Dean N
Topic Starter
My laptop has redirect virus. The most common site I get redirected to is Newsfudge. It happens both in IE and in Firefox (I recently made the move to Firefox). Also, IE in particular seems to lock up quite a bit with the standard (not responding) alert while browsing.
Help!
Here are the OTL logs:
OTL Extras logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3544DED1-07DB-40C0-98F3-435A6DA195C7}" = Google SketchUp 8
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{44E9D4C2-946C-4378-9354-558803C47A68}" = Client Security - Password Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78E83B4F-7230-4F0B-B1AD-8DDF05473D6F}" = Intel® PROSet/Wireless WiFi Software
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DA0C101-5C7C-40C9-A485-68E12780232C}" = Sierra Wireless MC5720 Package for Access Connections
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{987F1753-1F42-4DF2-A5EA-0CCB777F3EB0}" = ASPCA Reminder by We-Care.com v4.0.19.1
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = ThinkPad 11a/b/g/n Wireless LAN Mini-PCI Express Adapter
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkPad
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"ATI Display Driver" = ATI Display Driver
"BrewMate_is1" = BrewMate
"CCleaner" = CCleaner
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem
"Debenu PDF Maximus" = Debenu PDF Maximus [removed]
"Exact Audio Copy" = Exact Audio Copy 1.0beta3
"Family Tree Builder" = MyHeritage Family Tree Builder
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSNINST" = MSN
"NeroMultiInstaller!UninstallKey" = Nero Suite
"OnScreenDisplay" = On Screen Display
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/16/2012 8:46:48 PM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32242515
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2781
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2781
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4781
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4781
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7047
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7047
[ System Events ]
Error - 7/4/2012 11:04:56 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/4/2012 4:43:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/4/2012 5:01:49 PM | Computer Name = MOLESWORTH | Source = DCOM | ID = 10010
Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register
with DCOM within the required timeout.
Error - 7/4/2012 9:37:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/9/2012 7:56:43 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/15/2012 10:50:02 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/16/2012 9:28:22 PM | Computer Name = MOLESWORTH | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).
< End of report >
OTL logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dean\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRO.DLL ()
MOD - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2MSVC6.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\IconRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\GUIHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\SvcHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2ExtDLL.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (acs) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DozeHDD) – C:\WINDOWS\system32\drivers\DOZEHDD.SYS (Lenovo.)
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (Shockprf) – C:\WINDOWS\system32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\system32\drivers\ApsHM86.sys (Lenovo.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (lenovo.smi) – C:\WINDOWS\system32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (TVTI2C) – C:\WINDOWS\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (swmx01) Sierra Wireless USB MUX Driver (#01) – C:\WINDOWS\system32\drivers\swmx01.sys (Sierra Wireless Corporation)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (SWNC5E01) Sierra Wireless MUX NDIS Driver (#01) – C:\WINDOWS\system32\drivers\SWNC5E01.sys (Sierra Wireless Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/08 13:42:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{89198AC7-A618-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\Dean\Local Settings\Application Data\{89198AC7-A618-11E1-8270-B8AC6F996F26}\ [2012/05/24 23:20:21 | 000,000,000 | —D | M]
[2012/04/14 16:54:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] ("I Want This") – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions\[removed]
[2012/04/14 16:54:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 14:16:57 | 000,003,793 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DEAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\IIXRSKXW.DEFAULT\EXTENSIONS\{66E978CD-981F-47DF-AC42-E3CF417C1467}.XPI
[2012/05/24 23:20:21 | 000,000,000 | —D | M] (Mozilla Safe Browsing) – C:\DOCUMENTS AND SETTINGS\DEAN\LOCAL SETTINGS\APPLICATION DATA\{89198AC7-A618-11E1-8270-B8AC6F996F26}
[2012/07/08 13:42:34 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/08 13:42:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/08 13:42:30 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: Gmail = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2008/08/21 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Debenu PDF Maximus Watched Folder Agent] C:\Program Files\Debenu\PDF Maximus\MaximusWatchedFolders.exe (Debenu)
O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - Startup: C:\Documents and Settings\Dean\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Lenovo Password Manager… - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1341434498890 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9665963E-2A59-4F40-90CE-230724DBB3AC}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - (ACNotify.dll) - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/30 14:28:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/21 12:02:51 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Dean\Recent
[2012/07/18 19:39:32 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:39:32 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/18 19:35:21 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Start Menu\Programs\Debenu PDF Maximus
