCSvcn) SafeGuard® – C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Trans) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Sem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_LogSystem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_BEService) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (iPassConnectEngine) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateApp) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (ndGlobalLauncher) – C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
SRV - (ndinit) – C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
SRV - (mgssecsvc) – C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
SRV - (mgsdl) – C:\Program Files\ManageSoft\Launcher\mgsdl.exe (ManageSoft Corp)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PWSSvc) – C:\Program Files\Colligo Networks\Colligo Workgroup Edition\PWSSvc.exe ()
SRV - (Lotus Notes Single Logon) – C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)
========== Driver Services (SafeList) ==========
DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (PnSson) – File not found
DRV - (mfeavfk01) – File not found
DRV - (ehdrv) – system32\DRIVERS\ehdrv.sys File not found
DRV - (Avgtdix) – system32\DRIVERS\avgtdix.sys File not found
DRV - (Avgrkx86) – system32\DRIVERS\avgrkx86.sys File not found
DRV - (AVGIDSShim) – system32\DRIVERS\avgidsshimx.sys File not found
DRV - (AVGIDSHX) – system32\DRIVERS\avgidshx.sys File not found
DRV - (AVGIDSFilter) – system32\DRIVERS\avgidsfilterx.sys File not found
DRV - (AVGIDSDriver) – system32\DRIVERS\avgidsdriverx.sys File not found
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (Spfd) – C:\Windows\System32\drivers\Spfd.sys (Safend Ltd.)
DRV - (Sidney) – C:\Windows\System32\drivers\Sidney.sys (Sophos Plc)
DRV - (SofiaMp) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofia) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofy) – C:\Windows\System32\drivers\Sofy.sys (Sophos Plc)
DRV - (Shandy) – C:\Windows\System32\drivers\Shandy.sys (Sophos Plc)
DRV - (Scarlet) – C:\Windows\System32\drivers\Scarlet.sys (Sophos Plc)
DRV - (Shlos) – C:\Windows\System32\drivers\Shlos.sys (Sophos Plc)
DRV - (Sahara) – C:\Windows\System32\drivers\Sahara.sys (Sophos Plc)
DRV - (Salvador) – C:\Windows\System32\drivers\Salvador.sys (Sophos Plc)
DRV - (Santa) – C:\Windows\System32\drivers\Santa.sys (Sophos Plc)
DRV - (Diego) – C:\Windows\System32\drivers\Diego.sys (Sophos Plc)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvkflt) – C:\Windows\System32\drivers\nvkflt.sys (NVIDIA Corporation)
DRV - (nvpciflt) – C:\Windows\System32\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV - (BeFlt) – C:\Windows\System32\drivers\BEFLT.SYS (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (HIPK) – C:\Windows\System32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\Windows\System32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\Windows\System32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (firelm01) – C:\Windows\System32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\Windows\System32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\Windows\System32\drivers\FirePM.sys (McAfee, Inc.)
DRV - (risdxc) – C:\Windows\System32\drivers\risdxc86.sys (REDC)
DRV - (5U877) – C:\Windows\System32\drivers\5U877.sys (Ricoh co.,Ltd.)
DRV - (DKRtWrt) – C:\Windows\System32\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (Shockprf) – C:\Windows\System32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\Windows\System32\drivers\ApsHM86.sys (Lenovo.)
DRV - (NETwNs32) ___ Intel® – C:\Windows\System32\drivers\NETwNs32.sys (Intel Corporation)
DRV - (e1cexpress) Intel® – C:\Windows\System32\drivers\e1c6232.sys (Intel Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\System32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (MEI) Intel® – C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (BE_FLTI) – C:\Windows\System32\drivers\be_fltim.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAES2M) – C:\Windows\System32\drivers\cegaes2m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAESM) – C:\Windows\System32\drivers\cegaesm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (SGSTDRVM) – C:\Windows\System32\drivers\SGStDrvm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEEIDEM) – C:\Windows\System32\drivers\ceeidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEIDEM) – C:\Windows\System32\drivers\ceidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEDESM) – C:\Windows\System32\drivers\cedesm.sys ()
DRV - (CEDES3M) – C:\Windows\System32\drivers\cedes3m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEHMACM) – C:\Windows\System32\drivers\cehmacm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CESHAM) – C:\Windows\System32\drivers\cesham.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CERNDM) – C:\Windows\System32\drivers\cerndm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (lenovo.smi) – C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (SpfdBus) – C:\Windows\System32\drivers\SpfdBus.sys (Safend Ltd.)
DRV - (CVPNDRVA) – C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (TVTI2C) – C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (psadd) – C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (DNE) – C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (FirehkMP) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (CVirtA) – C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\ManageSoft\Usage Agent\mgsusageagent\ [2011/08/10 03:48:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/02 08:39:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/11/29 09:15:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/05/10 20:53:55 | 000,000,000 | —D | M]
[2011/07/21 13:09:28 | 000,032,040 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ManageSoft Web Application Tracker) - {30A22EC9-42D0-4D46-A2F7-7516419F943D} - C:\Program Files\ManageSoft\Usage Agent\mgsiebho.dll ()
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111209122843.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ForteConfig] C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
O4 - HKLM..\Run: [RotateImage] C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [RunSimba] C:\Windows\System32\Simba.exe (Sophos Plc)
O4 - HKLM..\Run: [SchedulingAgent_nDG] C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
O4 - HKLM..\Run: [ScrewDrivers RDP Plugin] C:\Program Files\triCerat\Simplify Printing\ScrewDrivers Client v4\install_rdp.exe ()
O4 - HKLM..\Run: [SGNMasterApplication] C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant systems, Inc.)
