This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unusally high system mem being used [Solved]

64 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

  • click on Start … Run and type in cmd
  • in the window that appears, type in netsh winsock reset
  • press Enter.
Reboot your system and let me know if that has fixed it.
Hello satchfan. Now windows won t let me even try to connect to my wireless network. It says it can't connect, and says that windows is not set to automatically connect. To the network. This happens even when I manually select the network and try to connect. Thanks
You need to follow the previous instructions by logging on as an administrator. The message "the requested operation requires elevation" means you must have administrator status to make these changes.
Hello satchfan, The network wizard will not allow me to attempt to connect and says that it is not set to auto connect. When i went to the network wizard to set up the connection again it doesn't give me an option for wireless, the only option is for a modem setup" Did my wireless network card get deleted? Or is it a problem with windows zero configuration. Thank you.
Hello satchfan. When I went to reconfigure my network adapter i saw that DHCP client service is not running. Could that be the problem?

i saw that DHCP client service is not running. Could that be the problem?

You could try enabling it but it may not work.

There was a problem with ComboFix which I thought had been fixed but this has obviously been the problem..

If re-enabling the DHCP client service doesn;t work, running ComboFix again should solve the problem.


Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.

Let me know if that worked.

Satchfan
Hello satchfan. Running combo fix got the dns and dhcp running again. However it connected but with limited connectivity so I reset the winsock with the Cmd you gave me earlier and refreshed the tcp ip settings and now it connects fine. One question though. Will it get messed up again when I remove combo fix? Thank you.
Good that it seems to have fixed the problem.

Will it get messed up again when I remove combo fix?

Yes: it's OK to delete the files/program but not to uninstall it.

ComboFix will cause no problems by being on your computerbut just don't run it again without supervision.

If everything else is alright now I'll close this in 24 hours if I have not heard from you

Regards

Satchfan
hello satchfan.

the one computer is working now but there was a second on the network that was infected with the same trojan.

i will post the aswmbr log that found it, then the subsequent one after I deleted the infected file with file assassin in mbam.

i also ran OTL after aswmbr cleaned up the boot record.

here are the logs;


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-29 16:07:45
—————————–
16:07:45.075 OS Version: Windows 6.0.6002 Service Pack 2
16:07:45.075 Number of processors: 2 586 0xF0D
16:07:45.090 ComputerName: MAINBOARD UserName: studio
16:07:46.167 Initialize success
16:07:55.105 AVAST engine defs: 12052800
16:08:19.379 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-5
16:08:19.379 Disk 0 Vendor: Hitachi_HDT725040VLA360 V5COA7BA Size: 381554MB BusType: 3
16:08:19.395 Disk 0 MBR read successfully
16:08:19.395 Disk 0 MBR scan
16:08:19.410 Disk 0 unknown MBR code
16:08:19.410 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 372475 MB offset 63
16:08:19.441 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9075 MB offset 762830460
16:08:19.457 Disk 0 scanning sectors +781417665
16:08:19.519 Disk 0 scanning C:\Windows\system32\drivers
16:08:33.123 Service scanning
16:09:05.727 Modules scanning
16:09:12.996 Disk 0 trace - called modules:
16:09:13.027 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
16:09:13.542 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d26340]
16:09:13.542 3 CLASSPNP.SYS[8b7a08b3] -> nt!IofCallDriver -> [0x85b37f08]
16:09:13.558 5 acpi.sys[806996bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-5[0x85152b98]
16:09:14.837 AVAST engine scan C:\Windows
16:09:22.918 AVAST engine scan C:\Windows\system32
16:10:38.063 File: C:\Windows\system32\jureg.exe **INFECTED** Win32:SMSSend-IG [Trj]
16:15:48.565 AVAST engine scan C:\Windows\system32\drivers
16:16:08.253 AVAST engine scan C:\Users\studio
16:34:42.030 AVAST engine scan C:\ProgramData
16:47:40.969 Scan finished successfully
17:02:45.070 Verifying
17:02:55.085 Disk 0 Windows 600 MBR fixed successfully
17:03:06.333 Disk 0 MBR has been saved successfully to "C:\Users\studio\Desktop\MBR.dat"
17:03:06.348 The log file has been saved successfully to "C:\Users\studio\Desktop\aswMBR.txt"