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/07/09 10:09:16 | 000,000,000 | —D | C] – C:\Program Files\Debenu
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\My Documents\Amazon MP3
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/07/09 08:00:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Amazon
[2012/07/09 08:00:17 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/07/04 20:59:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/07/04 20:59:32 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/07/04 20:58:48 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/04 20:58:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/07/04 20:58:11 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/21 12:03:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004UA.job
[2012/07/21 11:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2012/07/21 10:18:16 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/21 10:17:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/19 09:03:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004Core.job
[2012/07/18 19:53:10 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:53:10 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/12 21:20:35 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 08:33:39 | 000,123,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/12 08:01:38 | 000,002,255 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/07/09 08:00:18 | 000,001,852 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | M] () – C:\WINDOWS\AM_D7.PRF
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/01 00:10:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/06/30 16:44:57 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Dean\My Documents\Default.rdp
[2012/06/30 16:06:13 | 000,000,468 | —- | M] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,145,383 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/24 12:04:08 | 000,143,985 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 01:23:50 | 000,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/06/22 23:49:00 | 000,139,290 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table square.skp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/18 19:39:33 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/09 08:00:18 | 000,001,852 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | C] () – C:\WINDOWS\AM_D7.PRF
[2012/06/30 16:06:13 | 000,000,468 | —- | C] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,143,985 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 12:04:08 | 000,145,383 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/18 22:51:07 | 000,000,417 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2012/06/18 22:47:52 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2012/06/05 23:26:47 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2978286325-1291239056-3539293820-1004-0.dat
[2012/06/05 23:26:46 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/17 23:14:06 | 000,073,488 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/18 16:28:11 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/03/11 01:39:47 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2012/02/15 07:28:49 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/19 00:44:13 | 007,549,704 | —- | C] () – C:\Program Files\InternationalPrimoPDF.exe
[2012/01/19 00:37:29 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2010/09/02 09:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/09/01 12:17:42 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2010/09/01 09:15:04 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2010/09/01 09:15:04 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2010/09/01 09:15:04 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2010/08/31 15:02:54 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/31 15:00:09 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/31 15:00:09 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/31 15:00:08 | 000,189,051 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/31 14:54:09 | 000,008,572 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/31 13:41:54 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/08/31 13:26:48 | 000,196,608 | —- | C] () – C:\WINDOWS\PWMBTHLP.EXE
[2010/08/31 13:26:47 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2010/08/30 14:36:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/08/30 14:36:38 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/08/30 14:36:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/08/30 14:36:38 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/08/30 14:30:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/30 14:26:39 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/30 14:15:51 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/30 14:15:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/08/30 14:15:49 | 000,473,482 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/30 14:15:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/08/30 14:15:49 | 000,076,410 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/30 14:15:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/08/30 14:15:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/08/30 14:15:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/08/30 14:15:48 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/08/30 14:15:48 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/08/30 14:15:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/08/30 14:15:41 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2010/08/30 07:24:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/30 07:23:50 | 000,123,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2012/07/09 10:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/01/12 22:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2012/06/18 22:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/30 14:49:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2012/05/28 11:01:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2012/07/04 20:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/09 08:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/01/12 22:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Avaya