O4 - HKLM..\Run: [STFWebFormApp] "C:\Program Files\Common Files\STF Services Shared\WebFormApp.exe" -start File not found
O4 - HKCU..\Run: [Google] C:\Users\hillmd\AppData\Local\javasharedresources\Google\wimpud.dll (MainConcept GmbH)
O4 - Startup: C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk = C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceRunOnStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 2 = nusrmgr.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 3 = wscui.cpl (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = wuaucpl.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 5 = Microsoft.ActionCenter
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 6 = Microsoft.BitlockerDriveEncryption
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 7 = Microsoft.WindowsDefender
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = crowe-chizek.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5124753B-F203-43E3-9BE8-9C547CC546DE}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\cw {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\cwt {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\aSinadin: DllName - (Sinadin.dll) - C:\Windows\System32\Sinadin.dll (Sophos Plc)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Authentication Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O30 - LSA: Security Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: nvstor64 - %systemroot%\system32\vxsvc.dll File not found
NetSvcs: oracle_load_balancer_60_client-forms6i - %systemroot%\system32\atimpab.dll File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/10 21:13:58 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/05/10 19:47:20 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Malwarebytes
[2012/05/10 19:46:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/10 19:38:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/05/10 19:27:08 | 000,040,328 | —- | C] (McAfee, Inc.) – C:\Windows\System32\HIPIS0e011b8.dll
[2012/05/10 18:47:48 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/05/10 18:44:29 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/05/10 18:44:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Local\Conduit
[2012/05/10 15:49:41 | 000,000,000 | —D | C] – C:\ProgramData\Roaming
[2012/05/09 15:26:52 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\INSTEC
[2012/05/04 11:34:06 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\Performance
[2012/05/03 10:44:44 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACL 9
[2012/05/03 10:44:43 | 000,000,000 | —D | C] – C:\ACL Data
[2012/05/03 10:43:00 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2012/04/18 07:35:18 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2012/04/15 22:51:50 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/04/15 22:45:18 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/15 22:43:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/04/15 22:26:23 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/04/15 22:11:29 | 000,000,000 | —D | C] – C:\ProgramData\B7E858A70004254C00079FC2B4EB238B
========== Files - Modified Within 30 Days ==========
[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 20:54:34 | 000,001,118 | —- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk
[2012/05/10 20:54:12 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/10 20:53:49 | 000,127,577 | —- | M] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 20:53:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2012/05/10 20:29:08 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/10 15:47:59 | 000,000,544 | —- | M] () – C:\Windows\ODBC.INI
[2012/05/10 11:32:51 | 000,389,760 | —- | M] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/04 13:44:16 | 000,414,800 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/03 10:44:44 | 000,002,077 | —- | M] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/05/03 00:17:08 | 000,143,008 | —- | M] (McAfee, Inc.) – C:\Windows\System32\KevlarSigs.dll
[2012/04/30 16:27:35 | 000,032,832 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/25 11:31:19 | 000,688,486 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/25 11:31:19 | 000,129,136 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/19 08:09:27 | 000,029,733 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | M] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | M] () – C:\Windows\System32\dds_trash_log.cmd
========== Files Created - No Company Name ==========
[2012/05/10 20:53:49 | 000,127,577 | —- | C] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 11:32:51 | 000,389,760 | —- | C] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/03 10:44:44 | 000,002,077 | —- | C] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/04/30 16:27:35 | 000,032,832 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/19 08:09:27 | 000,029,733 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | C] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | C] () – C:\Windows\System32\dds_trash_log.cmd
[2011/09/26 18:05:46 | 000,222,488 | —- | C] () – C:\Windows\System32\SPHook.dll
[2011/09/12 07:21:08 | 000,009,886 | —- | C] () – C:\Users\hillmd\AppData\Roaming\connector.dotm
[2011/08/30 15:06:10 | 000,002,080 | —- | C] () – C:\Windows\System32\drivers\SamSfPa.dat
[2011/08/30 11:48:31 | 000,000,544 | —- | C] () – C:\Windows\ODBC.INI
[2011/08/30 11:48:23 | 000,000,608 | —- | C] () – C:\Windows\tenkey.ini
[2011/08/09 16:38:36 | 000,002,658 | —- | C] () – C:\Windows\INSTAREA.DAT
[2011/08/09 16:16:38 | 000,039,472 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/03/06 19:45:44 | 000,213,332 | —- | C] () – C:\Windows\System32\igfcg600m.bin
[2011/03/06 19:45:44 | 000,145,804 | —- | C] () – C:\Windows\System32\igcompkrng600.bin
[2011/03/06 19:45:42 | 000,963,116 | —- | C] () – C:\Windows\System32\igkrng600.bin
[2011/03/06 19:13:20 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/03/06 19:11:06 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2011/03/06 19:07:58 | 000,094,208 | —- | C] () – C:\Windows\System32\IccLibDll.dll
[2011/02/02 23:29:52 | 001,816,324 | —- | C] () – C:\Windows\System32\nvcoproc.bin
[2011/01/18 10:35:42 | 000,030,893 | —- | C] () – C:\Windows\System32\drivers\Mixer.ini
[2010/11/20 16:29:34 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 16:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2010/10/28 12:27:48 | 000,001,816 | —- | C] () – C:\Windows\System32\drivers\Altmixer.ini
[2010/10/15 06:58:42 | 067,108,864 | —- | C] () – C:\Windows\SGBEKERNEL.BIN
[2010/10/15 06:58:42 | 000,000,512 | R— | C] () – C:\Windows\KrnlPatt.bin
[2010/10/15 01:28:02 | 000,000,512 | —- | C] () – C:\Windows\SGBEMBR.BIN
[2010/10/14 21:11:02 | 000,167,936 | —- | C] () – C:\Windows\System32\sptbasen.dll
[2010/10/14 17:40:00 | 000,118,784 | R— | C] () – C:\Windows\System32\SGNP11RSAn.dll
[2010/10/14 15:37:04 | 000,019,712 | —- | C] () – C:\Windows\System32\drivers\cedesm.sys
[2010/10/01 14:39:56 | 000,001,372 | —- | C] () – C:\Windows\System32\VoipUpdate.ini
========== LOP Check ==========
[2011/09/19 15:11:08 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\CognosRCP
[2011/08/30 12:01:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Colligo Networks
[2012/01/15 15:35:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Leadertech
[2011/08/30 11:44:57 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\ManageSoft Corp
[2011/08/30 14:27:28 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\MessageOne
[2012/05/10 19:38:32 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/01/02 21:37:44 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Tacori Bridal Collection
[2009/07/13 23:53:46 | 000,029,670 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 16:29:06 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/08/10 07:18:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/05/09 15:39:20 | 000,000,000 | —- | M] () – C:\dataset.log