here is the log after the fix


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-06-15 00:27:04
—————————–
00:27:04.961 OS Version: Windows 6.0.6002 Service Pack 2
00:27:04.961 Number of processors: 2 586 0xF0D
00:27:04.976 ComputerName: MAINBOARD UserName: studio
00:27:09.453 Initialize success
00:27:11.107 AVAST engine defs: 12030600
00:28:01.760 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-5
00:28:01.760 Disk 0 Vendor: Hitachi_HDT725040VLA360 V5COA7BA Size: 381554MB BusType: 3
00:28:01.791 Disk 0 MBR read successfully
00:28:01.791 Disk 0 MBR scan
00:28:01.807 Disk 0 Windows VISTA default MBR code
00:28:01.807 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 372475 MB offset 63
00:28:01.838 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9075 MB offset 762830460
00:28:01.854 Disk 0 scanning sectors +781417665
00:28:01.916 Disk 0 scanning C:\Windows\system32\drivers
00:28:12.961 Service scanning
00:28:40.542 Modules scanning
00:28:49.075 Disk 0 trace - called modules:
00:28:49.091 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
00:28:49.106 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865a5968]
00:28:49.122 3 CLASSPNP.SYS[8b7a28b3] -> nt!IofCallDriver -> [0x85153918]
00:28:49.122 5 acpi.sys[806966bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-5[0x8514b030]
00:28:50.198 AVAST engine scan C:\Windows
00:28:54.738 AVAST engine scan C:\Windows\system32
00:32:47.303 AVAST engine scan C:\Windows\system32\drivers
00:33:09.564 AVAST engine scan C:\Users\studio
01:04:15.090 AVAST engine scan C:\ProgramData
01:20:42.492 Scan finished successfully
09:04:22.599 Disk 0 MBR has been saved successfully to "C:\Users\studio\Desktop\MBR.dat"
09:04:22.615 The log file has been saved successfully to "C:\Users\studio\Desktop\aswMBRnew.txt"






here is the OTL log :


OTL logfile created on: 6/25/2012 3:36:12 PM - Run 1
OTL by OldTimer - Version 3.2.51.0 Folder = C:\Users\studio\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 82.37% Memory free
6.69 Gb Paging File | 6.39 Gb Available in Paging File | 95.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.75 Gb Total Space | 168.34 Gb Free Space | 46.28% Space Free | Partition Type: NTFS
Drive D: | 8.86 Gb Total Space | 0.94 Gb Free Space | 10.64% Space Free | Partition Type: NTFS
Drive G: | 7.76 Gb Total Space | 2.14 Gb Free Space | 27.60% Space Free | Partition Type: FAT32

Computer Name: MAINBOARD | User Name: studio | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - C:\Users\studio\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (QDWYCN) – C:\Users\studio\AppData\Local\Temp\QDWYCN.exe File not found
SRV - (vToolbarUpdater11.0.2) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (ATKFUSService) – C:\Windows\System32\ATKFUSService.exe (ASUSTeK COMPUTER INC.)
SRV - (ASDR) – C:\Windows\System32\ASDR.exe ()
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (ASWLCCSvc) – C:\Program Files\ASUS\WLAN Card Utilities\ASWLCCSVC.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Remote UI Service) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (MCLServiceATL) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (ISSM) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\issm.exe (Intel® Corporation)
SRV - (AlertService) Intel® – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (DQLWinService) – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (M1 Server) Intel® Viiv™ – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (IntelDHSvcConf) – C:\Program Files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (PcdrNdisuio) – system32\DRIVERS\pcdrndisuio.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mbr) – C:\Users\studio\AppData\Local\Temp\mbr.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (EraserUtilDrvI9) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (Afc) – system32\drivers\Afc.sys File not found
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120613.007\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120529.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120529.002\NAVENG.SYS (Symantec Corporation)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120531.001\BHDrvx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (EIO) – C:\Windows\System32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (SYMTDIv) – C:\Windows\System32\drivers\NIS\1207020.003\symtdiv.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1207020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\System32\drivers\NIS\1207020.003\srtspx.sys (Symantec Corporation)
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdLH3.sys (Advanced Micro Devices)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1207020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1207020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1207020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (SeratoUsb) – C:\Windows\System32\drivers\SeratoUsb.sys (Cristalink Ltd)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (IOMap) – C:\Windows\System32\drivers\IOMap.sys (ASUSTeK Computer Inc.)
DRV - (netr28u) – C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (vpnva) – C:\Windows\System32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (netr73) – C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (atkdisplf) – C:\Windows\System32\drivers\ATKDispLowFilter.sys (ASUSTeK Computer Inc.)
DRV - (asusgsb) – C:\Windows\System32\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (RT73) – C:\Windows\System32\drivers\Dr71WU.sys (Ralink Technology Corp.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{15C7739E-0732-4437-B45F-3D8CC68D56A5}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2391419
IE - HKLM\..\SearchScopes\{37A15818-308C-426B-97C7-EEBCBD758318}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDUS7
IE - HKLM\..\SearchScopes\{81795BDF-2A51-4B45-AAE0-9B53A622C002}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKLM\..\SearchScopes\{A29C6A80-3601-4435-997A-8329EB362F29}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{15C7739E-0732-4437-B45F-3D8CC68D56A5}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2391419
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{37A15818-308C-426B-97C7-EEBCBD758318}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDUS7
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{81795BDF-2A51-4B45-AAE0-9B53A622C002}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={BE12785…mp;d=2012-05-27 19:35:39&v;=11.0.0.9&sap;=dsp&q;={searchTerms}
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{A29C6A80-3601-4435-997A-8329EB362F29}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvdt
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…o=US&ver;=18
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Bd96a43a4-c017-4245-965b-100d69661b34%7D∣=e59b2e509e7447d0b70dd15426258be3-d445f58d8d92bde6426e946e4e8a330150dfd340&ds;=AVG&v;=11.0.0.9⟨=en≺=fr&d;=2012-05-27%2019%3A35%3A39&sap;=ku&q;="
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\studio\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\studio\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/15 21:19:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2012/02/03 00:35:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_9_4 [2012/06/25 14:48:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/05/27 19:35:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/27 19:33:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.0.0.9\ [2012/05/27 19:35:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/04 11:24:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/21 18:10:52 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/15 21:19:40 | 000,000,000 | —D | M]