[2012/02/25 17:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\EAC
[2012/06/05 11:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Garmin
[2010/09/01 12:59:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Lenovo
[2012/06/18 22:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\MyHeritage
[2012/04/14 13:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\OpenOffice.org
[2012/01/19 00:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\PrimoPDF
[2012/06/18 22:47:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\The Complete Genealogy Reporter - FTB
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/03/01 22:28:39 | 066,895,628 | —- | M] () – C:\01 Discovery.wav
[2012/03/02 01:00:32 | 079,591,724 | —- | M] () – C:\01 Gunslinging Bird.wav
[2012/03/02 01:02:22 | 063,163,004 | —- | M] () – C:\02 New Now Know How.wav
[2012/03/01 22:31:16 | 091,438,748 | —- | M] () – C:\02 Special Beings.wav
[2012/03/02 01:03:17 | 030,503,132 | —- | M] () – C:\03 Self-Portrait In Three Colors.wav
[2012/03/01 22:33:22 | 081,823,772 | —- | M] () – C:\03 The Fine Line.wav
[2012/03/02 01:04:51 | 061,768,268 | —- | M] () – C:\04 Birdcalls.wav
[2012/03/01 22:34:42 | 047,082,380 | —- | M] () – C:\04 Lost and Found.wav
[2012/03/02 01:06:36 | 075,555,692 | —- | M] () – C:\05 E's Flat Ah's Flat Too (Aka ''Hora Decubitus'').wav
[2012/03/01 22:36:15 | 067,326,044 | —- | M] () – C:\05 Recovery.wav
[2012/03/02 01:08:18 | 080,297,324 | —- | M] () – C:\06 Cryin' Blues.wav
[2012/03/01 22:37:46 | 069,588,668 | —- | M] () – C:\06 To the One.wav
[2012/03/02 01:09:58 | 076,251,884 | —- | M] () – C:\07 Open Letter To Duke.wav
[2012/03/02 01:11:50 | 101,415,932 | —- | M] () – C:\08 Moanin'.wav
[2012/03/02 01:12:57 | 062,062,268 | —- | M] () – C:\09 Goodbye Pork Pie Hat.wav
[2012/03/02 01:15:06 | 131,025,260 | —- | M] () – C:\10 Song With Orange.wav
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/01/12 22:32:27 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/11/02 02:53:58 | 000,438,840 | —- | M] () – C:\bootmgr
[2009/04/20 16:30:22 | 000,057,856 | —- | M] () – C:\CabExtractor.exe
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/30 13:04:06 | 000,000,839 | —- | M] () – C:\DeleteContent.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/12/12 13:59:41 | 000,000,191 | —- | M] () – C:\ibminst.log
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/03/01 22:39:39 | 000,006,448 | —- | M] () – C:\John McLaughlin - To the One.log
[2012/03/02 08:06:23 | 000,008,086 | —- | M] () – C:\Mingus Big Band - Live At Jazz Standard.log
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 13:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/07/21 10:17:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/12/12 17:16:11 | 000,000,020 | —- | M] () – C:\SYSLEVEL.IBM
[2010/06/30 13:04:06 | 000,000,666 | —- | M] () – C:\UnattendInstallation.bat
[2012/03/01 20:03:42 | 000,011,986 | —- | M] () – C:\Unknown Artist - Unknown Title.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/30 14:28:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2012/01/19 00:44:26 | 007,549,704 | —- | M] () – C:\Program Files\InternationalPrimoPDF.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/30 07:23:26 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/30 07:23:26 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/30 07:23:26 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/12/12 14:00:09 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/08/30 14:37:00 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/12 22:32:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/30 14:39:20 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-12 11:57:19
< End of report >
Help!
Here are the OTL logs:
OTL Extras logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3544DED1-07DB-40C0-98F3-435A6DA195C7}" = Google SketchUp 8
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{44E9D4C2-946C-4378-9354-558803C47A68}" = Client Security - Password Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78E83B4F-7230-4F0B-B1AD-8DDF05473D6F}" = Intel® PROSet/Wireless WiFi Software
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DA0C101-5C7C-40C9-A485-68E12780232C}" = Sierra Wireless MC5720 Package for Access Connections
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{987F1753-1F42-4DF2-A5EA-0CCB777F3EB0}" = ASPCA Reminder by We-Care.com v4.0.19.1
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = ThinkPad 11a/b/g/n Wireless LAN Mini-PCI Express Adapter
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{D728E945-256D-4477-B377-6BBA693714AC}" = Productivity Center Supplement for ThinkPad
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"ATI Display Driver" = ATI Display Driver
"BrewMate_is1" = BrewMate
"CCleaner" = CCleaner
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem
"Debenu PDF Maximus" = Debenu PDF Maximus [removed]
"Exact Audio Copy" = Exact Audio Copy 1.0beta3
"Family Tree Builder" = MyHeritage Family Tree Builder
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSNINST" = MSN
"NeroMultiInstaller!UninstallKey" = Nero Suite
"OnScreenDisplay" = On Screen Display
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/16/2012 8:46:48 PM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32242515
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2781
Error - 7/19/2012 9:22:25 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2781
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4781
Error - 7/19/2012 9:22:27 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4781
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7047
Error - 7/19/2012 9:22:30 AM | Computer Name = MOLESWORTH | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7047
[ System Events ]
Error - 7/4/2012 11:04:56 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/4/2012 4:43:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/4/2012 5:01:49 PM | Computer Name = MOLESWORTH | Source = DCOM | ID = 10010
Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register
with DCOM within the required timeout.