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/08/30 12:19:21 | 000,067,049 | —- | M] () – C:\MGSPostWork.log
[2011/09/12 12:35:40 | 000,013,176 | —- | M] () – C:\Open Items Summary Report.xls
[2012/05/10 20:53:30 | 3130,220,544 | -HS- | M] () – C:\pagefile.sys
[2012/02/23 17:26:17 | 000,000,312 | —- | M] () – C:\Ping.txt
[2011/08/09 16:44:38 | 000,000,211 | —- | M] () – C:\setup.log
[2012/05/10 21:03:24 | 000,040,324 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.03.12_log.txt
[2012/05/10 21:05:17 | 000,077,580 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.04.59_log.txt
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:15:26 | 000,280,064 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
[2009/07/13 20:15:26 | 000,090,624 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2011/02/05 12:25:34 | 000,082,184 | —- | M] (Microsoft Corporation.) – C:\Windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
[2010/11/03 17:45:10 | 000,016,896 | —- | M] (Captaris, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\rfprint.dll
[2010/11/20 16:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2008/05/22 10:35:34 | 000,299,324 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1280x1024.jpg
[2008/05/22 10:33:48 | 000,299,480 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1400x990.jpg
[2008/05/22 10:32:36 | 000,124,577 | —- | M] () – C:\Windows\Crowe Wallpaper 1.jpg
[2008/05/22 10:30:08 | 000,326,220 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1280x1024.jpg
[2008/05/22 10:28:12 | 000,295,571 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1400x990.jpg
[2008/05/22 10:27:30 | 000,141,897 | —- | M] () – C:\Windows\Crowe Wallpaper 2.jpg
[2008/05/22 10:23:36 | 000,430,497 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1280x1024.jpg
[2008/05/22 10:22:34 | 000,403,300 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1400x990.jpg
[2008/05/22 10:21:32 | 000,366,234 | —- | M] () – C:\Windows\Crowe Wallpaper 3.jpg
[2008/05/22 10:20:26 | 000,210,931 | —- | M] () – C:\Windows\Crowe Wallpaper 4.jpg
[2006/02/28 12:41:04 | 000,031,565 | —- | M] () – C:\Windows\Unique2Big4.JPG
[2008/05/22 10:43:44 | 000,091,442 | —- | M] () – C:\Windows\Unique2Big4Crowe.JPG
< %systemroot%\*.png >
[2008/05/22 10:45:20 | 000,006,569 | —- | M] () – C:\Windows\Crowe_2c_White_Small.png
[2008/05/22 10:46:30 | 000,148,091 | —- | M] () – C:\Windows\Unique2Big4Crowe.PNG
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/04 08:42:08 | 000,000,221 | -HS- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAUShutdownOption" = 1
"NoAutoUpdate" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB20529$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:502D809E
< End of report >
Here is the report from Extras.Txt
OTL Extras logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS
Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3A273A4B-7E8C-4F16-8B50-060367B3135D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{B6D68FF2-5B6F-4570-B65B-6D0F4A31A067}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{18FF6F66-51DB-4292-8668-F92B3A1ADF67}" = dir=in | app=c:\program files\microsoft lync\ucmapi.exe |
"{23315F50-6557-49A4-B9D8-290F06FA98D0}" = protocol=6 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{273FADB2-C640-42AF-88DA-76D7B7BB5054}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2D443245-1CC4-41EC-B966-7B257939E0E4}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{3EDBA95D-0C14-46DB-9B19-9DE48FE8ACC6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{40446D02-B013-4F2E-84D7-1F45091199AE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{4CD225EE-ADC8-4871-BD82-BFED6CE09209}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5CB3D8B8-9674-4313-9A96-71DC2C85C7EA}" = dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{5D6F1B84-D5FC-422A-B1D6-C1DC0DAAC3B1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{5EC0DB8E-5C3C-4A46-A2BA-6278C27AFDD6}" = dir=in | app=c:\program files\colligo networks\colligo workgroup edition\colligo.exe |
"{680F3BCF-DE69-49FE-A1CE-D0DD81DF7926}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{6ADB6757-1A99-496B-8C71-57724809D4BA}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{71B98DBA-2899-419D-B5F5-376F304B1529}" = protocol=17 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{71D7CD66-ABC4-46C9-8F64-D54C5AA0B4A4}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{7B1DEDEF-2193-47D2-933A-E607753C81CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8D0F57C7-3264-4096-84B7-284E368D0F5C}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B3C09CC4-C96C-43AE-A571-7847FCCC0FE0}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B726BA07-0EC2-4165-9B22-D93C17C490A9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{CE08BEF9-2C30-4EC9-BFD1-2F385AB00B66}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{D64D9E2A-4C86-40A2-8F8F-325ED96831C7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{DECC7D06-1820-40BB-88F5-1D6E68022CB3}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{E87FF355-F7EF-46D4-8EF7-A75556B87CEE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{EAAB60CC-E615-4E13-96D6-130FDA2780C2}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{F100AF2C-6A14-4138-BDAA-5EC9A981C454}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC3F65-86EB-475E-881F-A5B1CF731320}" = McAfee SiteAdvisor Enterprise Plus
"{05227385-5073-46ED-9035-B1910E2613CC}" = DSmobileSCAN II
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{134774E3-4A0B-4139-815B-A7171CFA0B9C}" = Caseware Master Library 4.18.2011.00
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23D79730-EC1A-435E-83F8-AAEBFE5237B0}" = Adobe Flash Player 11 ActiveX
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2BB9B2F5-79E7-4220-B903-22E849100547}" = Microsoft Conferencing Add-in for Microsoft Office Outlook
"{2C2EA2C8-1B0F-4FEC-88E2-2B104E0507F3}" = Outlook Space On Demand
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{51D359FF-91CA-467B-967D-DEEDA013628A}" = Colligo Workgroup Edition
"{5395ACBD-D72C-4ECB-0AAC-1821D15D049A}" = SafeGuard PortProtector Client
"{55D1BF8E-EA8F-4969-82B9-B577010CFBCD}" = Microsoft Baseline Security Analyzer 2.1
"{56BD1B37-3934-4FA4-AE71-91DDB176C032}" = ACL 9
"{6267109C-50D2-4667-9FF6-03FB9A94A771}" = Sophos SafeGuard 5.50.8 Client
"{65545E0A-8288-43CF-8A68-E2F6CC8B469E}" = ManageSoft for managed devices
"{65E9B2E4-555F-441C-A8F7-B754FB1A010E}" = iPassConnect Crowe Connect
"{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"{6FED6E57-AA25-4597-9ED5-C66C02992066}" = Symantec NetBackup Desktop Agent
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774391DB-E12D-47AE-B4D2-46F7EB4ABDDC}" = McAfee Virtual Technician
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{846A8F6B-BEE5-4E94-9356-99B51E4D6F54}" = IBM Cognos Contributor Client
"{84BDCF3F-9FDE-4526-BBB4-3077CB8515EC}" = CaseWare Connector 2011
"{89DFC26C-9CB3-44E3-A799-80BCE8CE0BEB}" = Monarch 10.00
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B39A4EA-6E2C-4298-97AA-D8CDB0D91E7A}" = Outlook Secure Option
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{1E6AE8C5-CAC6-49B2-953B-3A4C8CDC1AD2}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00D1-0409-0000-0000000FF1CE}" = Microsoft Access database engine 2010 (English)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90C65E91-03C5-47B9-9EBF-72AAB0E7FDF3}" = ePO-MVT
"{94FB0978-D094-40C7-91D7-834D39220D4A}" = Crystal Reports XI Release 2 for Sage
"{9A235AC3-FA85-42D6-9B93-78A45E23596F}" = ScrewDrivers Client v4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA0DEE4-E84B-466F-9B96-FC255F3A929F}" = Integrated Camera TWAIN
"{9FCD6918-3DB5-45F2-B89F-654BB3233483}" = Sophos SafeGuard 5.50.0 Client Configuration
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A0E54EC6-EA51-4088-A6EE-BEF1D1D128AB}" = Lotus Notes 7.0.2