[2012/04/04 11:25:10 | 000,000,000 | —D | M] (No name found) – C:\Users\studio\AppData\Roaming\Mozilla\Extensions
[2012/04/17 16:52:26 | 000,000,000 | —D | M] (No name found) – C:\Users\studio\AppData\Roaming\Mozilla\Firefox\Profiles\0vp4vw24.default\extensions
[2012/04/05 15:06:02 | 000,002,470 | —- | M] () – C:\Users\studio\AppData\Roaming\Mozilla\Firefox\Profiles\0vp4vw24.default\searchplugins\safesearch.xml
[2012/06/10 22:55:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/05/27 19:33:44 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/05/27 19:35:59 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2012/05/27 19:35:53 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\PROGRAMDATA\AVG SECURE SEARCH\11.0.0.9
File not found (No name found) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\COFFPLGN_2011_7_7_5
[2012/02/03 00:35:30 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPLGN
[2012/04/17 16:52:26 | 000,634,964 | —- | M] () (No name found) – C:\USERS\STUDIO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0VP4VW24.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/03/12 21:39:39 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/06 08:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2012/04/19 13:31:49 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/06 08:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/05/27 19:35:30 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/12 21:38:32 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/12 21:38:32 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\studio\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\studio\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\studio\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\studio\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\studio\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: AVG Do Not Track = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Gmail = C:\Users\studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()
O3 - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\CenterAgent.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3108194886-47130466-2820981335-1002\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1858F427-08FE-4B18-9596-68E5F934F04B}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20F5B54C-1F12-4538-A26C-E5DAAF827F94}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EC69410-96BC-4444-AA61-970798B56C79}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{46B9F81B-C634-4C69-8838-70783921BC73}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C0834E4-86CA-4F34-AAC0-A8059F1A10CF}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8C9693F-EA40-4413-9077-534083A88DE2}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D240F05E-4B63-4DAD-A987-ED1FA7B7FAF3}: DhcpNameServer = 192.168.1.254 [removed]
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\studio\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Users\studio\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/11 18:39:50 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{1af0c7ee-b3ef-11e1-835a-001d60c16210}\Shell - "" = AutoRun
O33 - MountPoints2\{1af0c7ee-b3ef-11e1-835a-001d60c16210}\Shell\AutoRun\command - "" = G:\Setup.exe
O33 - MountPoints2\{242657d7-7c38-11e0-bdc8-001d60c16210}\Shell - "" = AutoRun
O33 - MountPoints2\{242657d7-7c38-11e0-bdc8-001d60c16210}\Shell\AutoRun\command - "" = J:\PcOptions.exe
O33 - MountPoints2\{a03e4d84-ae05-11e0-8727-001d60c16210}\Shell\AutoRun\command - "" = K:\Start.exe
O33 - MountPoints2\{a03e4d84-ae05-11e0-8727-001d60c16210}\Shell\Install\Command - "" = K:\Start.exe
O33 - MountPoints2\{af3d04b6-d3b0-11dc-85fa-001d60c16210}\Shell - "" = AutoRun
O33 - MountPoints2\{af3d04b6-d3b0-11dc-85fa-001d60c16210}\Shell\AutoRun\command - "" = E:\COGLAB.exe
O33 - MountPoints2\{d04f496b-6686-11e0-8b7f-001d60c16210}\Shell - "" = AutoRun
O33 - MountPoints2\{d04f496b-6686-11e0-8b7f-001d60c16210}\Shell\AutoRun\command - "" = J:\PcOptions.exe
O33 - MountPoints2\{e42d9766-21aa-11e0-aedf-001d60c16210}\Shell - "" = AutoRun
O33 - MountPoints2\{e42d9766-21aa-11e0-aedf-001d60c16210}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 60 Days ==========