Error - 7/4/2012 9:37:51 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/9/2012 7:56:43 AM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/15/2012 10:50:02 PM | Computer Name = MOLESWORTH | Source = PlugPlayManager | ID = 12
Description = The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV;_109A&SUBSYS;_200117AA&REV;_00\4&192ac53f&0&00E0)
disappeared from the system without first being prepared for removal.
Error - 7/16/2012 9:28:22 PM | Computer Name = MOLESWORTH | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).
< End of report >
OTL logfile created on: 7/21/2012 12:05:31 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Dean\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 74.07% Memory free
4.84 Gb Paging File | 4.25 Gb Available in Paging File | 87.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.02 Gb Total Space | 66.74 Gb Free Space | 74.97% Space Free | Partition Type: NTFS
Computer Name: MOLESWORTH | User Name: Dean | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dean\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRO.DLL ()
MOD - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2MSVC6.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\IconRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\GUIHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\Res\US\SvcHlprRes.dll ()
MOD - C:\Program Files\ThinkPad\ConnectUtilities\ACAthV2ExtDLL.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (acs) – C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (ThinkVantage Registry Monitor Service) – C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (psadd) – C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DozeHDD) – C:\WINDOWS\system32\drivers\DOZEHDD.SYS (Lenovo.)
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (Shockprf) – C:\WINDOWS\system32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\system32\drivers\ApsHM86.sys (Lenovo.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (lenovo.smi) – C:\WINDOWS\system32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (TVTI2C) – C:\WINDOWS\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (WSIMD) – C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (swmx01) Sierra Wireless USB MUX Driver (#01) – C:\WINDOWS\system32\drivers\swmx01.sys (Sierra Wireless Corporation)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (SWNC5E01) Sierra Wireless MUX NDIS Driver (#01) – C:\WINDOWS\system32\drivers\SWNC5E01.sys (Sierra Wireless Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/08 13:42:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{89198AC7-A618-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\Dean\Local Settings\Application Data\{89198AC7-A618-11E1-8270-B8AC6F996F26}\ [2012/05/24 23:20:21 | 000,000,000 | —D | M]
[2012/04/14 16:54:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions
[2012/07/21 10:19:09 | 000,000,000 | —D | M] ("I Want This") – C:\Documents and Settings\Dean\Application Data\Mozilla\Firefox\Profiles\iixrskxw.default\extensions\[removed]
[2012/04/14 16:54:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 14:16:57 | 000,003,793 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DEAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\IIXRSKXW.DEFAULT\EXTENSIONS\{66E978CD-981F-47DF-AC42-E3CF417C1467}.XPI
[2012/05/24 23:20:21 | 000,000,000 | —D | M] (Mozilla Safe Browsing) – C:\DOCUMENTS AND SETTINGS\DEAN\LOCAL SETTINGS\APPLICATION DATA\{89198AC7-A618-11E1-8270-B8AC6F996F26}
[2012/07/08 13:42:34 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/08 13:42:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/08 13:42:30 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: Gmail = C:\Documents and Settings\Dean\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2008/08/21 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Debenu PDF Maximus Watched Folder Agent] C:\Program Files\Debenu\PDF Maximus\MaximusWatchedFolders.exe (Debenu)
O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)
O4 - HKLM..\Run: [LPMailChecker] C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - Startup: C:\Documents and Settings\Dean\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Lenovo Password Manager… - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1341434498890 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9665963E-2A59-4F40-90CE-230724DBB3AC}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - (ACNotify.dll) - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dean\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/30 14:28:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/21 12:02:51 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Dean\Recent
[2012/07/18 19:39:32 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:39:32 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/18 19:35:21 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Start Menu\Programs\Debenu PDF Maximus
[2012/07/09 10:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/07/09 10:09:16 | 000,000,000 | —D | C] – C:\Program Files\Debenu
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\My Documents\Amazon MP3