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-BA7E-000000000005}" = Adobe Acrobat X Standard - English, Français, Deutsch
"{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}" = Cisco Systems VPN Client 5.0.07.0290
"{B2CA6F37-1602-4823-81B5-0384B6888AA6}" = Integrated Camera Driver Installer Package Ver.1.1.0.1147
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Display Control Panel
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B332732A-4958-41DD-B439-DDA2D32753C5}" = McAfee Host Intrusion Prevention
"{B60C695C-EF2F-4826-9106-417ED7A68658}" = RightFax Product Suite - Client
"{B72B06E0-0C54-495F-896F-E3ED2905624A}" = Microsoft Junk E-mail Reporting Add-in
"{B87E6D2C-1365-4507-AA4F-15D007A64D1A}" = Dell Outlook Addin (x86)
"{C184AAA4-DFD6-44DF-B1E1-B2B9CC19EAA7}" = CaseWare Working Papers 2011
"{CDBAAE82-1725-4BDF-9770-69EA174318F1}" = Sophos SafeGuard Preinstall 5.50.0
"{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}" = McAfee VirusScan Enterprise
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D79036E3-A83E-41CD-9776-28853C258940}" = DSmobile 600
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DE91C193-2611-4BD3-A9F9-DF589C572565}" = McAfee Agent
"{E117B4A1-5C43-4ED8-8DE8-B45B58940191}" = Diskeeper 2011 Professional
"{E2C29C93-171B-40CF-949E-B27E3E6F9EDE}" = Becker's CPA Exam Review and PassMaster - 2011 Edition
"{E60146B0-C083-47BE-BD6B-EFA57AC8D9B1}" = RightFax Product Suite - Client
"{EA710A0A-BF5D-433C-8EB5-D17DC54CC298}" = Microsoft Office Live Meeting 2007
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F30B17C3-F398-4832-9176-6B2B52D9682A}" = IBM Cognos 8 Planning 8.4 Client Framework
"{F7797694-3F06-41C7-B9A0-C4BEF21ACE7A}" = Judy's TenKey ™ Installer
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe PDF IFilter 6.0" = Adobe PDF IFilter 6.0
"B2A - Windows Active X Files [Common] (ManageSoft)" = B2A - Windows Active X Files [Common] (via ManageSoft)
"CNXT_AUDIO_HDA" = Conexant 20672 SmartAudio HD
"Crowe Utilities [Common] (ManageSoft)" = Crowe Utilties [Common] (via ManageSoft)
"DTE Remote 2004" = DTE Remote 2004
"HP OfficeJet 100 Printer Drivers [Common] (ManageSoft)" = HP OfficeJet 100 Printer Drivers [Common] (via ManageSoft)
"HP450 [Common] (ManageSoft)" = HP450 Print Drivers [Common] (via ManageSoft)
"HP470 [Common] (ManageSoft)" = HP470 Print Drivers [Common] (via ManageSoft)
"InstallShield_{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"LENOVO.SMIIF" = Lenovo System Interface Driver
"McAfee GetSusp Malware Scanner [Common] (ManageSoft)" = McAfee GetSusp Malware Scanner [Common] (via ManageSoft)
"McAfee Stinger - Standard [Common] (ManageSoft)" = McAfee Stinger - Standard [Common] (via ManageSoft)
"MGS Config [Common] (ManageSoft)" = MGS Config [Common] (via ManageSoft)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Office 2010 Help Guides [Common] (ManageSoft)" = Microsoft Office 2010 Help Guides [Common] (via ManageSoft)
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Nvidia Config [Common] (ManageSoft)" = Nvidia Config [Common] (via ManageSoft)
"Office Update Inventory Tool [Common] (ManageSoft)" = Office Update Inventory Tool [Common] (via ManageSoft)
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OnScreenDisplay" = On Screen Display
"PaperPort Viewer [Common] (ManageSoft)" = PaperPort Viewer [Common] (via ManageSoft)
"Power Management Driver" = ThinkPad Power Management Driver
"Security Patch Settings for Microsoft Office [Common] (ManageSoft)" = Security Patch Settings for Microsoft Office [Common] (via ManageSoft)
"Security Patch Settings for Microsoft Windows [Common] (ManageSoft)" = Security Patch Settings for Microsoft Windows [Common] (via ManageSoft)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"WinZip" = WinZip
"WinZip [Common] (ManageSoft)" = WinZip 9.0 SR1 [Common] (via ManageSoft)
"Wireless Profiles Config [Common] (ManageSoft)" = Wireless Profiles Config [Common] (via ManageSoft)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ACL Update [HillMD] (ManageSoft)" = ACL Update [HillMD] (via ManageSoft)
"AOL Toolbar" = AOL Toolbar
"FAS 2012.1 DLL Patch [hillmd] (ManageSoft)" = FAS 2012.1 DLL Patch [hillmd] (via ManageSoft)
"Interactive Forms 2011 [HillMD] (ManageSoft)" = Interactive Forms 2011 [HillMD] (via ManageSoft)
"Lotus Notes Configuration [hillmd] (ManageSoft)" = Lotus Notes Configuration [HillMD] (via ManageSoft)
"MGS User Config [hillmd] (ManageSoft)" = MGS User Config [hillmd] (via ManageSoft)
"Microsoft Windows Desktop Shortcuts [HillMD] (ManageSoft)" = Microsoft Windows Desktop Shortcuts [HillMD] (via ManageSoft)
"Personalization_2 [hillmd] (ManageSoft)" = Personalization_2 [hillmd] (via ManageSoft)
"Symantec NetBackup Configuration Changes [hillmd] (ManageSoft)" = Symantec NetBackup Configuration Changes [HillMD] (via ManageSoft)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998
Error - 2/12/2012 6:17:37 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program vpngui.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 27ac Start Time:
01cce803bba98cad Termination Time: 120 Application Path: C:\Program Files\Cisco Systems\VPN
Client\vpngui.exe Report Id: 5d0bc9be-55c7-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:55:39 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2694 Start
Time: 01ccea5e9a381ee4 Termination Time: 6 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: c98b5480-5652-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:57:34 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1698 Start
Time: 01ccea5f915db115 Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 0e1873a3-5653-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:59:17 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2044 Start
Time: 01ccea5fd2ff48de Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 4bc82321-5653-11e1-864e-c80953cf97d0
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 15569
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 15569
[ ManageSoft Events ]
Error - 5/10/2012 9:26:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 9:26:11 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T202611] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:02:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:02:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210207] Failed to run "Update Schedule" - Program did not
execute successfully
Error - 5/10/2012 10:08:02 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:08:06 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210806] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:12:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:12:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211207] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Installation Agent | ID = 65537
Description =
Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211542] Failed to run "Update Client Settings" - Program
did not execute successfully
[ System Events ]
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Cercsr6 service terminated with the following error: %%126
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Nidomainservice service terminated with the following error: %%126
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.
Error - 5/10/2012 9:53:47 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:53:51 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
luafv
Error - 5/10/2012 9:53:53 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:54:13 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:54:16 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 10:11:01 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7030
Description = The ESET Service service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 5/10/2012 10:11:30 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The epfwwfpr service depends the following service: BFE. This service
might not be installed.
< End of report >
OTL logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS
Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\hillmd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Windows\System32\SProtector.exe (Sophos Plc)
PRC - C:\Windows\System32\SimonPro.exe (Sophos Plc)
PRC - C:\Windows\System32\Simba.exe (Sophos Plc)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\dloclientu.exe (Symantec Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited)
PRC - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Users\hillmd\AppData\Roaming\CognosRCP\rcp\cognosrcp.exe (IBM Cognos ULC)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndlaunch.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
PRC - C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
PRC - C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\lotus\notes\nsl.exe (IBM Corp)
PRC - C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll ()
MOD - C:\Windows\System32\IccLibDll.dll ()
MOD - C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
MOD - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNBELinkern.dll ()
MOD - C:\Windows\System32\sptbasen.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
========== Win32 Services (SafeList) ==========
SRV - (oracle_load_balancer_60_client-forms6i) – %systemroot%\system32\atimpab.dll File not found
SRV - (nvstor64) – %systemroot%\system32\vxsvc.dll File not found
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (SophosSGPPS) – C:\Windows\System32\SProtector.exe (Sophos Plc)
SRV - (SDBAgent) – C:\Program Files\Sophos\SafeGuard PortProtector Client\SDBAgent.exe (Sophos Plc)
SRV - (McAfee SiteAdvisor Enterprise Service) – C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (SAService) – C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
SRV - (DLOChangeJournalSvc) – C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (CxAudMsg) – C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
SRV - (TPHKLOAD) – C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (SGNAuthService) – C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEDevCtl) SafeGuard® – C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEFCSvcn) SafeGuard® – C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Trans) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Sem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_LogSystem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_BEService) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (iPassConnectEngine) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateApp) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (ndGlobalLauncher) – C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
SRV - (ndinit) – C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
SRV - (mgssecsvc) – C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
SRV - (mgsdl) – C:\Program Files\ManageSoft\Launcher\mgsdl.exe (ManageSoft Corp)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PWSSvc) – C:\Program Files\Colligo Networks\Colligo Workgroup Edition\PWSSvc.exe ()
SRV - (Lotus Notes Single Logon) – C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)
========== Driver Services (SafeList) ==========
DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (PnSson) – File not found
DRV - (mfeavfk01) – File not found
DRV - (ehdrv) – system32\DRIVERS\ehdrv.sys File not found
DRV - (Avgtdix) – system32\DRIVERS\avgtdix.sys File not found
DRV - (Avgrkx86) – system32\DRIVERS\avgrkx86.sys File not found
DRV - (AVGIDSShim) – system32\DRIVERS\avgidsshimx.sys File not found
DRV - (AVGIDSHX) – system32\DRIVERS\avgidshx.sys File not found
DRV - (AVGIDSFilter) – system32\DRIVERS\avgidsfilterx.sys File not found
DRV - (AVGIDSDriver) – system32\DRIVERS\avgidsdriverx.sys File not found
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (Spfd) – C:\Windows\System32\drivers\Spfd.sys (Safend Ltd.)
DRV - (Sidney) – C:\Windows\System32\drivers\Sidney.sys (Sophos Plc)
DRV - (SofiaMp) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofia) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofy) – C:\Windows\System32\drivers\Sofy.sys (Sophos Plc)
DRV - (Shandy) – C:\Windows\System32\drivers\Shandy.sys (Sophos Plc)
DRV - (Scarlet) – C:\Windows\System32\drivers\Scarlet.sys (Sophos Plc)
DRV - (Shlos) – C:\Windows\System32\drivers\Shlos.sys (Sophos Plc)
DRV - (Sahara) – C:\Windows\System32\drivers\Sahara.sys (Sophos Plc)
DRV - (Salvador) – C:\Windows\System32\drivers\Salvador.sys (Sophos Plc)
DRV - (Santa) – C:\Windows\System32\drivers\Santa.sys (Sophos Plc)
DRV - (Diego) – C:\Windows\System32\drivers\Diego.sys (Sophos Plc)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvkflt) – C:\Windows\System32\drivers\nvkflt.sys (NVIDIA Corporation)
DRV - (nvpciflt) – C:\Windows\System32\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV - (BeFlt) – C:\Windows\System32\drivers\BEFLT.SYS (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (HIPK) – C:\Windows\System32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\Windows\System32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\Windows\System32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (firelm01) – C:\Windows\System32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\Windows\System32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\Windows\System32\drivers\FirePM.sys (McAfee, Inc.)
DRV - (risdxc) – C:\Windows\System32\drivers\risdxc86.sys (REDC)
DRV - (5U877) – C:\Windows\System32\drivers\5U877.sys (Ricoh co.,Ltd.)
DRV - (DKRtWrt) – C:\Windows\System32\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (Shockprf) – C:\Windows\System32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\Windows\System32\drivers\ApsHM86.sys (Lenovo.)
DRV - (NETwNs32) ___ Intel® – C:\Windows\System32\drivers\NETwNs32.sys (Intel Corporation)
DRV - (e1cexpress) Intel® – C:\Windows\System32\drivers\e1c6232.sys (Intel Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\System32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (MEI) Intel® – C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (BE_FLTI) – C:\Windows\System32\drivers\be_fltim.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAES2M) – C:\Windows\System32\drivers\cegaes2m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAESM) – C:\Windows\System32\drivers\cegaesm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (SGSTDRVM) – C:\Windows\System32\drivers\SGStDrvm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEEIDEM) – C:\Windows\System32\drivers\ceeidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEIDEM) – C:\Windows\System32\drivers\ceidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEDESM) – C:\Windows\System32\drivers\cedesm.sys ()
DRV - (CEDES3M) – C:\Windows\System32\drivers\cedes3m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEHMACM) – C:\Windows\System32\drivers\cehmacm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CESHAM) – C:\Windows\System32\drivers\cesham.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CERNDM) – C:\Windows\System32\drivers\cerndm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (lenovo.smi) – C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (SpfdBus) – C:\Windows\System32\drivers\SpfdBus.sys (Safend Ltd.)
DRV - (CVPNDRVA) – C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (TVTI2C) – C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (psadd) – C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (DNE) – C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (FirehkMP) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (CVirtA) – C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\ManageSoft\Usage Agent\mgsusageagent\ [2011/08/10 03:48:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/02 08:39:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/11/29 09:15:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/05/10 20:53:55 | 000,000,000 | —D | M]
[2011/07/21 13:09:28 | 000,032,040 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ManageSoft Web Application Tracker) - {30A22EC9-42D0-4D46-A2F7-7516419F943D} - C:\Program Files\ManageSoft\Usage Agent\mgsiebho.dll ()
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111209122843.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ForteConfig] C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
O4 - HKLM..\Run: [RotateImage] C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [RunSimba] C:\Windows\System32\Simba.exe (Sophos Plc)
O4 - HKLM..\Run: [SchedulingAgent_nDG] C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
O4 - HKLM..\Run: [ScrewDrivers RDP Plugin] C:\Program Files\triCerat\Simplify Printing\ScrewDrivers Client v4\install_rdp.exe ()
O4 - HKLM..\Run: [SGNMasterApplication] C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant systems, Inc.)
O4 - HKLM..\Run: [STFWebFormApp] "C:\Program Files\Common Files\STF Services Shared\WebFormApp.exe" -start File not found
O4 - HKCU..\Run: [Google] C:\Users\hillmd\AppData\Local\javasharedresources\Google\wimpud.dll (MainConcept GmbH)
O4 - Startup: C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk = C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceRunOnStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 2 = nusrmgr.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 3 = wscui.cpl (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = wuaucpl.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 5 = Microsoft.ActionCenter
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 6 = Microsoft.BitlockerDriveEncryption
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 7 = Microsoft.WindowsDefender
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = crowe-chizek.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5124753B-F203-43E3-9BE8-9C547CC546DE}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\cw {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\cwt {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\aSinadin: DllName - (Sinadin.dll) - C:\Windows\System32\Sinadin.dll (Sophos Plc)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Authentication Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O30 - LSA: Security Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: nvstor64 - %systemroot%\system32\vxsvc.dll File not found
NetSvcs: oracle_load_balancer_60_client-forms6i - %systemroot%\system32\atimpab.dll File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/05/10 21:13:58 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/05/10 19:47:20 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Malwarebytes
[2012/05/10 19:46:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/10 19:38:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/05/10 19:27:08 | 000,040,328 | —- | C] (McAfee, Inc.) – C:\Windows\System32\HIPIS0e011b8.dll
[2012/05/10 18:47:48 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/05/10 18:44:29 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/05/10 18:44:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Local\Conduit
[2012/05/10 15:49:41 | 000,000,000 | —D | C] – C:\ProgramData\Roaming
[2012/05/09 15:26:52 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\INSTEC
[2012/05/04 11:34:06 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\Performance
[2012/05/03 10:44:44 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACL 9
[2012/05/03 10:44:43 | 000,000,000 | —D | C] – C:\ACL Data
[2012/05/03 10:43:00 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2012/04/18 07:35:18 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2012/04/15 22:51:50 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/04/15 22:45:18 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/15 22:43:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/04/15 22:26:23 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/04/15 22:11:29 | 000,000,000 | —D | C] – C:\ProgramData\B7E858A70004254C00079FC2B4EB238B
========== Files - Modified Within 30 Days ==========
[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 20:54:34 | 000,001,118 | —- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk
[2012/05/10 20:54:12 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/10 20:53:49 | 000,127,577 | —- | M] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 20:53:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2012/05/10 20:29:08 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/10 15:47:59 | 000,000,544 | —- | M] () – C:\Windows\ODBC.INI
[2012/05/10 11:32:51 | 000,389,760 | —- | M] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/04 13:44:16 | 000,414,800 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/03 10:44:44 | 000,002,077 | —- | M] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/05/03 00:17:08 | 000,143,008 | —- | M] (McAfee, Inc.) – C:\Windows\System32\KevlarSigs.dll
[2012/04/30 16:27:35 | 000,032,832 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/25 11:31:19 | 000,688,486 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/25 11:31:19 | 000,129,136 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/19 08:09:27 | 000,029,733 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | M] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | M] () – C:\Windows\System32\dds_trash_log.cmd
========== Files Created - No Company Name ==========
[2012/05/10 20:53:49 | 000,127,577 | —- | C] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 11:32:51 | 000,389,760 | —- | C] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/03 10:44:44 | 000,002,077 | —- | C] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/04/30 16:27:35 | 000,032,832 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/19 08:09:27 | 000,029,733 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | C] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | C] () – C:\Windows\System32\dds_trash_log.cmd
[2011/09/26 18:05:46 | 000,222,488 | —- | C] () – C:\Windows\System32\SPHook.dll
[2011/09/12 07:21:08 | 000,009,886 | —- | C] () – C:\Users\hillmd\AppData\Roaming\connector.dotm
[2011/08/30 15:06:10 | 000,002,080 | —- | C] () – C:\Windows\System32\drivers\SamSfPa.dat
[2011/08/30 11:48:31 | 000,000,544 | —- | C] () – C:\Windows\ODBC.INI
[2011/08/30 11:48:23 | 000,000,608 | —- | C] () – C:\Windows\tenkey.ini
[2011/08/09 16:38:36 | 000,002,658 | —- | C] () – C:\Windows\INSTAREA.DAT
[2011/08/09 16:16:38 | 000,039,472 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/03/06 19:45:44 | 000,213,332 | —- | C] () – C:\Windows\System32\igfcg600m.bin
[2011/03/06 19:45:44 | 000,145,804 | —- | C] () – C:\Windows\System32\igcompkrng600.bin
[2011/03/06 19:45:42 | 000,963,116 | —- | C] () – C:\Windows\System32\igkrng600.bin
[2011/03/06 19:13:20 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/03/06 19:11:06 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2011/03/06 19:07:58 | 000,094,208 | —- | C] () – C:\Windows\System32\IccLibDll.dll
[2011/02/02 23:29:52 | 001,816,324 | —- | C] () – C:\Windows\System32\nvcoproc.bin
[2011/01/18 10:35:42 | 000,030,893 | —- | C] () – C:\Windows\System32\drivers\Mixer.ini
[2010/11/20 16:29:34 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 16:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2010/10/28 12:27:48 | 000,001,816 | —- | C] () – C:\Windows\System32\drivers\Altmixer.ini
[2010/10/15 06:58:42 | 067,108,864 | —- | C] () – C:\Windows\SGBEKERNEL.BIN
[2010/10/15 06:58:42 | 000,000,512 | R— | C] () – C:\Windows\KrnlPatt.bin
[2010/10/15 01:28:02 | 000,000,512 | —- | C] () – C:\Windows\SGBEMBR.BIN
[2010/10/14 21:11:02 | 000,167,936 | —- | C] () – C:\Windows\System32\sptbasen.dll
[2010/10/14 17:40:00 | 000,118,784 | R— | C] () – C:\Windows\System32\SGNP11RSAn.dll
[2010/10/14 15:37:04 | 000,019,712 | —- | C] () – C:\Windows\System32\drivers\cedesm.sys
[2010/10/01 14:39:56 | 000,001,372 | —- | C] () – C:\Windows\System32\VoipUpdate.ini
========== LOP Check ==========
[2011/09/19 15:11:08 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\CognosRCP
[2011/08/30 12:01:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Colligo Networks
[2012/01/15 15:35:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Leadertech
[2011/08/30 11:44:57 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\ManageSoft Corp
[2011/08/30 14:27:28 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\MessageOne
[2012/05/10 19:38:32 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/01/02 21:37:44 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Tacori Bridal Collection
[2009/07/13 23:53:46 | 000,029,670 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 16:29:06 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/08/10 07:18:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/05/09 15:39:20 | 000,000,000 | —- | M] () – C:\dataset.log
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/08/30 12:19:21 | 000,067,049 | —- | M] () – C:\MGSPostWork.log
[2011/09/12 12:35:40 | 000,013,176 | —- | M] () – C:\Open Items Summary Report.xls
[2012/05/10 20:53:30 | 3130,220,544 | -HS- | M] () – C:\pagefile.sys
[2012/02/23 17:26:17 | 000,000,312 | —- | M] () – C:\Ping.txt
[2011/08/09 16:44:38 | 000,000,211 | —- | M] () – C:\setup.log
[2012/05/10 21:03:24 | 000,040,324 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.03.12_log.txt
[2012/05/10 21:05:17 | 000,077,580 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.04.59_log.txt
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:15:26 | 000,280,064 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
[2009/07/13 20:15:26 | 000,090,624 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2011/02/05 12:25:34 | 000,082,184 | —- | M] (Microsoft Corporation.) – C:\Windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
[2010/11/03 17:45:10 | 000,016,896 | —- | M] (Captaris, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\rfprint.dll
[2010/11/20 16:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2008/05/22 10:35:34 | 000,299,324 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1280x1024.jpg
[2008/05/22 10:33:48 | 000,299,480 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1400x990.jpg
[2008/05/22 10:32:36 | 000,124,577 | —- | M] () – C:\Windows\Crowe Wallpaper 1.jpg
[2008/05/22 10:30:08 | 000,326,220 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1280x1024.jpg
[2008/05/22 10:28:12 | 000,295,571 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1400x990.jpg
[2008/05/22 10:27:30 | 000,141,897 | —- | M] () – C:\Windows\Crowe Wallpaper 2.jpg
[2008/05/22 10:23:36 | 000,430,497 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1280x1024.jpg
[2008/05/22 10:22:34 | 000,403,300 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1400x990.jpg
[2008/05/22 10:21:32 | 000,366,234 | —- | M] () – C:\Windows\Crowe Wallpaper 3.jpg
[2008/05/22 10:20:26 | 000,210,931 | —- | M] () – C:\Windows\Crowe Wallpaper 4.jpg
[2006/02/28 12:41:04 | 000,031,565 | —- | M] () – C:\Windows\Unique2Big4.JPG
[2008/05/22 10:43:44 | 000,091,442 | —- | M] () – C:\Windows\Unique2Big4Crowe.JPG
< %systemroot%\*.png >
[2008/05/22 10:45:20 | 000,006,569 | —- | M] () – C:\Windows\Crowe_2c_White_Small.png
[2008/05/22 10:46:30 | 000,148,091 | —- | M] () – C:\Windows\Unique2Big4Crowe.PNG
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/04 08:42:08 | 000,000,221 | -HS- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAUShutdownOption" = 1
"NoAutoUpdate" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB20529$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:502D809E
< End of report >
Here is the report from Extras.Txt
OTL Extras logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS
Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3A273A4B-7E8C-4F16-8B50-060367B3135D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{B6D68FF2-5B6F-4570-B65B-6D0F4A31A067}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{18FF6F66-51DB-4292-8668-F92B3A1ADF67}" = dir=in | app=c:\program files\microsoft lync\ucmapi.exe |
"{23315F50-6557-49A4-B9D8-290F06FA98D0}" = protocol=6 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{273FADB2-C640-42AF-88DA-76D7B7BB5054}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2D443245-1CC4-41EC-B966-7B257939E0E4}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{3EDBA95D-0C14-46DB-9B19-9DE48FE8ACC6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{40446D02-B013-4F2E-84D7-1F45091199AE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{4CD225EE-ADC8-4871-BD82-BFED6CE09209}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5CB3D8B8-9674-4313-9A96-71DC2C85C7EA}" = dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{5D6F1B84-D5FC-422A-B1D6-C1DC0DAAC3B1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{5EC0DB8E-5C3C-4A46-A2BA-6278C27AFDD6}" = dir=in | app=c:\program files\colligo networks\colligo workgroup edition\colligo.exe |
"{680F3BCF-DE69-49FE-A1CE-D0DD81DF7926}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{6ADB6757-1A99-496B-8C71-57724809D4BA}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{71B98DBA-2899-419D-B5F5-376F304B1529}" = protocol=17 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{71D7CD66-ABC4-46C9-8F64-D54C5AA0B4A4}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{7B1DEDEF-2193-47D2-933A-E607753C81CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8D0F57C7-3264-4096-84B7-284E368D0F5C}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B3C09CC4-C96C-43AE-A571-7847FCCC0FE0}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B726BA07-0EC2-4165-9B22-D93C17C490A9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{CE08BEF9-2C30-4EC9-BFD1-2F385AB00B66}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{D64D9E2A-4C86-40A2-8F8F-325ED96831C7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{DECC7D06-1820-40BB-88F5-1D6E68022CB3}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{E87FF355-F7EF-46D4-8EF7-A75556B87CEE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{EAAB60CC-E615-4E13-96D6-130FDA2780C2}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{F100AF2C-6A14-4138-BDAA-5EC9A981C454}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC3F65-86EB-475E-881F-A5B1CF731320}" = McAfee SiteAdvisor Enterprise Plus
"{05227385-5073-46ED-9035-B1910E2613CC}" = DSmobileSCAN II
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{134774E3-4A0B-4139-815B-A7171CFA0B9C}" = Caseware Master Library 4.18.2011.00
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23D79730-EC1A-435E-83F8-AAEBFE5237B0}" = Adobe Flash Player 11 ActiveX
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2BB9B2F5-79E7-4220-B903-22E849100547}" = Microsoft Conferencing Add-in for Microsoft Office Outlook
"{2C2EA2C8-1B0F-4FEC-88E2-2B104E0507F3}" = Outlook Space On Demand
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{51D359FF-91CA-467B-967D-DEEDA013628A}" = Colligo Workgroup Edition
"{5395ACBD-D72C-4ECB-0AAC-1821D15D049A}" = SafeGuard PortProtector Client
"{55D1BF8E-EA8F-4969-82B9-B577010CFBCD}" = Microsoft Baseline Security Analyzer 2.1
"{56BD1B37-3934-4FA4-AE71-91DDB176C032}" = ACL 9
"{6267109C-50D2-4667-9FF6-03FB9A94A771}" = Sophos SafeGuard 5.50.8 Client
"{65545E0A-8288-43CF-8A68-E2F6CC8B469E}" = ManageSoft for managed devices
"{65E9B2E4-555F-441C-A8F7-B754FB1A010E}" = iPassConnect Crowe Connect
"{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"{6FED6E57-AA25-4597-9ED5-C66C02992066}" = Symantec NetBackup Desktop Agent
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774391DB-E12D-47AE-B4D2-46F7EB4ABDDC}" = McAfee Virtual Technician
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{846A8F6B-BEE5-4E94-9356-99B51E4D6F54}" = IBM Cognos Contributor Client
"{84BDCF3F-9FDE-4526-BBB4-3077CB8515EC}" = CaseWare Connector 2011
"{89DFC26C-9CB3-44E3-A799-80BCE8CE0BEB}" = Monarch 10.00
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B39A4EA-6E2C-4298-97AA-D8CDB0D91E7A}" = Outlook Secure Option
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{1E6AE8C5-CAC6-49B2-953B-3A4C8CDC1AD2}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00D1-0409-0000-0000000FF1CE}" = Microsoft Access database engine 2010 (English)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90C65E91-03C5-47B9-9EBF-72AAB0E7FDF3}" = ePO-MVT
"{94FB0978-D094-40C7-91D7-834D39220D4A}" = Crystal Reports XI Release 2 for Sage
"{9A235AC3-FA85-42D6-9B93-78A45E23596F}" = ScrewDrivers Client v4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA0DEE4-E84B-466F-9B96-FC255F3A929F}" = Integrated Camera TWAIN
"{9FCD6918-3DB5-45F2-B89F-654BB3233483}" = Sophos SafeGuard 5.50.0 Client Configuration
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A0E54EC6-EA51-4088-A6EE-BEF1D1D128AB}" = Lotus Notes 7.0.2
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-BA7E-000000000005}" = Adobe Acrobat X Standard - English, Français, Deutsch
"{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}" = Cisco Systems VPN Client 5.0.07.0290
"{B2CA6F37-1602-4823-81B5-0384B6888AA6}" = Integrated Camera Driver Installer Package Ver.1.1.0.1147
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Display Control Panel
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B332732A-4958-41DD-B439-DDA2D32753C5}" = McAfee Host Intrusion Prevention
"{B60C695C-EF2F-4826-9106-417ED7A68658}" = RightFax Product Suite - Client
"{B72B06E0-0C54-495F-896F-E3ED2905624A}" = Microsoft Junk E-mail Reporting Add-in
"{B87E6D2C-1365-4507-AA4F-15D007A64D1A}" = Dell Outlook Addin (x86)
"{C184AAA4-DFD6-44DF-B1E1-B2B9CC19EAA7}" = CaseWare Working Papers 2011
"{CDBAAE82-1725-4BDF-9770-69EA174318F1}" = Sophos SafeGuard Preinstall 5.50.0
"{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}" = McAfee VirusScan Enterprise
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D79036E3-A83E-41CD-9776-28853C258940}" = DSmobile 600
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DE91C193-2611-4BD3-A9F9-DF589C572565}" = McAfee Agent
"{E117B4A1-5C43-4ED8-8DE8-B45B58940191}" = Diskeeper 2011 Professional
"{E2C29C93-171B-40CF-949E-B27E3E6F9EDE}" = Becker's CPA Exam Review and PassMaster - 2011 Edition
"{E60146B0-C083-47BE-BD6B-EFA57AC8D9B1}" = RightFax Product Suite - Client
"{EA710A0A-BF5D-433C-8EB5-D17DC54CC298}" = Microsoft Office Live Meeting 2007
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F30B17C3-F398-4832-9176-6B2B52D9682A}" = IBM Cognos 8 Planning 8.4 Client Framework
"{F7797694-3F06-41C7-B9A0-C4BEF21ACE7A}" = Judy's TenKey ™ Installer
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe PDF IFilter 6.0" = Adobe PDF IFilter 6.0
"B2A - Windows Active X Files [Common] (ManageSoft)" = B2A - Windows Active X Files [Common] (via ManageSoft)
"CNXT_AUDIO_HDA" = Conexant 20672 SmartAudio HD
"Crowe Utilities [Common] (ManageSoft)" = Crowe Utilties [Common] (via ManageSoft)
"DTE Remote 2004" = DTE Remote 2004
"HP OfficeJet 100 Printer Drivers [Common] (ManageSoft)" = HP OfficeJet 100 Printer Drivers [Common] (via ManageSoft)
"HP450 [Common] (ManageSoft)" = HP450 Print Drivers [Common] (via ManageSoft)
"HP470 [Common] (ManageSoft)" = HP470 Print Drivers [Common] (via ManageSoft)
"InstallShield_{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"LENOVO.SMIIF" = Lenovo System Interface Driver
"McAfee GetSusp Malware Scanner [Common] (ManageSoft)" = McAfee GetSusp Malware Scanner [Common] (via ManageSoft)
"McAfee Stinger - Standard [Common] (ManageSoft)" = McAfee Stinger - Standard [Common] (via ManageSoft)
"MGS Config [Common] (ManageSoft)" = MGS Config [Common] (via ManageSoft)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Office 2010 Help Guides [Common] (ManageSoft)" = Microsoft Office 2010 Help Guides [Common] (via ManageSoft)
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Nvidia Config [Common] (ManageSoft)" = Nvidia Config [Common] (via ManageSoft)
"Office Update Inventory Tool [Common] (ManageSoft)" = Office Update Inventory Tool [Common] (via ManageSoft)
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OnScreenDisplay" = On Screen Display
"PaperPort Viewer [Common] (ManageSoft)" = PaperPort Viewer [Common] (via ManageSoft)
"Power Management Driver" = ThinkPad Power Management Driver
"Security Patch Settings for Microsoft Office [Common] (ManageSoft)" = Security Patch Settings for Microsoft Office [Common] (via ManageSoft)
"Security Patch Settings for Microsoft Windows [Common] (ManageSoft)" = Security Patch Settings for Microsoft Windows [Common] (via ManageSoft)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"WinZip" = WinZip
"WinZip [Common] (ManageSoft)" = WinZip 9.0 SR1 [Common] (via ManageSoft)
"Wireless Profiles Config [Common] (ManageSoft)" = Wireless Profiles Config [Common] (via ManageSoft)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ACL Update [HillMD] (ManageSoft)" = ACL Update [HillMD] (via ManageSoft)
"AOL Toolbar" = AOL Toolbar
"FAS 2012.1 DLL Patch [hillmd] (ManageSoft)" = FAS 2012.1 DLL Patch [hillmd] (via ManageSoft)
"Interactive Forms 2011 [HillMD] (ManageSoft)" = Interactive Forms 2011 [HillMD] (via ManageSoft)
"Lotus Notes Configuration [hillmd] (ManageSoft)" = Lotus Notes Configuration [HillMD] (via ManageSoft)
"MGS User Config [hillmd] (ManageSoft)" = MGS User Config [hillmd] (via ManageSoft)
"Microsoft Windows Desktop Shortcuts [HillMD] (ManageSoft)" = Microsoft Windows Desktop Shortcuts [HillMD] (via ManageSoft)
"Personalization_2 [hillmd] (ManageSoft)" = Personalization_2 [hillmd] (via ManageSoft)
"Symantec NetBackup Configuration Changes [hillmd] (ManageSoft)" = Symantec NetBackup Configuration Changes [HillMD] (via ManageSoft)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998
Error - 2/12/2012 6:17:37 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program vpngui.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 27ac Start Time:
01cce803bba98cad Termination Time: 120 Application Path: C:\Program Files\Cisco Systems\VPN
Client\vpngui.exe Report Id: 5d0bc9be-55c7-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:55:39 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2694 Start
Time: 01ccea5e9a381ee4 Termination Time: 6 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: c98b5480-5652-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:57:34 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1698 Start
Time: 01ccea5f915db115 Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 0e1873a3-5653-11e1-864e-c80953cf97d0
Error - 2/13/2012 10:59:17 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2044 Start
Time: 01ccea5fd2ff48de Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 4bc82321-5653-11e1-864e-c80953cf97d0
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 15569
Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 15569
[ ManageSoft Events ]
Error - 5/10/2012 9:26:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 9:26:11 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T202611] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:02:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:02:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210207] Failed to run "Update Schedule" - Program did not
execute successfully
Error - 5/10/2012 10:08:02 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:08:06 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210806] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:12:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1
Error - 5/10/2012 10:12:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211207] Failed to run "Apply Machine Policy" - Program did
not execute successfully
Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Installation Agent | ID = 65537
Description =
Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211542] Failed to run "Update Client Settings" - Program
did not execute successfully
[ System Events ]
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Cercsr6 service terminated with the following error: %%126
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Nidomainservice service terminated with the following error: %%126
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.
Error - 5/10/2012 9:53:47 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:53:51 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
luafv
Error - 5/10/2012 9:53:53 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:54:13 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 9:54:16 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
Error - 5/10/2012 10:11:01 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7030
Description = The ESET Service service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 5/10/2012 10:11:30 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The epfwwfpr service depends the following service: BFE. This service
might not be installed.
< End of report >