[2012/06/25 15:34:50 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\studio\Desktop\OTL.exe
[2012/06/18 13:57:10 | 000,607,260 | R— | C] (Swearware) – C:\Users\studio\Desktop\dds.scr
[2012/06/17 22:29:55 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2012/06/17 22:29:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2012/06/17 22:29:44 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2012/06/17 15:09:59 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/06/17 15:09:57 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/06/13 22:08:20 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/06/12 14:51:19 | 000,000,000 | —D | C] – C:\ProgramData\MemeoCommon
[2012/06/12 13:50:00 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\Memeo
[2012/06/12 13:47:19 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\Seagate
[2012/06/12 13:46:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard
[2012/06/12 13:44:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Memeo
[2012/06/12 13:44:23 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Memeo
[2012/06/12 13:44:13 | 000,000,000 | —D | C] – C:\Program Files\Memeo
[2012/06/12 13:41:59 | 000,000,000 | —D | C] – C:\Program Files\Seagate
[2012/06/12 13:41:04 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\Leadertech
[2012/06/10 17:21:38 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/06/10 17:17:58 | 002,127,960 | —- | C] (Kaspersky Lab ZAO) – C:\Users\studio\Desktop\TDSSKiller.exe
[2012/06/10 16:27:45 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/06/10 16:27:45 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/05/29 16:01:52 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\studio\Desktop\aswMBR.exe
[2012/05/28 13:01:15 | 000,000,000 | —D | C] – C:\scanning and virus protection
[2012/05/27 21:36:20 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2012/05/27 19:40:44 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\AVG2012
[2012/05/27 19:36:24 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Local\AVG Secure Search
[2012/05/27 19:36:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/05/27 19:35:37 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/05/27 19:35:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/05/27 19:35:32 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/05/27 19:34:44 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/05/27 19:33:16 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/05/27 19:33:15 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/05/27 19:33:15 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2012/05/27 19:31:13 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/05/27 19:26:07 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/05/16 11:55:54 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/16 11:55:54 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/16 11:55:54 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/16 11:55:54 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/16 11:55:54 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/16 11:53:43 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/16 11:53:43 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/16 11:53:42 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/04 12:46:47 | 000,033,280 | —- | C] (ASUSTeK Computer Inc.) – C:\Windows\System32\drivers\IOMap.sys
[2012/05/03 19:29:38 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Roaming\Tific
[2012/05/03 19:29:35 | 000,000,000 | —D | C] – C:\Users\studio\AppData\Local\Symantec

========== Files - Modified Within 60 Days ==========

[2012/06/25 15:04:07 | 000,603,516 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/06/25 15:04:07 | 000,103,586 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/06/25 14:59:47 | 000,002,525 | —- | M] () – C:\Users\studio\Desktop\HiJackThis.lnk
[2012/06/25 14:57:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/25 14:50:19 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{7CE00273-40F6-4033-8F7F-9605411E0533}.job
[2012/06/25 14:48:31 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/25 14:48:31 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/24 16:41:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/24 16:37:11 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3108194886-47130466-2820981335-1002UA.job
[2012/06/24 10:37:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3108194886-47130466-2820981335-1002Core.job
[2012/06/22 01:28:26 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\studio\Desktop\OTL.exe
[2012/06/21 22:25:57 | 000,002,206 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/06/21 22:25:36 | 002,537,656 | —- | M] () – C:\Windows\System32\drivers\NIS\1207020.003\Cat.DB
[2012/06/17 22:29:48 | 000,000,878 | —- | M] () – C:\Users\studio\Desktop\SpywareBlaster.lnk
[2012/06/17 11:42:33 | 207,452,352 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/06/16 21:28:14 | 000,607,260 | R— | M] (Swearware) – C:\Users\studio\Desktop\dds.scr
[2012/06/15 09:04:22 | 000,000,512 | —- | M] () – C:\Users\studio\Desktop\MBR.dat
[2012/06/13 22:16:52 | 000,339,266 | —- | M] () – C:\Users\studio\Documents\cc_20120613_221530registry_backup.reg
[2012/06/13 22:08:30 | 000,000,806 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/12 13:46:03 | 000,001,076 | —- | M] () – C:\Users\Public\Desktop\Seagate Dashboard.lnk
[2012/06/10 18:28:26 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/06/10 13:32:10 | 002,127,960 | —- | M] (Kaspersky Lab ZAO) – C:\Users\studio\Desktop\TDSSKiller.exe
[2012/06/07 19:08:38 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\NIS\1207020.003\isolate.ini
[2012/05/29 15:36:54 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\studio\Desktop\aswMBR.exe
[2012/05/28 14:13:43 | 000,000,680 | —- | M] () – C:\Users\studio\AppData\Local\d3d9caps.dat
[2012/05/28 12:49:27 | 000,001,142 | —- | M] () – C:\Users\studio\Documents\scan may 29.csv
[2012/05/28 01:26:08 | 000,026,952 | —- | M] () – C:\Users\studio\Documents\virus logs may 29 2012.csv
[2012/05/27 23:18:05 | 000,000,326 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForstudio.job
[2012/05/27 19:43:21 | 062,880,403 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/05/27 19:36:02 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/27 18:42:28 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/27 18:42:28 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/27 18:26:18 | 000,002,011 | —- | M] () – C:\Users\studio\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/05/27 18:26:17 | 000,002,049 | —- | M] () – C:\Users\studio\Desktop\Google Chrome.lnk
[2012/05/16 14:25:44 | 000,366,952 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/17 22:29:48 | 000,000,878 | —- | C] () – C:\Users\studio\Desktop\SpywareBlaster.lnk
[2012/06/17 15:09:59 | 000,002,525 | —- | C] () – C:\Users\studio\Desktop\HiJackThis.lnk
[2012/06/17 11:42:33 | 207,452,352 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/06/13 22:15:53 | 000,339,266 | —- | C] () – C:\Users\studio\Documents\cc_20120613_221530registry_backup.reg
[2012/06/13 22:08:30 | 000,000,806 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/12 13:46:03 | 000,001,076 | —- | C] () – C:\Users\Public\Desktop\Seagate Dashboard.lnk
[2012/05/29 17:03:06 | 000,000,512 | —- | C] () – C:\Users\studio\Desktop\MBR.dat
[2012/05/28 12:49:26 | 000,001,142 | —- | C] () – C:\Users\studio\Documents\scan may 29.csv
[2012/05/28 01:26:08 | 000,026,952 | —- | C] () – C:\Users\studio\Documents\virus logs may 29 2012.csv
[2012/05/27 19:43:21 | 062,880,403 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/05/27 19:36:00 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/04/23 22:20:05 | 015,573,633 | —- | C] () – C:\Users\studio\AppData\Roaming\SMRBackup250.dat
[2012/02/11 15:59:59 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\asrussian.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\askorean.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\asjapan.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\asgerman.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\asfrench.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\aseng.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\ASCHT.dll
[2012/02/11 15:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\aschs.dll
[2012/02/11 15:15:05 | 000,761,856 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2012/02/11 15:15:05 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2012/02/11 14:57:29 | 000,003,929 | —- | C] () – C:\Windows\System32\atipblag.dat
[2012/02/11 13:27:49 | 000,000,680 | —- | C] () – C:\Users\studio\AppData\Local\d3d9caps.dat
[2011/06/18 14:11:32 | 000,000,531 | —- | C] () – C:\Windows\eReg.dat
[2011/05/25 00:44:26 | 000,059,904 | —- | C] () – C:\Windows\System32\OVDecode.dll
[2011/05/24 07:24:16 | 000,037,376 | —- | C] () – C:\Windows\System32\atitmpxx.dll
[2011/04/20 21:42:22 | 000,002,384 | —- | C] () – C:\Users\studio\home.html
[2011/04/19 21:30:06 | 000,233,765 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2011/04/10 22:50:44 | 000,001,025 | —- | C] () – C:\Windows\System32\sysprs7.dll
[2011/04/10 22:50:44 | 000,000,205 | —- | C] () – C:\Windows\System32\lsprst7.dll
[2011/03/15 21:03:28 | 000,208,174 | —- | C] () – C:\Windows\hpoins43.dat
[2011/01/23 17:02:26 | 000,026,624 | —- | C] () – C:\Users\studio\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/10 03:45:32 | 000,102,744 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2010/08/06 14:27:42 | 000,013,931 | —- | C] () – C:\Windows\System32\RaCoInst.dat
[2010/07/13 03:05:29 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/07/12 04:39:50 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/12 04:39:49 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll

========== LOP Check ==========

[2010/12/29 12:46:57 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Ableton
[2012/05/27 19:40:44 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\AVG2012
[2012/06/13 22:13:26 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Azureus
[2011/03/09 12:20:22 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\CoffeeCup Software
[2012/06/13 22:13:30 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\DAEMON Tools Lite
[2011/04/10 23:04:32 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Eclipse
[2011/03/26 13:44:31 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\FileZilla
[2012/06/12 13:41:04 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Leadertech
[2012/06/12 13:50:00 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Memeo
[2012/06/12 13:47:19 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Seagate
[2011/01/05 19:03:11 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Sony
[2012/05/03 19:29:38 | 000,000,000 | —D | M] – C:\Users\studio\AppData\Roaming\Tific
[2010/12/28 14:26:39 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\Ableton
[2008/11/20 15:11:29 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\funkitron
[2010/09/06 06:27:07 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\PlayFirst
[2008/01/18 19:34:11 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\Snapfish
[2008/06/09 23:30:18 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\Template
[2007/11/26 22:20:53 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\WildTangent
[2008/02/04 23:22:50 | 000,000,000 | —D | M] – C:\Users\Tricia\AppData\Roaming\WinBatch
[2012/06/24 20:12:45 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/25 14:50:19 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{7CE00273-40F6-4033-8F7F-9605411E0533}.job

========== Purity Check ==========



< End of report >



and the extra log from otl:



OTL Extras logfile created on: 6/25/2012 3:36:12 PM - Run 1
OTL by OldTimer - Version 3.2.51.0 Folder = C:\Users\studio\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 82.37% Memory free
6.69 Gb Paging File | 6.39 Gb Available in Paging File | 95.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.75 Gb Total Space | 168.34 Gb Free Space | 46.28% Space Free | Partition Type: NTFS
Drive D: | 8.86 Gb Total Space | 0.94 Gb Free Space | 10.64% Space Free | Partition Type: NTFS
Drive G: | 7.76 Gb Total Space | 2.14 Gb Free Space | 27.60% Space Free | Partition Type: FAT32