[2012/07/09 08:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/07/09 08:00:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Amazon
[2012/07/09 08:00:17 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/07/08 13:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/07/04 20:59:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/07/04 20:59:32 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/07/04 20:58:48 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/07/04 20:58:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/04 20:58:27 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/07/04 20:58:11 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/21 12:03:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004UA.job
[2012/07/21 11:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2012/07/21 10:18:16 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/21 10:17:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/19 09:03:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2978286325-1291239056-3539293820-1004Core.job
[2012/07/18 19:53:10 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/18 19:53:10 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/12 21:20:35 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 08:33:39 | 000,123,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/12 08:01:38 | 000,002,255 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/07/09 08:00:18 | 000,001,852 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | M] () – C:\WINDOWS\AM_D7.PRF
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/01 00:10:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/06/30 16:44:57 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Dean\My Documents\Default.rdp
[2012/06/30 16:06:13 | 000,000,468 | —- | M] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,145,383 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/24 12:04:08 | 000,143,985 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 01:23:50 | 000,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/06/22 23:49:00 | 000,139,290 | —- | M] () – C:\Documents and Settings\Dean\My Documents\entry table square.skp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/18 19:39:33 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/09 08:00:18 | 000,001,852 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/07/04 20:59:33 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/07/04 11:18:29 | 000,000,024 | —- | C] () – C:\WINDOWS\AM_D7.PRF
[2012/06/30 16:06:13 | 000,000,468 | —- | C] () – C:\Documents and Settings\Dean\My Documents\spider.sav
[2012/06/24 12:12:06 | 000,143,985 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skb
[2012/06/24 12:04:08 | 000,145,383 | —- | C] () – C:\Documents and Settings\Dean\My Documents\entry table arched apron.skp
[2012/06/18 22:51:07 | 000,000,417 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2012/06/18 22:47:52 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2012/06/05 23:26:47 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2978286325-1291239056-3539293820-1004-0.dat
[2012/06/05 23:26:46 | 000,132,302 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/17 23:14:06 | 000,073,488 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/18 16:28:11 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2012/03/11 01:39:47 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2012/02/15 07:28:49 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/19 00:44:13 | 007,549,704 | —- | C] () – C:\Program Files\InternationalPrimoPDF.exe
[2012/01/19 00:37:29 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2010/09/02 09:29:25 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/09/01 12:17:42 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2010/09/01 09:15:04 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2010/09/01 09:15:04 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2010/09/01 09:15:04 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2010/08/31 15:02:54 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/31 15:00:09 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/31 15:00:09 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/31 15:00:08 | 000,189,051 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/31 14:54:09 | 000,008,572 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/31 13:41:54 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/08/31 13:26:48 | 000,196,608 | —- | C] () – C:\WINDOWS\PWMBTHLP.EXE
[2010/08/31 13:26:47 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2010/08/30 14:36:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/08/30 14:36:38 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/08/30 14:36:38 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/08/30 14:36:38 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/08/30 14:36:38 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/08/30 14:30:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/30 14:26:39 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/30 14:15:51 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/30 14:15:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2010/08/30 14:15:49 | 000,473,482 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/30 14:15:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2010/08/30 14:15:49 | 000,076,410 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/30 14:15:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2010/08/30 14:15:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2010/08/30 14:15:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2010/08/30 14:15:48 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2010/08/30 14:15:48 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2010/08/30 14:15:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2010/08/30 14:15:41 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2010/08/30 07:24:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/30 07:23:50 | 000,123,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2012/07/09 10:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Debenu
[2012/01/12 22:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lenovo
[2012/06/18 22:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/30 14:49:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UIB
[2012/05/28 11:01:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2012/07/04 20:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/07/09 08:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Amazon
[2012/01/12 22:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Avaya
[2012/02/25 17:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\EAC
[2012/06/05 11:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Garmin
[2010/09/01 12:59:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\Lenovo
[2012/06/18 22:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\MyHeritage
[2012/04/14 13:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\OpenOffice.org
[2012/01/19 00:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\PrimoPDF
[2012/06/18 22:47:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Dean\Application Data\The Complete Genealogy Reporter - FTB
[2012/07/21 10:18:37 | 000,000,316 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/03/01 22:28:39 | 066,895,628 | —- | M] () – C:\01 Discovery.wav
[2012/03/02 01:00:32 | 079,591,724 | —- | M] () – C:\01 Gunslinging Bird.wav
[2012/03/02 01:02:22 | 063,163,004 | —- | M] () – C:\02 New Now Know How.wav
[2012/03/01 22:31:16 | 091,438,748 | —- | M] () – C:\02 Special Beings.wav
[2012/03/02 01:03:17 | 030,503,132 | —- | M] () – C:\03 Self-Portrait In Three Colors.wav
[2012/03/01 22:33:22 | 081,823,772 | —- | M] () – C:\03 The Fine Line.wav
[2012/03/02 01:04:51 | 061,768,268 | —- | M] () – C:\04 Birdcalls.wav
[2012/03/01 22:34:42 | 047,082,380 | —- | M] () – C:\04 Lost and Found.wav
[2012/03/02 01:06:36 | 075,555,692 | —- | M] () – C:\05 E's Flat Ah's Flat Too (Aka ''Hora Decubitus'').wav
[2012/03/01 22:36:15 | 067,326,044 | —- | M] () – C:\05 Recovery.wav
[2012/03/02 01:08:18 | 080,297,324 | —- | M] () – C:\06 Cryin' Blues.wav
[2012/03/01 22:37:46 | 069,588,668 | —- | M] () – C:\06 To the One.wav
[2012/03/02 01:09:58 | 076,251,884 | —- | M] () – C:\07 Open Letter To Duke.wav
[2012/03/02 01:11:50 | 101,415,932 | —- | M] () – C:\08 Moanin'.wav
[2012/03/02 01:12:57 | 062,062,268 | —- | M] () – C:\09 Goodbye Pork Pie Hat.wav
[2012/03/02 01:15:06 | 131,025,260 | —- | M] () – C:\10 Song With Orange.wav
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/01/12 22:32:27 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/11/02 02:53:58 | 000,438,840 | —- | M] () – C:\bootmgr
[2009/04/20 16:30:22 | 000,057,856 | —- | M] () – C:\CabExtractor.exe
[2010/08/30 14:28:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/30 13:04:06 | 000,000,839 | —- | M] () – C:\DeleteContent.bat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/12/12 13:59:41 | 000,000,191 | —- | M] () – C:\ibminst.log
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/03/01 22:39:39 | 000,006,448 | —- | M] () – C:\John McLaughlin - To the One.log
[2012/03/02 08:06:23 | 000,008,086 | —- | M] () – C:\Mingus Big Band - Live At Jazz Standard.log
[2010/08/30 14:28:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 13:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/07/21 10:17:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/12/12 17:16:11 | 000,000,020 | —- | M] () – C:\SYSLEVEL.IBM
[2010/06/30 13:04:06 | 000,000,666 | —- | M] () – C:\UnattendInstallation.bat
[2012/03/01 20:03:42 | 000,011,986 | —- | M] () – C:\Unknown Artist - Unknown Title.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/30 14:28:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2012/01/19 00:44:26 | 007,549,704 | —- | M] () – C:\Program Files\InternationalPrimoPDF.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/30 07:23:26 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/30 07:23:26 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/30 07:23:26 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/12/12 14:00:09 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/08/30 14:37:00 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/12 22:32:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/30 14:39:20 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dean\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-12 11:57:19
< End of report >