Computer Name: MAINBOARD | User Name: studio | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3108194886-47130466-2820981335-1002\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1D2BB397-C856-4AE5-9DDB-84782B01D63D}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{237E5389-E23C-478D-AB0D-2DBBFDA1BB8E}" = rport=138 | protocol=17 | dir=out | app=system |
"{26D6EB31-5093-4E6A-B517-28F0EF593F03}" = rport=137 | protocol=17 | dir=out | app=system |
"{2ABB7AA0-89A9-4CD8-B12D-259F0AA20537}" = lport=2869 | protocol=6 | dir=in | app=system |
"{472D558A-45CA-4823-82F9-F3B9899A924B}" = rport=139 | protocol=6 | dir=out | app=system |
"{4BF01407-4C1C-4ADE-BD17-BA56492A56B4}" = lport=138 | protocol=17 | dir=in | app=system |
"{61C7E100-2218-4F7F-8967-B2751B9F33EA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7A03D072-8423-4600-9E87-E039754D3084}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7A403FDD-6A18-46EC-8377-08E5D72B98F4}" = rport=445 | protocol=6 | dir=out | app=system |
"{7CCD1F64-ABC9-4E17-B251-47E8C229661B}" = lport=9442 | protocol=17 | dir=in | name=intel® viiv™ media server discovery |
"{8CEF6059-89A3-4412-B46A-71584B100F74}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{90EDA806-0DF5-43BF-AB5C-8FA1FE09AAC5}" = lport=137 | protocol=17 | dir=in | app=system |
"{B5346410-6087-4CB8-A4FA-6A8A85673B4A}" = lport=445 | protocol=6 | dir=in | app=system |
"{F1617C11-50A5-4207-A4FF-D223824CB22C}" = lport=1900 | protocol=17 | dir=in | name=intel® viiv™ media server upnp discovery |
"{F548D1B5-0298-4AC4-945A-C7FCD227FF29}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D2DD59A-371A-4360-8630-592595CE09A1}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe |
"{0FABD660-F6B8-444B-B164-D096B63CB5C0}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{11578024-9501-4B3C-9EDC-A363FB3E7B37}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{18000C83-DDE7-45A7-8400-5182DAE12145}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{1AA25E93-F724-4519-9BBC-825D63ADCC86}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1F06AFE9-19A4-4744-B70C-7A4CE467BDC9}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{27D4A20B-F6CB-4DD7-AFE1-D7A0B236A37D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{2863B925-6C5C-4C5F-ABDC-D6EB625683DE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2D86C32F-40F6-4251-BF89-0B99991FE00A}" = dir=in | app=e:\setup\hpznui01.exe |
"{337FA63D-1C64-45F5-89C4-5347031DEBB2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{369AC3FE-A3C2-47FC-9C6B-5FAB478CB017}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{37F6CE24-51BD-450C-B692-A1444CAF16E7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{39219979-9410-4E8B-A454-FD0D7B523DC9}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{4968AABF-529A-43D6-8F31-59CE07D97168}" = dir=in | app=c:\program files\seagate\seagate dashboard\hipservagent\hipservagent.exe |
"{4BFCC7B7-BBD6-454F-8B1B-5890239EEDCC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{52090AA7-EA8D-4D81-8B69-A7D0ADBFD1EE}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{5316F94B-F35A-4177-A366-7D3E19D3C972}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{556F7F9E-575B-4BE3-9A4A-79654B3B26C0}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{595FD6CD-D95F-4645-B045-368C6D443A11}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{6991AEA9-5D0C-45BF-AAC0-12DF0DA184AF}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe |
"{6A3D49B4-4120-41B8-B9E7-9697AD90D5EE}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{6E845F7C-A560-46F4-A919-739851CABFA3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{781332C7-33A2-4550-BC39-06CDF7F43F24}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7AD925F2-9CB3-4A1B-AD6C-37AD54932EBB}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe |
"{7B301E65-88BE-45CE-AA7D-F97CFDCF6EFC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{8728AD43-0FAC-461F-AA44-7B75ADE8AD60}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe |
"{91FADFE6-1916-4886-AA30-CA884A664759}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe |
"{98E5FEB8-40FD-48C3-9A51-83EC321DB353}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{A38CA596-D157-4A0A-ABBF-444F2F44D4C2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{A4D487F5-E5C0-4A1E-86DA-B36444678613}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{A59E0CDF-DED3-4C52-A838-59FAB677216A}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{AFA13D98-391F-4CDF-8DC8-32BED6D0E200}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{BAEA8F3F-E7F2-42BC-A5A7-846CEF91B72C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{CCC7F21A-6743-45CB-9FFF-DD15D49BA8C3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{CE276C8D-E817-47DD-85BA-9F566CDCD353}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{D17F272F-0FF2-42F2-A97B-94D868D7735D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E007D9F5-039C-4701-AC46-32A0CE8819F9}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{E24E8410-0BA6-44A2-BBD8-0DE571FAE314}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E62E09E0-9C00-4084-8A7D-24C3B0861C50}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{EA158527-A016-4591-8195-1E73DBFF4D0E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{EC007B9C-4922-46AC-B595-D9B5B93CF395}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{ECC3267D-DF47-48B5-8B71-515B348A4DCE}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe |
"{EF014346-93CC-4876-B95C-3461C0A9A3B4}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{F3E20EAB-C7BB-4320-91C1-EAD8A1D0164C}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{F7D7B489-897A-4FB4-9E0E-9A58EA344E7E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FDEFBFAA-EA94-4053-8E25-BC9F274B8923}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"TCP Query User{3FAA679A-949B-4F94-BCF4-2B887DF738D8}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{CCAACCA9-ED2C-4421-B9D7-D2CD9D02C05F}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{F1CD1470-604A-49BA-8421-2D694A91CB4F}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02F6993D-B763-4F40-8F93-2A9CD97586E3}" = Microsoft IntelliType Pro 6.3
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{06C43FAA-7226-41EF-A05E-9AE0AA849FFE}" = IBM SPSS Statistics 19
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A80329D-1B59-4F10-8D1D-924C59B2840B}" = ShufflePlusVLOI
"{0B6AC7AE-2C15-4F1F-9179-24BA055F82E7}" = SPSS Inc. Data Access Pack 6.0 for Windows
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{14AF024E-2E3B-49D0-A175-D1C1A06B155A}" = muvee autoProducer 6.0
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1B7710D4-9D75-D5E5-4B6D-40F471E70398}" = HydraVision
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}" = QuickTax 2007
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{287EAC0F-6C96-4712-97A6-958510872CBB}" = Utility
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E46D5AD-6B32-78E0-61E1-12A51284A21F}" = ATI Catalyst Install Manager
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2EBA5473-558B-462C-AEE4-FE50FA799F2A}" = Mouse Driver
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{364B2826-EEB6-A31B-F25B-5CBB78273414}" = CCC Help English
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F7423FB-8E9A-4EF4-BB8A-EAD6314CCB3D}" = Scratch Live 2.2.0 (22033)
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{471CE240-A1E5-56ED-C3FE-6A9BF4FB198B}" = ATI AVIVO Codecs
"{50B93225-3F76-F555-27A2-A1EAEC83C527}" = Catalyst Control Center InstallProxy
"{537DB9D6-1AB1-4CE9-8DE7-312256B49A98}" = PS_AIO_06_C4700_SW_Min
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57AC79C8-157E-403A-A8D0-DD74EF71BAE2}" = Catalyst Control Center - Branding
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{5F64E152-51C1-47B4-BEA8-007D73C7460F}" = Cisco AnyConnect VPN Client
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66A9D30D-1464-4C7F-B2F3-507DADAF2595}" = Microsoft IntelliPoint 6.3
"{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}" = Sony Sound Forge 9.0
"{68550918-63B5-4762-85CB-3C160AA4B213}" = HP Photosmart C4700 All-in-One Driver Software 14.0 Rel. 6
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B}" = Intel® Viiv™ Software
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79AA4C3A-F13F-1585-43D9-A9C3813FB9B4}" = ccc-utility
"{7F88C9E5-12BD-404F-AC6A-108BAAC9B708}" = ASUS Gamer OSD
"{809D7E6D-915D-4EAD-821F-E13D93F37161}" = ASUS Smart Doctor
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8334930A-9405-467B-9498-1EBC1878A09D}" = Catalyst Control Center
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CC928F6-93A2-D49D-E253-532C2FF053A1}" = Catalyst Control Center Profiles Desktop
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8F722FA9-B994-4C9B-B292-FD32D6206EDF}" = ASUS WLAN Card Utilities/Driver
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90157C5D-D791-4D36-8C2B-7553DC01D601}" = ASUS VGA Driver
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{979D10B8-4D39-4CA5-9A53-60BFF2A4DD79}" = IBM SPSS Statistics 19 Data File Driver - Service Client
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF9CA86D-83FA-C143-F9C8-EAB535B8B78C}" = Catalyst Control Center Localization All
"{B5978DF3-8A04-4F22-AF67-8CCE52E04B13}" = C4700
"{B6ADA0E4-9451-43EB-B86E-878AD9E68D4F}" = LightScribe [removed]
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C25215FC-5900-48B0-B93C-8D3379027312}" = PASW Statistics Student Version 18.0
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}" = Sony Noise Reduction Plug-In 2.0e
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F51C2A69-D2E2-4813-AAD7-618D2BF85DFD}" = AVG 2012
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVG" = AVG 2012
"BC Divorce Forms (Joint)08-1" = BC Divorce Forms (Joint)
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Soft Data Fax Modem with SmartCP
"CoffeeCup HTML Editor" = CoffeeCup HTML Editor
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photo Creations" = HP Photo Creations
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"HP-LaserJet 1020 series" = LaserJet 1020 series
"InstallShield_{809D7E6D-915D-4EAD-821F-E13D93F37161}" = ASUS Smart Doctor
"Intel® Configuration Center" = Intel® Viiv™ Software
"Live 8.1.1" = Live 8.1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MIDI File Splitter" = MIDI File Splitter
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"NIS" = Norton Internet Security
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PROSet" = Intel® PRO Network Connections Drivers
"Rhapsody" = Rhapsody
"Shop for HP Supplies" = Shop for HP Supplies
"SpywareBlaster_is1" = SpywareBlaster 4.6
"VLC media player" = VLC media player 1.1.11
"WBFS Manager 3.0" = WBFS Manager 3.0
"WildTangent hp Master Uninstall" = My HP Games
"WinRAR archiver" = WinRAR archiver
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3108194886-47130466-2820981335-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"FileZilla Client" = FileZilla Client 3.3.5.1
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/30/2012 3:54:52 PM | Computer Name = Mainboard | Source = Windows Search Service | ID = 3100
Description =

Error - 5/30/2012 3:55:03 PM | Computer Name = Mainboard | Source = Windows Search Service | ID = 3083
Description =

Error - 5/30/2012 3:55:03 PM | Computer Name = Mainboard | Source = Windows Search Service | ID = 3083
Description =

Error - 5/30/2012 3:55:03 PM | Computer Name = Mainboard | Source = Windows Search Service | ID = 3083
Description =

Error - 5/30/2012 3:57:04 PM | Computer Name = Mainboard | Source = Windows Search Service | ID = 3100
Description =

Error - 6/8/2012 3:01:14 PM | Computer Name = Mainboard | Source = EventSystem | ID = 4609
Description =

Error - 6/14/2012 12:39:59 AM | Computer Name = Mainboard | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.0.6002.18005 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 11d0 Start Time: 01cd482825962c38 Termination Time: 31

Error - 6/14/2012 12:40:09 AM | Computer Name = Mainboard | Source = Application Hang | ID = 1002
Description = The program MemeoDashboard.exe version 1.0.0.0 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1098 Start Time: 01cd48dc9158aba8 Termination Time: 0

Error - 6/22/2012 1:26:02 AM | Computer Name = Mainboard | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/25/2012 5:58:46 PM | Computer Name = Mainboard | Source = EventSystem | ID = 4609
Description =

[ Cisco AnyConnect VPN Client Events ]
Error - 6/11/2012 1:57:58 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331650
Description = Termination reason code 9: Client PC is shutting down.

Error - 6/11/2012 1:57:58 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331649
Description = Function: CVpnMgr::processEvents Return code: 0 File: .\MainThread.cpp
Line:
997 Description: fatal error, stopping service

Error - 6/14/2012 12:44:05 AM | Computer Name = Mainboard | Source = vpnagent | ID = 50331650
Description = Termination reason code 9: Client PC is shutting down.

Error - 6/14/2012 12:44:05 AM | Computer Name = Mainboard | Source = vpnagent | ID = 50331649
Description = Function: CVpnMgr::processEvents Return code: 0 File: .\MainThread.cpp
Line:
997 Description: fatal error, stopping service

Error - 6/14/2012 11:41:22 AM | Computer Name = Mainboard | Source = vpnagent | ID = 50331650
Description = Termination reason code 9: Client PC is shutting down.

Error - 6/14/2012 11:41:22 AM | Computer Name = Mainboard | Source = vpnagent | ID = 50331649
Description = Function: CVpnMgr::processEvents Return code: 0 File: .\MainThread.cpp
Line:
997 Description: fatal error, stopping service

Error - 6/17/2012 2:39:22 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331650
Description = Termination reason code 9: Client PC is shutting down.

Error - 6/17/2012 2:39:22 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331649
Description = Function: CVpnMgr::processEvents Return code: 0 File: .\MainThread.cpp
Line:
997 Description: fatal error, stopping service

Error - 6/24/2012 11:12:43 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331650
Description = Termination reason code 9: Client PC is shutting down.

Error - 6/24/2012 11:12:43 PM | Computer Name = Mainboard | Source = vpnagent | ID = 50331649
Description = Function: CVpnMgr::processEvents Return code: 0 File: .\MainThread.cpp
Line:
997 Description: fatal error, stopping service

[ Media Center Events ]
Error - 9/13/2009 1:30:13 AM | Computer Name = Tricia-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/7/2009 4:23:10 PM | Computer Name = Tricia-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 3/19/2010 5:37:58 PM | Computer Name = Tricia-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 4/1/2010 6:16:16 AM | Computer Name = Tricia-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1767396
seconds with 121500 seconds of active time. This session ended with a crash.

Error - 7/30/2010 12:25:43 AM | Computer Name = Tricia-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6535.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 982038
seconds with 11460 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7026
Description =

Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:16 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:22 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =

Error - 6/25/2012 5:59:23 PM | Computer Name = Mainboard | Source = DCOM | ID = 10005
Description =

Error - 6/25/2012 5:59:24 PM | Computer Name = Mainboard | Source = DCOM | ID = 10005
Description =

Error - 6/25/2012 5:59:25 PM | Computer Name = Mainboard | Source = Service Control Manager | ID = 7001
Description =


< End of report >



if i should start another post instead of continuing this one, please let me know
thank you
Hi comp_problems I apologise for the delay in answering but for some reason I didn't receive notification of your post. I only discovered it when I was going to close the thread. Please don't run logs and fixes on your own - it is not a good idea. I would carry on with this myself but I have a bit of a sudden situation that will take up my time for a couple of days do so please start the new topic and wait for instructions. Sorry for the inconvenience but I'm pleased to have helped with the other PC. Take care Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI