This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Constant crashing and very slow performance [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello What the Tech,
You all have helped me in the past with my home computer with stunning results!
These days it's my work computer that's buggering up :(
I'm experiencing at least 2 crashes per work day along with amazingly slow performance lately. Every program chugs along, 15 minute + start ups and shut downs, opening any type of file is a chore. I've tried the typical disc defragmenting and such which has made little difference. If there is anyone out there who has a minute I would be eternally grateful for any advice.

OTL.txt

OTL logfile created on: 3/6/2013 8:13:17 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and SettingsAndyDesktopOTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 61.92% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.06% Paging File free
Paging file location(s): C:pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.76 Gb Total Space | 123.03 Gb Free Space | 52.86% Space Free | Partition Type: NTFS
Drive D: | 50.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MODEL | User Name: Andy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:Documents and SettingsAndyDesktopOTLOTL.exe (OldTimer Tools)
PRC - c:Program FilesMicrosoft Security ClientMsMpEng.exe (Microsoft Corporation)
PRC - C:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
PRC - C:Documents and SettingsAndyLocal SettingsApplication DataAkamainetsession_win.exe (Akamai Technologies, Inc.)
PRC - C:Program FilesCommon FilesAutodesk SharedAutodesk Download ManagerDLMSession.exe (Autodesk, Inc.)
PRC - C:Program FilesJavajre7binjqs.exe (Oracle Corporation)
PRC - C:Program FilesAutodeskContent ServiceConnect.Service.ContentService.exe (Autodesk, Inc.)
PRC - C:Program FilesCommon FilesJavaJava Updatejucheck.exe (Sun Microsystems, Inc.)
PRC - C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32server.exe ()
PRC - C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32server.exe ()
PRC - C:xampplitemysqlbinmysqld.exe (MySQL AB)
PRC - C:xamppliteapachebinhttpd.exe (Apache Software Foundation)
PRC - C:Program FilesSonicWALLSonicWALL Global VPN ClientSWGVCSvc.exe (SonicWALL, Inc.)
PRC - C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe (Autodesk)
PRC - C:Program FilesCyberLinkPowerDVD DXPDVDDXSrv.exe (CyberLink Corp.)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)
PRC - C:WINDOWSsystem32cmd.exe (Microsoft Corporation)
PRC - C:Program FilesIntelIntel Matrix Storage ManagerIAANTmon.exe (Intel Corporation)
PRC - C:Program FilesIntelIntel Matrix Storage ManagerIAAnotif.exe (Intel Corporation)
PRC - C:Program FilesDell SAS RAID Storage ManagerMegaPopuppopup.exe ( )
PRC - C:Program FilesDell SAS RAID Storage ManagerMegaMonitormrmonitor.exe ()
PRC - C:Program FilesBroadcomASFIPMonAsfIpMon.exe (Broadcom Corporation)
PRC - C:Program FilesDell SAS RAID Storage ManagerFrameworkVivaldiFramework.exe ()
PRC - C:Program FilesNETGEARWG111Twlan111t.exe (NETGEAR)
PRC - C:Program FilesHewlett-PackardHP Deskjet 9800 SeriesToolboxHPWQTBX.exe (Hewlett-Packard Company)
PRC - C:Program FilesDell SAS RAID Storage ManagerJREbinjavaw.exe ()


========== Modules (No Company Name) ==========

MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.WorkflowServ#74e83f69320f
01190c6067c2f8b30489System.WorkflowServices.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel#4edc2adecbaa
b74f9975be6c69167e15System.ServiceModel.Routing.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel#2ce0a49fbfc6
924594dd5967a616eb06System.ServiceModel.Discovery.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel#85138a3833f1
f6c7db57e09de3deee27System.ServiceModel.Channels.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel#9b61f1ff6391
792692c432394c26c79cSystem.ServiceModel.Activities.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.IdentityModel6a69d4225b39
1d3c9a63b82c707f68dfSystem.IdentityModel.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel252adcaff1070
555538f68e50f52c055System.ServiceModel.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceModel#f7fb007b7720
5f93cac30408a5bea10fSystem.ServiceModel.Web.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.ServiceProce#65acd066ece0
048520819cb160ebaae5System.ServiceProcess.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Web.Services1a39e50cf087a
a4d71d93ddf2199b3faSystem.Web.Services.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.EnterpriseSe#6b04f4c4bd0a
6e6bf91e8eb5fccb045aSystem.EnterpriseServices.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.EnterpriseSe#6b04f4c4bd0a
6e6bf91e8eb5fccb045aSystem.EnterpriseServices.Wrapper.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Transactions79d3ecc74b681
4032c800db49534e153System.Transactions.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Runtime.Dura#ee7b13803a53
9a8e268e137284cf3560System.Runtime.DurableInstancing.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32SMDiagnosticsf749bd80cadc8925dac
6e7a37705e411SMDiagnostics.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Runtime.Seri#a31756f7a2c2
b2b884815da8a87fe4daSystem.Runtime.Serialization.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Data\06b973a6644eeaef2a6d1617fba5ca54System.Data.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Xml9f782ec14c759c492ac760
56b05f11e7System.Xml.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Core35d23b34d83acc8d52858
c89169a312eSystem.Core.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Configuration661b58707b02
cb70078e50273ac91633System.Configuration.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System.Drawing8b906332417c7790e1
9b663d157f9d72System.Drawing.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32System8e12f4f895975a109ef745043f
4d0c62System.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v4.0.30319_32mscorlib3f95a6d480ed1ebe45cf27b7
70ba94edmscorlib.ni.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll ()
MOD - C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32server.exe ()
MOD - C:Program FilesFileZilla FTP Clientfzshellext.dll ()
MOD - C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32server.exe ()
MOD - C:Program FilesGoogleGoogle Desktop Searchgzlib.dll ()
MOD - C:WINDOWSsystem32PDFreDirectMonNT.dll ()
MOD - C:WINDOWSsystem32spoolprtprocsw32x86aloaha_prntproc.dll ()
MOD - C:WINDOWSsystem32aloaha_prntmon.dll ()
MOD - C:Program FilesCommon FilesRoxio Shared9.0DLLShareddlaapi_w.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerMegaMonitormrmonitor.exe ()
MOD - C:WINDOWSsystem32cpwmon2k.dll ()
MOD - C:WINDOWSsystem32AlertStrings.dll ()
MOD - C:WINDOWSsystem32ssleay32.dll ()
MOD - C:WINDOWSsystem32libeay32.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerFrameworkVivaldiFramework.exe ()
MOD - C:Program FilesDell SAS RAID Storage ManagerFrameworksystype.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerFrameworkstorelibirjni.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerFrameworkstorelibjni.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerFrameworkAuthenticate.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinnet.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinzip.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinjavaw.exe ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinjava.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinverify.dll ()
MOD - C:Program FilesDell SAS RAID Storage ManagerJREbinhpi.dll ()


========== Services (SafeList) ==========

SRV - (MsMpSvc) – c:Program FilesMicrosoft Security ClientMsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe (Flexera Software, Inc.)
SRV - (Akamai) – c:program filescommon filesakamai/netsession_win_ce5ba24.dll ()
SRV - (JavaQuickStarterService) – C:Program FilesJavajre7binjqs.exe (Oracle Corporation)
SRV - (Autodesk Content Service) – C:Program FilesAutodeskContent ServiceConnect.Service.ContentService.exe (Autodesk, Inc.)
SRV - (mi-raysat_3dsmax2013_32) – C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32server.exe ()
SRV - (mi-raysat_3dsmax2012_32) – C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32server.exe ()
SRV - (pdfprint) – C:Program FilesWrocklagepdfprint.exe (Wrocklage Intermedia GmbH)
SRV - (MySQL) – C:xampplitemysqlbinmysqld.exe (MySQL AB)
SRV - (Apache2.2) – C:xamppliteapachebinhttpd.exe (Apache Software Foundation)
SRV - (SWGVCSvc) – C:Program FilesSonicWALLSonicWALL Global VPN ClientSWGVCSvc.exe (SonicWALL, Inc.)
SRV - (Macromedia Licensing Service) – C:Program FilesCommon FilesMacromedia SharedServiceMacromedia Licensing.exe (Macromedia)
SRV - (Autodesk Licensing Service) – C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe (Autodesk)
SRV - (IAANTMON) – C:Program FilesIntelIntel Matrix Storage ManagerIAANTmon.exe (Intel Corporation)
SRV - (MegaMonitorSrv) – C:Program FilesDell SAS RAID Storage ManagerMegaMonitormrmonitor.exe ()
SRV - (ASFIPmon) – C:Program FilesBroadcomASFIPMonAsfIpMon.exe (Broadcom Corporation)
SRV - (MSMFramework) – C:Program FilesDell SAS RAID Storage ManagerFrameworkVivaldiFramework.exe ()
SRV - (WinDefend) – C:Program FilesWindows DefenderMsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (RTLWUSB) – system32DRIVERSwg111v2.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (nielprt) – system32DRIVERSnielprt.sys File not found
DRV - (NielGfx) – system32driversnielgfx.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:ComboFixcatchme.sys File not found
DRV - (SASKUTIL) – C:Program FilesSUPERAntiSpywareSASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:Program FilesSUPERAntiSpywaresasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SWIPsec) – C:WINDOWSsystem32driversSWIPsec.sys (SonicWALL, Inc.)
DRV - (SWVNIC) – C:WINDOWSsystem32driversSWVNIC.sys (SonicWALL, Inc.)
DRV - (DNE) – C:WINDOWSsystem32driversdne2000.sys (Deterministic Networks, Inc.)
DRV - (SYMMPI) – C:WINDOWSsystem32driverssymmpi.sys (LSI Corporation)
DRV - (b57w2k) – C:WINDOWSsystem32driversb57xp32.sys (Broadcom Corporation)
DRV - (SenFiltService) – C:WINDOWSsystem32driverssenfilt.sys (Sensaura)
DRV - (DLADResM) – C:WINDOWSsystem32driversDLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:WINDOWSsystem32driversDLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:WINDOWSsystem32driversDLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:WINDOWSsystem32driversDLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:WINDOWSsystem32driversDLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:WINDOWSsystem32driversDLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:WINDOWSsystem32driversDLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:WINDOWSsystem32driversDLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:WINDOWSsystem32driversDLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:WINDOWSsystem32driversDLACDBHM.SYS (Roxio)
DRV - (BASFND) – C:Program FilesBroadcomASFIPMonBASFND.sys (Broadcom Corporation)
DRV - (AR5523) – C:WINDOWSsystem32driversWG11TND5.sys (NETGEAR, Inc.)
DRV - (DNINDIS5) – C:WINDOWSsystem32DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,Default_Search_URL = http://www.google.com/ie
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.google.com/ie
IE - HKCU..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…id=ie7&rlz;=
IE - HKCU..SearchScopes{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s;=fZsQXPl…q={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [removed]:1.9.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found

FF - [removed]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/GoogleEarthPlugin: C:Program FilesGoogleGoogle Earthpluginnpgeplugin.dll (Google)
FF - [removed]/DTPlugin,version=10.3.1: C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)
FF - [removed]/JavaPlugin,version=10.3.1: C:Program FilesOracleJavaFX 2.0 Runtimebinplugin2npjp2.dll (Oracle Corporation)
FF - [removed]/YahooMessengerStatePlugin;version=1.0.0.6: C:Program FilesYahoo!SharednpYState.dll (Yahoo! Inc.)
FF - [removed]/WPF,version=3.5: c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/Google Updater;version=14: C:Program FilesGoogleGoogle Updater2.4.2432.1652npCIDetect14.dll (Google)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Winzip Courier: C:Program FilesWinZip Couriernpwzwmc.dll (WinZip Computing, S.L.)
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program FilesAdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - [removed]/Google Update;version=3: C:Documents and SettingsAndyLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Documents and SettingsAndyLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{74c841e3-b59f-479e-8d7a-e26a942a87c8}: C:Program FilesWinZip CourierFFExt [2011/07/07 08:52:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/09/17 16:51:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 6.0.2extensionsPlugins: C:Program FilesMozilla Firefoxplugins [2013/02/21 09:27:25 | 000,000,000 | —D | M]

[2011/03/16 08:38:28 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsAndyApplication DataMozillaExtensions
[2012/06/01 09:14:34 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsAndyApplication DataMozillaFirefoxProfiles\0ztaw4bn.defaultextensions
[2012/06/01 09:14:34 | 001,335,949 | —- | M] () (No name found) – C:Documents and SettingsAndyApplication DataMozillaFirefoxProfiles\[removed]
[2011/09/17 16:52:01 | 000,019,153 | —- | M] () (No name found) – C:Documents and SettingsAndyApplication DataMozillaFirefoxProfiles\0ztaw4bn.defaultextensions{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/02/20 09:03:08 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2011/09/03 01:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2011/07/13 16:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:Program Filesmozilla firefoxpluginsnpCouponPrinter.dll
[2011/07/13 16:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:Program Filesmozilla firefoxpluginsnpMozCouponPrinter.dll
[2011/09/02 18:25:59 | 000,002,252 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsbing.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - homepage: http://yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeApplication25.0.1364.152PepperFlashpepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeApplication25.0.1364.152ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeApplication25.0.1364.152pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeApplicationpluginsnpMozCouponPrinter.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:Program FilesAdobeReader 10.0ReaderBrowsernppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:Program FilesMozilla FirefoxpluginsnpCouponPrinter.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:Program FilesWindows Media Playernpdsplay.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:Program FilesGoogleGoogle Earthpluginnpgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:Program FilesGoogleGoogle Updater2.4.2432.1652npCIDetect14.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:Program FilesOracleJavaFX 2.0 Runtimebinplugin2npjp2.dll
CHR - plugin: WinZip Courier (Enabled) = C:Program FilesWinZip Couriernpwzwmc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:Program FilesiTunesMozilla Pluginsnpitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:WINDOWSsystem32MacromedFlashNPSWF32.dll
CHR - plugin: Java Deployment Toolkit [removed] (Enabled) = C:WINDOWSsystem32npDeployJava1.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll
CHR - Extension: YouTube = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_1
CHR - Extension: Google Search = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1
CHR - Extension: WinZip Courier = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsilckobikkmajlmhhdenkhonjkoaneclk3.0.2_0
CHR - Extension: Gmail = C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_1

O1 HOSTS File: ([2011/10/10 17:21:57 | 000,000,027 | —- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:Program FilesWinZip Courierwzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.8313.1002swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:Program FilesDellBAEBAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesOracleJavaFX 2.0 Runtimebinjp2ssv.dll (Oracle Corporation)
O3 - HKCU..ToolbarWebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..Run: [ADSK DLMSession] C:Program FilesCommon FilesAutodesk SharedAutodesk Download ManagerDLMSession.exe (Autodesk, Inc.)
O4 - HKLM..Run: [APSDaemon] C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [HPWQTOOLBOX] C:Program FilesHewlett-PackardHP Deskjet 9800 SeriesToolboxHPWQTBX.exe (Hewlett-Packard Company)
O4 - HKLM..Run: [IAAnotif] C:Program FilesIntelIntel Matrix Storage ManagerIaanotif.exe (Intel Corporation)
O4 - HKLM..Run: [MSC] c:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..Run: [PDVDDXSrv] C:Program FilesCyberLinkPowerDVD DXPDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..Run: [Popup] C:Program FilesDell SAS RAID Storage ManagerMegaPopupPopup.exe ( )
O4 - HKCU..Run: [Akamai NetSession Interface] C:Documents and SettingsAndyLocal SettingsApplication DataAkamainetsession_win.exe (Akamai Technologies, Inc.)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupAdobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupAutoCAD Startup Accelerator.lnk = C:Program FilesCommon FilesAutodesk Sharedacstart17.exe (Autodesk, Inc)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupNETGEAR WG111T Smart Wizard.lnk = C:Program FilesNETGEARWG111Twlan111t.exe (NETGEAR)
O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoCDBurning = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O7 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: =
O8 - Extra context menu item: Google Sidewiki… - res://C:Program FilesGoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O10 - NameSpace_Catalog5Catalog_Entries\000000000004 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O15 - HKCU..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0FCB27D0-3397-498B-ACA6-E881421153AD} https://plansonline.ggp.com/Plans/Resources…elpLauncher.cab (HelpLauncher.ProjectDoxHelp)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1229092540562 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 10.0.0.1
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{175C2E08-AC7C-4EC7-AF15-EA68A9E815C8}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - WinlogonNotify!SASWinLogon: DllName - (C:Program FilesSUPERAntiSpywareSASWINLO.DLL) - C:Program FilesSUPERAntiSpywareSASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:Documents and SettingsAndyLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsAndyLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:Program FilesWindows DefenderMpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:Program FilesSUPERAntiSpywareSASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/10 17:17:04 | 000,000,000 | —D | M] - C:Autodesk – [ NTFS ]
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | —- | M] () - C:AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = ComFile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:WINDOWSsystem32iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv41 - C:WINDOWSSystem32ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:WINDOWSSystem32ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/06 08:11:04 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopOTL
[2013/03/06 08:04:52 | 025,782,728 | —- | C] (Autodesk, Inc.) – C:Documents and SettingsAndyDesktopAutoCAD_2013_SP1.1_32bit.exe
[2013/03/01 10:07:44 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopIP2
[2013/02/28 08:00:57 | 000,000,000 | —D | C] – C:Marlette
[2013/02/20 12:18:38 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopbuddypress.1.6.4
[2013/02/19 15:04:16 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopthethe-image-slider.1.1.8.1
[2013/02/12 12:08:07 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopbiggby social
[2013/02/12 10:02:46 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopwordpress-3.5.1
[2013/02/11 11:21:45 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopMarlette addition
[2013/02/06 11:34:35 | 000,000,000 | —D | C] – C:Documents and SettingsAndyDesktopRR poster
[3 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[1 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/06 08:04:52 | 025,782,728 | —- | M] (Autodesk, Inc.) – C:Documents and SettingsAndyDesktopAutoCAD_2013_SP1.1_32bit.exe
[2013/03/06 07:59:09 | 000,000,384 | -H– | M] () – C:WINDOWStasksMicrosoft Antimalware Scheduled Scan.job
[2013/03/06 07:50:41 | 000,002,206 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2013/03/06 07:50:37 | 000,000,882 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineCore.job
[2013/03/06 07:48:31 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2013/03/06 07:48:28 | 2145,013,760 | -HS- | M] () – C:hiberfil.sys
[2013/03/06 07:39:00 | 000,000,974 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005UA.job
[2013/03/06 07:33:00 | 000,000,886 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineUA.job
[2013/03/06 05:38:00 | 000,000,922 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005Core.job
[2013/03/05 16:34:16 | 000,071,847 | —- | M] () – C:Documents and SettingsAndyDesktopCOOP.skp
[2013/03/05 14:21:02 | 000,000,868 | —- | M] () – C:WINDOWStasksGoogle Software Updater.job
[2013/03/05 03:43:35 | 000,002,333 | —- | M] () – C:Documents and SettingsAndyApplication DataMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk
[2013/03/04 10:33:46 | 000,018,733 | —- | M] () – C:Documents and SettingsAndyDesktopLAMP.jpg
[2013/03/04 07:24:00 | 000,000,284 | —- | M] () – C:WINDOWStasksAppleSoftwareUpdate.job
[2013/02/27 09:13:35 | 000,385,349 | —- | M] () – C:Documents and SettingsAndyDesktopA1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 07:45:39 | 000,475,014 | —- | M] () – C:Documents and SettingsAndyDesktopinstagram.jpg
[2013/02/25 17:26:50 | 000,336,097 | —- | M] () – C:Documents and SettingsAndyDesktopA2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 17:26:11 | 000,474,673 | —- | M] () – C:Documents and SettingsAndyDesktopA1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 16:51:15 | 000,391,153 | —- | M] () – C:Documents and SettingsAndyDesktopA1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 16:00:53 | 000,000,138 | —- | M] () – C:Documents and SettingsAndyDesktoptube.htm
[2013/02/21 13:01:21 | 000,060,032 | —- | M] () – C:Documents and SettingsAndyDesktopMarlette Elementary Frost Slabs.pdf
[2013/02/21 11:18:38 | 000,359,943 | —- | M] () – C:Documents and SettingsAndyDesktopA5.1 - Roof Details.pdf
[2013/02/21 11:18:09 | 000,234,202 | —- | M] () – C:Documents and SettingsAndyDesktopA5.0 - Roof Plans.pdf
[2013/02/20 16:15:21 | 000,366,036 | —- | M] () – C:Documents and SettingsAndyDesktoptruck-single.jpg
[2013/02/20 13:31:43 | 000,304,118 | —- | M] () – C:Documents and SettingsAndyDesktopElevations.dwg
[2013/02/20 12:17:14 | 001,527,671 | —- | M] () – C:Documents and SettingsAndyDesktopbuddypress.1.6.4.zip
[2013/02/20 10:56:52 | 000,051,344 | —- | M] () – C:Documents and SettingsAndyDesktopsnow in mqt.jpg
[2013/02/20 10:10:38 | 000,298,143 | —- | M] () – C:Documents and SettingsAndyDesktopExisting Windows.jpg
[2013/02/20 10:04:18 | 000,324,577 | —- | M] () – C:Documents and SettingsAndyDesktopElevations.bak
[2013/02/19 15:25:04 | 000,079,423 | —- | M] () – C:Documents and SettingsAndyDesktopmidlandfacade.jpg
[2013/02/19 15:24:59 | 000,072,736 | —- | M] () – C:Documents and SettingsAndyDesktopflatrock.jpg
[2013/02/19 15:24:55 | 000,398,359 | —- | M] () – C:Documents and SettingsAndyDesktopwoodland-park-1.jpg
[2013/02/19 15:03:41 | 000,447,147 | —- | M] () – C:Documents and SettingsAndyDesktopthethe-image-slider.1.1.8.1.zip
[2013/02/18 16:27:46 | 000,542,238 | —- | M] () – C:WINDOWSSystem32perfh009.dat
[2013/02/18 16:27:46 | 000,104,144 | —- | M] () – C:WINDOWSSystem32perfc009.dat
[2013/02/18 07:37:37 | 000,380,040 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2013/02/15 18:27:16 | 000,001,374 | —- | M] () – C:WINDOWSimsins.BAK
[2013/02/15 18:08:22 | 000,001,945 | —- | M] () – C:WINDOWSepplauncher.mif
[2013/02/14 07:53:01 | 000,181,901 | —- | M] () – C:Documents and SettingsAndyDesktopMARLETTE JR SR.dwg
[2013/02/13 08:36:19 | 000,645,574 | —- | M] () – C:Documents and SettingsAndyMy DocumentsArchitectural 2-1-13 dd reveiw.dwf
[2013/02/12 16:56:04 | 001,615,313 | —- | M] () – C:Documents and SettingsAndyMy DocumentsSLED.skp
[2013/02/12 16:51:26 | 000,054,474 | —- | M] () – C:Documents and SettingsAndyDesktopSLED.jpg
[2013/02/12 12:07:03 | 000,007,576 | —- | M] () – C:Documents and SettingsAndyDesktopwordpress-logo.png
[2013/02/12 12:05:03 | 000,017,910 | —- | M] () – C:Documents and SettingsAndyDesktopBiggby_Coffee_Logo.png
[2013/02/12 11:57:29 | 000,000,184 | —- | M] () – C:Documents and SettingsAndyDesktopphp.ini
[2013/02/12 11:43:45 | 000,028,331 | —- | M] () – C:Documents and SettingsAndyDesktopandy.jpg
[2013/02/12 10:32:35 | 000,262,546 | —- | M] () – C:Documents and SettingsAndyDesktopbuddypress-group-documents.zip
[2013/02/12 10:01:09 | 005,440,753 | —- | M] () – C:Documents and SettingsAndyDesktopwordpress-3.5.1.zip
[2013/02/12 09:26:35 | 000,078,195 | —- | M] () – C:Documents and SettingsAndyDesktopSidewalk.skp
[2013/02/11 11:23:23 | 000,445,908 | —- | M] () – C:Documents and SettingsAndyDesktopBase Concepts.dwg
[2013/02/11 11:23:07 | 000,620,974 | —- | M] () – C:Documents and SettingsAndyDesktopBase Concepts.bak
[2013/02/07 16:16:33 | 000,000,053 | —- | M] () – C:Documents and SettingsAndyDesktopgoogle8d1333126cc0f762.html
[2013/02/06 09:52:33 | 000,213,175 | —- | M] () – C:Documents and SettingsAndyDesktop\02 01 13 Brochure.pdf
[2013/02/04 10:30:42 | 002,280,021 | —- | M] () – C:Documents and SettingsAndyDesktopNathan Clisch.jpg
[2013/02/04 09:39:04 | 002,170,724 | —- | M] () – C:Documents and SettingsAndyDesktop8x5.jpg
[3 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[1 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/05 16:34:16 | 000,071,847 | —- | C] () – C:Documents and SettingsAndyDesktopCOOP.skp
[2013/03/04 10:33:43 | 000,018,733 | —- | C] () – C:Documents and SettingsAndyDesktopLAMP.jpg
[2013/02/27 09:13:30 | 000,385,349 | —- | C] () – C:Documents and SettingsAndyDesktopA1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 07:45:38 | 000,475,014 | —- | C] () – C:Documents and SettingsAndyDesktopinstagram.jpg
[2013/02/25 17:26:49 | 000,336,097 | —- | C] () – C:Documents and SettingsAndyDesktopA2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 17:26:09 | 000,474,673 | —- | C] () – C:Documents and SettingsAndyDesktopA1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 16:51:13 | 000,391,153 | —- | C] () – C:Documents and SettingsAndyDesktopA1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 15:53:20 | 000,000,138 | —- | C] () – C:Documents and SettingsAndyDesktoptube.htm
[2013/02/21 13:01:18 | 000,060,032 | —- | C] () – C:Documents and SettingsAndyDesktopMarlette Elementary Frost Slabs.pdf
[2013/02/21 11:18:37 | 000,359,943 | —- | C] () – C:Documents and SettingsAndyDesktopA5.1 - Roof Details.pdf
[2013/02/21 11:17:57 | 000,234,202 | —- | C] () – C:Documents and SettingsAndyDesktopA5.0 - Roof Plans.pdf
[2013/02/20 16:15:14 | 000,366,036 | —- | C] () – C:Documents and SettingsAndyDesktoptruck-single.jpg
[2013/02/20 12:16:50 | 001,527,671 | —- | C] () – C:Documents and SettingsAndyDesktopbuddypress.1.6.4.zip
[2013/02/20 10:56:39 | 000,051,344 | —- | C] () – C:Documents and SettingsAndyDesktopsnow in mqt.jpg
[2013/02/20 10:10:37 | 000,298,143 | —- | C] () – C:Documents and SettingsAndyDesktopExisting Windows.jpg
[2013/02/19 15:25:04 | 000,079,423 | —- | C] () – C:Documents and SettingsAndyDesktopmidlandfacade.jpg
[2013/02/19 15:24:59 | 000,072,736 | —- | C] () – C:Documents and SettingsAndyDesktopflatrock.jpg
[2013/02/19 15:24:53 | 000,398,359 | —- | C] () – C:Documents and SettingsAndyDesktopwoodland-park-1.jpg
[2013/02/19 15:03:36 | 000,447,147 | —- | C] () – C:Documents and SettingsAndyDesktopthethe-image-slider.1.1.8.1.zip
[2013/02/19 10:20:52 | 000,324,577 | —- | C] () – C:Documents and SettingsAndyDesktopElevations.bak
[2013/02/19 10:20:52 | 000,304,118 | —- | C] () – C:Documents and SettingsAndyDesktopElevations.dwg
[2013/02/15 18:17:30 | 000,000,384 | -H– | C] () – C:WINDOWStasksMicrosoft Antimalware Scheduled Scan.job
[2013/02/14 07:53:01 | 000,181,901 | —- | C] () – C:Documents and SettingsAndyDesktopMARLETTE JR SR.dwg
[2013/02/13 08:36:19 | 000,645,574 | —- | C] () – C:Documents and SettingsAndyMy DocumentsArchitectural 2-1-13 dd reveiw.dwf
[2013/02/12 16:56:03 | 001,615,313 | —- | C] () – C:Documents and SettingsAndyMy DocumentsSLED.skp
[2013/02/12 16:51:26 | 000,054,474 | —- | C] () – C:Documents and SettingsAndyDesktopSLED.jpg
[2013/02/12 12:05:01 | 000,017,910 | —- | C] () – C:Documents and SettingsAndyDesktopBiggby_Coffee_Logo.png
[2013/02/12 11:43:38 | 000,028,331 | —- | C] () – C:Documents and SettingsAndyDesktopandy.jpg
[2013/02/12 11:16:45 | 000,000,184 | —- | C] () – C:Documents and SettingsAndyDesktopphp.ini
[2013/02/12 10:32:34 | 000,262,546 | —- | C] () – C:Documents and SettingsAndyDesktopbuddypress-group-documents.zip
[2013/02/12 10:13:41 | 000,007,576 | —- | C] () – C:Documents and SettingsAndyDesktopwordpress-logo.png
[2013/02/12 10:00:20 | 005,440,753 | —- | C] () – C:Documents and SettingsAndyDesktopwordpress-3.5.1.zip
[2013/02/12 09:26:35 | 000,078,195 | —- | C] () – C:Documents and SettingsAndyDesktopSidewalk.skp
[2013/02/11 09:07:01 | 000,620,974 | —- | C] () – C:Documents and SettingsAndyDesktopBase Concepts.bak
[2013/02/11 09:07:01 | 000,445,908 | —- | C] () – C:Documents and SettingsAndyDesktopBase Concepts.dwg
[2013/02/07 16:16:27 | 000,000,053 | —- | C] () – C:Documents and SettingsAndyDesktopgoogle8d1333126cc0f762.html
[2013/02/06 09:52:32 | 000,213,175 | —- | C] () – C:Documents and SettingsAndyDesktop\02 01 13 Brochure.pdf
[2013/02/04 10:27:58 | 002,280,021 | —- | C] () – C:Documents and SettingsAndyDesktopNathan Clisch.jpg
[2013/02/04 09:39:02 | 002,170,724 | —- | C] () – C:Documents and SettingsAndyDesktop8x5.jpg
[2012/12/06 12:01:56 | 000,000,248 | —- | C] () – C:WINDOWSFXEZQJV.INI
[2012/07/31 11:04:23 | 000,000,811 | —- | C] () – C:Documents and SettingsAndy.recently-used.xbel
[2012/02/15 01:12:11 | 000,003,072 | —- | C] () – C:WINDOWSSystem32iacenc.dll
[2011/11/28 17:22:23 | 000,000,000 | —- | C] () – C:WINDOWSTMonitor.INI
[2011/10/13 15:29:11 | 000,110,456 | —- | C] () – C:Documents and SettingsAndyg2ax_customer_downloadhelper_win32_x86.exe
[2011/10/10 14:07:33 | 000,256,000 | —- | C] () – C:WINDOWSPEV.exe
[2011/10/10 14:07:33 | 000,208,896 | —- | C] () – C:WINDOWSMBR.exe
[2011/10/10 14:07:33 | 000,098,816 | —- | C] () – C:WINDOWSsed.exe
[2011/10/10 14:07:33 | 000,080,412 | —- | C] () – C:WINDOWSgrep.exe
[2011/10/10 14:07:33 | 000,068,096 | —- | C] () – C:WINDOWSzip.exe
[2011/09/16 16:57:43 | 000,879,964 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-1682135861-2545026859-4075531753-1005-0.dat
[2011/09/16 16:57:41 | 000,365,678 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-System.dat
[2011/09/06 18:08:37 | 000,000,147 | —- | C] () – C:Documents and SettingsAll UsersApplication DataMicrosoft.SqlServer.Compact.351.32.bc
[2011/03/16 08:38:22 | 000,000,000 | —- | C] () – C:WINDOWSnsreg.dat
[2009/06/12 07:40:32 | 000,120,838 | —- | C] () – C:Documents and SettingsAndyApplication Datamsvideo_flv.cab
[2009/06/11 13:33:29 | 000,001,636 | —- | C] () – C:Documents and SettingsAndyApplication Datamsvideo_3gp.cab
[2009/03/20 09:57:43 | 000,000,000 | —- | C] () – C:Documents and SettingsAndyApplication Datamsvideo_avi.cab
[2009/03/20 09:57:42 | 000,001,539 | —- | C] () – C:Documents and SettingsAndyApplication Datamsvideo_mpg.dat
[2009/03/12 09:56:41 | 000,001,541 | —- | C] () – C:Documents and SettingsAndyApplication Dataupdate_sp1v1.cab
[2009/03/12 09:56:41 | 000,000,016 | —- | C] () – C:Documents and SettingsAndyApplication Dataupdate_sp1v2.cab
[2008/12/12 09:34:03 | 000,043,520 | —- | C] () – C:Documents and SettingsAndyLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2008/04/25 16:34:35 | 000,000,227 | RHS- | M] () – C:WINDOWSassemblyDesktop.ini

[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]

[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]

[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shdocvw.dll – [2010/09/09 09:16:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = C:WINDOWSsystem32wbemfastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = C:WINDOWSsystem32wbemwbemess.dll – [2008/04/14 07:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/04/14 11:51:13 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataActMask EMF2PDF SDK
[2013/01/10 17:13:03 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataApplications
[2012/08/06 12:09:31 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataASGVIS
[2013/01/17 09:37:16 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAutodesk
[2012/11/12 11:55:32 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Databoost_interprocess
[2010/04/12 10:07:01 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataCanon
[2010/03/25 15:22:25 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Datae-onsoftware
[2009/02/02 16:40:55 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataKaren's Power Tools
[2008/12/12 10:25:38 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNitro PDF
[2010/05/17 11:36:38 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataOptiTex
[2012/11/12 11:19:15 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataPDF reDirect
[2009/07/01 10:51:43 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataTEMP
[2011/07/07 08:52:47 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataWinZipEC
[2012/01/27 11:16:10 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/14 17:44:47 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2013/01/17 09:37:16 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataAutodesk
[2010/03/12 09:02:32 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataBlender Foundation
[2013/03/02 18:03:50 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataCoreFTP
[2010/05/17 11:34:13 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataDAZ 3D
[2011/09/07 08:03:33 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataDropbox
[2010/03/25 13:33:43 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication Datae-on software
[2013/02/20 11:37:48 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataFileZilla
[2011/01/27 16:57:42 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataFontCreator
[2012/11/28 10:32:01 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataFuji Xerox
[2011/08/29 13:11:05 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataGetRightToGo
[2010/01/28 15:15:26 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataImgBurn
[2010/12/06 10:00:25 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication Datainkscape
[2008/12/12 10:26:09 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataNitro PDF
[2011/07/18 13:30:58 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataNotepad++
[2012/02/20 09:07:29 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataOracle
[2012/11/12 11:19:15 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataPDF reDirect
[2012/06/19 14:31:15 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DatauTorrent
[2008/12/12 09:48:35 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataWindows Search
[2008/12/12 14:26:55 | 000,000,000 | —D | M] – C:Documents and SettingsAndyApplication DataXerox

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%..|smtmp;true;true;true /FP >

< %temp%smtmp*.* /s > >

< MD5 for: EXPLORER.DESIGNER.VB >
[2008/07/30 05:54:20 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostArchitecture20129.0ItemTemplatesCacheVisualBasicWind
ows Forms1033Explorer.zipexplorer.designer.vb
[2008/07/30 05:54:20 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostMEP20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.designer.vb
[2008/07/30 05:54:20 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostStructure20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.designer.vb

< MD5 for: EXPLORER.EX_ >
[2008/04/14 07:00:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:I386EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:WINDOWSERDNTcacheexplorer.exe
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:WINDOWSexplorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2013/03/06 07:50:48 | 000,028,076 | —- | M] () MD5=D7787A161BC057ED548173155832CA73 – C:WINDOWSPrefetchEXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.HTM >
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguagesdewwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguagesenwwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguageseswwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguagesfrwwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguagesjawwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguageskowwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguageszh-CNwwhelpwwhimpljavahtmlexplorer.htm
[2003/05/19 14:37:54 | 000,002,160 | —- | M] () MD5=40C6F4D57261630B95830FBACD05EE91 – C:Program FilesDell SAS RAID Storage ManagerdocsLanguageszh-TWwwhelpwwhimpljavahtmlexplorer.htm

< MD5 for: EXPLORER.RESX >
[2008/07/30 05:54:20 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostArchitecture20129.0ItemTemplatesCacheVisualBasicWind
ows Forms1033Explorer.zipexplorer.resx
[2008/07/30 05:54:20 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostMEP20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.resx
[2008/07/30 05:54:20 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostStructure20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.resx

< MD5 for: EXPLORER.SC_ >
[2008/04/14 07:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:I386EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2008/04/14 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:WINDOWSexplorer.scf

< MD5 for: EXPLORER.VB >
[2008/07/30 05:54:20 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostArchitecture20129.0ItemTemplatesCacheVisualBasicWind
ows Forms1033Explorer.zipexplorer.vb
[2008/07/30 05:54:20 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostMEP20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.vb
[2008/07/30 05:54:20 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostStructure20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.vb

< MD5 for: EXPLORER.VSTEMPLATE >
[2008/07/30 05:54:20 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostArchitecture20129.0ItemTemplatesCacheVisualBasicWind
ows Forms1033Explorer.zipexplorer.vstemplate
[2008/07/30 05:54:20 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostMEP20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.vstemplate
[2008/07/30 05:54:20 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – C:Documents and SettingsAll UsersApplication DataMicrosoftVSTAHostStructure20129.0ItemTemplatesCacheVisualBasicWindows Forms1033Explorer.zipexplorer.vstemplate

< MD5 for: EXPLORER.ZIP >
[2008/07/30 05:54:22 | 000,024,306 | —- | M] () MD5=15FB707D04E269482E95D08430955719 – C:Program FilesMicrosoft Visual Studio 9.0Common7IDEItemTemplatesVisualBasicWindows Forms1033Explorer.zip

< MD5 for: IEXPLORE.CH_ >
[2008/04/14 07:00:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:I386IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:WINDOWSHelpiexplore.chm
[2008/04/14 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:WINDOWSie8iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2008/04/14 07:00:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:I386IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/04/14 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:WINDOWSie8iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:Program FilesInternet Exploreriexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:WINDOWSERDNTcacheiexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:WINDOWSsystem32dllcacheiexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:Program FilesInternet Exploreren-USiexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:Program FilesInternet Exploreriexplore.exe.mui

< MD5 for: IEXPLORE.HL_ >
[2008/04/14 07:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:I386IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2008/04/14 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:WINDOWSHelpiexplore.hlp

< MD5 for: SERVICES >
[2013/01/16 22:29:49 | 000,007,384 | —- | M] () MD5=82DA564975512ECCD2A7C951BDFCD9F8 – C:WINDOWSsystem32driversetcservices

< MD5 for: SERVICES._ >
[2008/04/14 07:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:I386SERVICES._

< MD5 for: SERVICES.CFG >
[2012/12/18 09:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:Program FilesAdobeReader 10.0ReaderServicesServices.cfg
[2011/06/06 11:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:WINDOWSInstaller$PatchCache$Managed68AB67CA7DA73301B744AA010000001010.1.0services.cfg

< MD5 for: SERVICES.EX_ >
[2008/04/14 07:00:00 | 000,049,959 | —- | M] () MD5=EE4885163C0C0729A3C5F1416A6E5F48 – C:I386SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:WINDOWS$hf_mig$KB956572SP3QFEservices.exe
[2008/04/14 07:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:WINDOWS$NtUninstallKB956572$services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:WINDOWSERDNTcacheservices.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:WINDOWSsystem32dllcacheservices.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:WINDOWSsystem32services.exe

< MD5 for: SERVICES.HTM >
[2009/10/12 08:11:28 | 000,003,126 | —- | M] () MD5=4B53D6D0FD009F77BEE7CCCBCC8AA213 – C:Documents and SettingsAll UsersDesktopAndy's carp**Hartland SepticHartland Septicservices.htm

< MD5 for: SERVICES.JPG.JPG >
[2011/12/28 14:37:12 | 000,053,853 | —- | M] () MD5=6A30D0AE4E7014DF6AA4D5172786CDCB – C:Documents and SettingsAndyDesktopWeb Site StuffIron FitnessFull Transferwp-contentuploads201112services.jpg.jpg
[2012/08/14 10:28:25 | 000,054,100 | —- | M] () MD5=81CF9D61AD16B7D3A2826A6F300A8954 – C:RECYCLERS-1-5-21-1682135861-2545026859-4075531753-1005Dc319uploads201112services.jpg.jpg

< MD5 for: SERVICES.JPG-100X100.JPG >
[2011/12/28 14:37:12 | 000,004,541 | —- | M] () MD5=CAA5F87FF8ECDEDDF12CB248CA281977 – C:Documents and SettingsAndyDesktopWeb Site StuffIron FitnessFull Transferwp-contentuploads201112services.jpg-100x100.jpg
[2012/08/14 10:28:25 | 000,004,558 | —- | M] () MD5=DDEE39C5C18C394EA8858088B4FE7661 – C:RECYCLERS-1-5-21-1682135861-2545026859-4075531753-1005Dc319uploads201112services.jpg-100x100.jpg

< MD5 for: SERVICES.JPG-225X300.JPG >
[2012/08/14 10:28:25 | 000,018,837 | —- | M] () MD5=5613B2F903FB5C91B7B3F6CEFE8890B7 – C:RECYCLERS-1-5-21-1682135861-2545026859-4075531753-1005Dc319uploads201112services.jpg-225x300.jpg
[2011/12/28 14:37:12 | 000,018,778 | —- | M] () MD5=D6F2583D5FDD0AEC8D1B025961867659 – C:Documents and SettingsAndyDesktopWeb Site StuffIron FitnessFull Transferwp-contentuploads201112services.jpg-225x300.jpg

< MD5 for: SERVICES.JPG-540X288.JPG >
[2012/08/14 10:28:24 | 000,035,014 | —- | M] () MD5=258A1CA3ACEFBE6B19B4D449CC805ECC – C:RECYCLERS-1-5-21-1682135861-2545026859-4075531753-1005Dc319uploads201112services.jpg-540x288.jpg
[2011/12/28 14:37:12 | 000,034,953 | —- | M] () MD5=2B24135BF30F5139ACD5E97D80E00C52 – C:Documents and SettingsAndyDesktopWeb Site StuffIron FitnessFull Transferwp-contentuploads201112services.jpg-540x288.jpg

< MD5 for: SERVICES.LNK >
[2009/03/09 09:24:35 | 000,001,604 | —- | M] () MD5=1EB5DD5F55788792948734F877DF732C – C:Documents and SettingsAll UsersStart MenuProgramsAdministrative ToolsServices.LNK

< MD5 for: SERVICES.MS_ >
[2008/04/14 07:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:I386SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2008/04/14 07:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:WINDOWSsystem32services.msc

< MD5 for: WINLOGON.EX_ >
[2008/04/14 07:00:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:I386WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:WINDOWSERDNTcachewinlogon.exe
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:WINDOWSsystem32winlogon.exe

< %SYSTEMDRIVE%*.* >
[2009/05/11 06:33:29 | 001,963,837 | —- | M] () – C:1 - Plot plan, Schedule.pdf
[2009/05/11 04:22:07 | 003,449,963 | —- | M] () – C:1 Site Plan.pdf
[2009/01/14 10:35:26 | 000,417,956 | —- | M] () – C:11x17 - Facility Upgrades - HS.dwg
[2009/04/10 14:33:06 | 000,121,984 | —- | M] () – C:8.5X11 DRAWING TEMPLATE.dwt
[2009/05/27 09:55:05 | 000,448,775 | —- | M] () – C:A10-FloorPlan.dwg
[2003/05/14 04:15:31 | 000,819,923 | —- | M] () – C:A10-FloorPlans.dwg
[2010/04/09 13:23:35 | 000,069,696 | —- | M] () – C:acadminidump.dmp
[2008/12/18 14:49:06 | 001,089,036 | —- | M] () – C:Andy.tif
[2008/04/25 16:29:32 | 000,000,000 | —- | M] () – C:AUTOEXEC.BAT
[2009/04/20 09:57:16 | 000,939,357 | —- | M] () – C:baseplan_High&MiddleSchool.dwg;
[2008/12/11 11:11:29 | 000,000,211 | —- | M] () – C:Boot.bak
[2012/07/24 08:23:40 | 000,000,327 | RHS- | M] () – C:boot.ini
[2004/08/03 22:00:00 | 000,260,272 | RHS- | M] () – C:cmldr
[2011/10/10 17:30:44 | 000,016,642 | —- | M] () – C:ComboFix.txt
[2008/04/25 16:29:32 | 000,000,000 | —- | M] () – C:CONFIG.SYS
[2008/12/07 05:06:05 | 000,005,099 | RH– | M] () – C:dell.sdr
[2009/05/11 08:04:51 | 001,099,505 | —- | M] () – C:EA14 - Wall Sections.pdf
[2005/03/21 11:28:20 | 000,498,560 | —- | M] () – C:ElemSchoolFP.dwg
[2009/04/17 13:28:16 | 000,000,231 | —- | M] () – C:filelist.xml
[2006/02/17 14:05:11 | 001,413,440 | —- | M] () – C:Final-Small.tif
[2012/08/09 16:18:09 | 034,031,720 | —- | M] (Google) – C:GoogleSketchUpWEN R7.exe
[2009/11/22 03:04:26 | 074,245,879 | —- | M] () – C:grandpa.wmv
[2009/05/11 08:47:05 | 001,428,798 | —- | M] () – C:HC1 - Site Plan.pdf
[2013/03/06 07:48:28 | 2145,013,760 | -HS- | M] () – C:hiberfil.sys
[2009/03/23 14:47:01 | 000,011,466 | —- | M] () – C:history page for website.docx
[2009/02/17 10:20:14 | 000,316,141 | —- | M] () – C:HP20 PLUMBING ENLARGED.dwg
[2010/02/01 19:02:00 | 000,000,520 | —- | M] () – C:IDI.bat
[2007/07/17 05:54:47 | 000,003,478 | —- | M] () – C:index.inc.php
[2008/04/25 16:29:32 | 000,000,000 | -H– | M] () – C:IO.SYS
[2010/05/24 09:16:11 | 000,748,544 | —- | M] () – C:Job Log.xls
[2006/01/19 09:06:36 | 001,281,592 | —- | M] () – C:Judy.tif
[2012/04/30 08:41:02 | 000,374,372 | —- | M] () – C:M1.0 - Mechanical Plan.dwg
[2009/08/19 13:24:13 | 000,810,718 | —- | M] () – C:M2-1 - Area B.dwg
[2009/07/29 12:13:55 | 000,440,309 | —- | M] () – C:M200 - Mech Plan-B & D-G.dwg
[2008/04/25 16:29:32 | 000,000,000 | -H– | M] () – C:MSDOS.SYS
[2011/12/08 17:25:50 | 000,559,156 | —- | M] () – C:Negaunee Concessions.jpg
[2009/05/08 07:55:48 | 000,000,439 | —- | M] () – C:nsinst.log
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:ntldr
[2013/03/06 07:48:26 | 2145,386,496 | -HS- | M] () – C:pagefile.sys
[2007/04/05 08:58:35 | 000,806,408 | —- | M] () – C:Picture 008.jpg
[2011/08/03 09:10:51 | 000,002,191 | —- | M] () – C:plot.log
[2011/09/01 07:22:43 | 000,608,768 | —- | M] () – C:Proposals Log.xls
[2010/11/10 17:12:48 | 000,000,268 | -H– | M] () – C:sqmdata00.sqm
[2010/11/12 16:58:11 | 000,000,268 | -H– | M] () – C:sqmdata01.sqm
[2010/11/18 17:28:51 | 000,000,268 | -H– | M] () – C:sqmdata02.sqm
[2010/11/19 18:01:43 | 000,000,268 | -H– | M] () – C:sqmdata03.sqm
[2010/11/23 17:50:51 | 000,000,268 | -H– | M] () – C:sqmdata04.sqm
[2010/12/03 17:52:03 | 000,000,268 | -H– | M] () – C:sqmdata05.sqm
[2010/12/07 14:24:40 | 000,000,268 | -H– | M] () – C:sqmdata06.sqm
[2010/12/10 10:47:04 | 000,000,268 | -H– | M] () – C:sqmdata07.sqm
[2010/12/10 17:31:30 | 000,000,268 | -H– | M] () – C:sqmdata08.sqm
[2010/12/10 17:39:05 | 000,000,268 | -H– | M] () – C:sqmdata09.sqm
[2010/12/14 08:55:40 | 000,000,268 | -H– | M] () – C:sqmdata10.sqm
[2010/12/17 18:13:12 | 000,000,268 | -H– | M] () – C:sqmdata11.sqm
[2010/12/22 17:39:42 | 000,000,268 | -H– | M] () – C:sqmdata12.sqm
[2010/12/29 13:49:24 | 000,000,268 | -H– | M] () – C:sqmdata13.sqm
[2011/01/04 13:47:06 | 000,000,268 | -H– | M] () – C:sqmdata14.sqm
[2011/01/05 16:53:02 | 000,000,268 | -H– | M] () – C:sqmdata15.sqm
[2011/01/27 13:43:21 | 000,000,268 | -H– | M] () – C:sqmdata16.sqm
[2011/01/28 18:08:57 | 000,000,268 | -H– | M] () – C:sqmdata17.sqm
[2010/11/02 08:15:40 | 000,000,268 | -H– | M] () – C:sqmdata18.sqm
[2010/11/02 16:48:52 | 000,000,268 | -H– | M] () – C:sqmdata19.sqm
[2010/11/10 17:12:48 | 000,000,244 | -H– | M] () – C:sqmnoopt00.sqm
[2010/11/12 16:58:11 | 000,000,244 | -H– | M] () – C:sqmnoopt01.sqm
[2010/11/18 17:28:51 | 000,000,244 | -H– | M] () – C:sqmnoopt02.sqm
[2010/11/19 18:01:43 | 000,000,244 | -H– | M] () – C:sqmnoopt03.sqm
[2010/11/23 17:50:51 | 000,000,244 | -H– | M] () – C:sqmnoopt04.sqm
[2010/12/03 17:52:03 | 000,000,244 | -H– | M] () – C:sqmnoopt05.sqm
[2010/12/07 14:24:40 | 000,000,244 | -H– | M] () – C:sqmnoopt06.sqm
[2010/12/10 10:47:04 | 000,000,244 | -H– | M] () – C:sqmnoopt07.sqm
[2010/12/10 17:31:30 | 000,000,244 | -H– | M] () – C:sqmnoopt08.sqm
[2010/12/10 17:39:05 | 000,000,244 | -H– | M] () – C:sqmnoopt09.sqm
[2010/12/14 08:55:40 | 000,000,244 | -H– | M] () – C:sqmnoopt10.sqm
[2010/12/17 18:13:12 | 000,000,244 | -H– | M] () – C:sqmnoopt11.sqm
[2010/12/22 17:39:42 | 000,000,244 | -H– | M] () – C:sqmnoopt12.sqm
[2010/12/29 13:49:23 | 000,000,244 | -H– | M] () – C:sqmnoopt13.sqm
[2011/01/04 13:47:06 | 000,000,244 | -H– | M] () – C:sqmnoopt14.sqm
[2011/01/05 16:53:02 | 000,000,244 | -H– | M] () – C:sqmnoopt15.sqm
[2011/01/27 13:43:21 | 000,000,244 | -H– | M] () – C:sqmnoopt16.sqm
[2011/01/28 18:08:57 | 000,000,244 | -H– | M] () – C:sqmnoopt17.sqm
[2010/11/02 08:15:40 | 000,000,244 | -H– | M] () – C:sqmnoopt18.sqm
[2010/11/02 16:48:52 | 000,000,244 | -H– | M] () – C:sqmnoopt19.sqm
[2011/01/04 15:06:21 | 000,142,422 | —- | M] () – C:StarBurn.log
[2010/07/29 18:08:30 | 000,007,587 | —- | M] () – C:style.css
[2011/04/05 15:35:11 | 000,000,000 | —- | M] () – C:VRLServer2.txt

< %systemroot%Fonts*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2008/04/25 16:29:00 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2008/09/16 15:24:58 | 000,098,304 | —- | M] () – C:WINDOWSsystem32spoolprtprocsw32x86aloaha_prntproc.dll
[2006/04/18 22:15:22 | 000,010,240 | —- | M] (CANON INC.) – C:WINDOWSsystem32spoolprtprocsw32x86CNWFDPL4.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2005/05/10 16:14:32 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86hpzpp3xt.dll
[2003/06/18 17:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >
[2008/04/25 04:21:09 | 000,094,208 | —- | M] () – C:WINDOWSSystem32configdefault.sav
[2008/04/25 04:21:09 | 001,089,536 | —- | M] () – C:WINDOWSSystem32configsoftware.sav
[2008/04/25 04:21:09 | 000,905,216 | —- | M] () – C:WINDOWSSystem32configsystem.sav

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2008/04/25 16:29:41 | 000,000,294 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2008/12/11 11:11:53 | 000,000,119 | -HS- | M] () – C:Documents and SettingsAndyApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2008/04/25 16:33:01 | 000,000,079 | —- | M] () – C:Documents and SettingsAndyApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf

< %USERPROFILE%Desktop*.exe >
[2013/03/06 08:04:52 | 025,782,728 | —- | M] (Autodesk, Inc.) – C:Documents and SettingsAndyDesktopAutoCAD_2013_SP1.1_32bit.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2013-02-15 23:51:25

========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:Documents and SettingsAll UsersApplication DataTEMP:4096C9B2
@Alternate Data Stream - 110 bytes -> C:Documents and SettingsAll UsersApplication DataTEMP:24975D5E

< End of report >

Extras.txt

OTL Extras logfile created on: 3/6/2013 8:13:17 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and SettingsAndyDesktopOTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 61.92% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.06% Paging File free
Paging file location(s): C:pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.76 Gb Total Space | 123.03 Gb Free Space | 52.86% Space Free | Partition Type: NTFS
Drive D: | 50.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MODEL | User Name: Andy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = ChromeHTML] – C:Documents and SettingsAndyLocal SettingsApplication DataGoogleChromeApplicationchrome.exe (Google Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewall]

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfile]

[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileGloballyOpenPortsList]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"50248:TCP" = 50248:TCP:*:Enabled:Autodesk Content Service
"1067:TCP" = 1067:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe" = %windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:Program FilesWindows LiveMessengermsnmsgr.exe" = C:Program FilesWindows LiveMessengermsnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:Program FilesWindows LiveMessengerlivecall.exe" = C:Program FilesWindows LiveMessengerlivecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:Program FilesCommon FilesaloahaCertInstaller.exe" = C:Program FilesCommon FilesaloahaCertInstaller.exe:*:Enabled:CertInstaller – (Aloaha Limited)
"C:Program FilesWrocklagecreator.exe" = C:Program FilesWrocklagecreator.exe:*:Enabled:creator.exe – (Aloaha Limited)

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"%windir%Network Diagnosticxpnetdiag.exe" = %windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:Program FilesDell SAS RAID Storage ManagerMegaPopuppopup.exe" = C:Program FilesDell SAS RAID Storage ManagerMegaPopuppopup.exe:*:Disabled:popup – ( )
"C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE" = C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:Program FilesWindows LiveMessengermsnmsgr.exe" = C:Program FilesWindows LiveMessengermsnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:Program FilesWindows LiveMessengerlivecall.exe" = C:Program FilesWindows LiveMessengerlivecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:Program FilesYahoo!MessengerYahooMessenger.exe" = C:Program FilesYahoo!MessengerYahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:Program FilesHewlett-PackardHP Deskjet 9800 SeriesToolboxHPWQTBX.exe" = C:Program FilesHewlett-PackardHP Deskjet 9800 SeriesToolboxHPWQTBX.exe:*:Enabled:Toolbox for HP Printing System for Windows – (Hewlett-Packard Company)
"C:Program FilesuTorrentuTorrent.exe" = C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:Program FilesSonicWALLSonicWALL Global VPN ClientSWGVC.exe" = C:Program FilesSonicWALLSonicWALL Global VPN ClientSWGVC.exe:*:Enabled:SonicWALL Global VPN Client – (SonicWALL, Inc.)
"C:Program FilesWrocklagecreator.exe" = C:Program FilesWrocklagecreator.exe:*:Enabled:creator.exe – (Aloaha Limited)
"C:Program FilesCommon FilesaloahaCertInstaller.exe" = C:Program FilesCommon FilesaloahaCertInstaller.exe:*:Enabled:CertInstaller – (Aloaha Limited)
"C:Program FilesGoogleGoogle Earthclientgoogleearth.exe" = C:Program FilesGoogleGoogle Earthclientgoogleearth.exe:*:Enabled:Google Earth – (Google)
"C:Documents and SettingsAndyMy DocumentsDownloadsutorrent.exe" = C:Documents and SettingsAndyMy DocumentsDownloadsutorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:Program FilesGoogleGoogle SketchUp 8SketchUp.exe" = C:Program FilesGoogleGoogle SketchUp 8SketchUp.exe:*:Enabled:SketchUp Application – (Google, Inc.)
"C:Documents and SettingsAndyApplication DataDropboxbinDropbox.exe" = C:Documents and SettingsAndyApplication DataDropboxbinDropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"C:Program FilesCoreFTPcoreftp.exe" = C:Program FilesCoreFTPcoreftp.exe:*:Enabled:Core FTP App – (Core FTP)
"C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32server.exe" = C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max Design 2012 32-bit - English – ()
"C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32.exe" = C:Program FilesAutodesk3ds Max Design 2012mentalimagessatelliteraysat_3dsmax2012_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max Design 2012 32-bit - English – (mental images GmbH)
"C:Program FilesAutodesk3ds Max Design 20123dsmax.exe" = C:Program FilesAutodesk3ds Max Design 20123dsmax.exe:*:Enabled:Autodesk 3ds Max Design 2012 32-bit - English – (Autodesk, Inc.)
"C:Documents and SettingsAndyLocal SettingsApplication DataAkamainetsession_win.exe" = C:Documents and SettingsAndyLocal SettingsApplication DataAkamainetsession_win.exe:*:Disabled:netsession_win – (Akamai Technologies, Inc.)
"C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe" = C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:Program FilesBonjourmDNSResponder.exe" = C:Program FilesBonjourmDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:Program FilesiTunesiTunes.exe" = C:Program FilesiTunesiTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:Program FilesAllegorithmicSubstancePlayer2.xsubstance_player.exe" = C:Program FilesAllegorithmicSubstancePlayer2.xsubstance_player.exe:*:Enabled:Substanc
e Player – (Allegorithmic)
"C:Program FilesXerox CorporationBT-PlotAssistant 3.5BTPlotAssistant.exe" = C:Program FilesXerox CorporationBT-PlotAssistant 3.5BTPlotAssistant.exe:*:Enabled:BT-PlotAssistant – ()
"C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32server.exe" = C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max Design 2013 32-bit – ()
"C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32.exe" = C:Program FilesAutodesk3ds Max Design 2013NVIDIAraysat_3dsmax2013_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max Design 2013 32-bit – (NVIDIA Corporation)
"C:Program FilesAutodesk3ds Max Design 20133dsmax.exe" = C:Program FilesAutodesk3ds Max Design 20133dsmax.exe:*:Enabled:Autodesk 3ds Max Design 2013 32-bit – (Autodesk, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}" = Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{09A02B7A-45A5-4E24-9AF3-14B8A86E18CA}" = Dell SAS RAID Storage Manager
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{0F9ED496-774C-0409-9659-968DACF8ED58}" = Autodesk 3ds Max Design 2013 32-bit
"{1111706F-666A-4037-7777-203328764D10}" = JavaFX 2.0.3
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{14866AAD-1F23-39AC-A62B-7091ED1ADE64}" = Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729
"{177D1318-3E4B-4A7C-A300-AC4E21BE090B}" = Broadcom Management Programs
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A89C9A6-578D-4501-95D4-A5C282917BC6}" = BT-PlotAssistant
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{241E2DF6-792B-42B6-9B79-B0DF73D5A69D}" = Aloaha Suite SDK
"{24FF088D-CDCF-480C-8A4B-98F14A54CAA8}" = Autodesk Material Library Low Resolution Image Library 2012
"{26A24AE4-039D-4CA4-87B4-2F83217003FF}" = Java™ 7 Update 3
"{27C6C0A2-2EC9-4FEA-BE2B-659EAAC2C68C}" = Autodesk Material Library Low Resolution Image Library 2013
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3544DED1-07DB-40C0-98F3-435A6DA195C7}" = Google SketchUp 8
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40624553-811E-400E-B69B-38D8926A66BD}" = SonicWALL Global VPN Client
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}" = Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{51123D42-6B9C-4B93-900C-29F9EC5963C9}" = NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter
"{5783F2D7-5004-0409-0002-0060B0CE6BBA}" = Autodesk Architectural Desktop 2007
"{5783F2D7-9028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2011
"{5783F2D7-A001-0409-0002-0060B0CE6BBA}" = AutoCAD 2012 - English
"{5783F2D7-A001-0409-1002-0060B0CE6BBA}" = AutoCAD 2012 Language Pack - English
"{5783F2D7-A004-0409-0002-0060B0CE6BBA}" = AutoCAD Architecture 2012 - English
"{5783F2D7-A004-0409-1002-0060B0CE6BBA}" = AutoCAD Architecture 2012 Language Pack - English
"{5783F2D7-B001-0000-0002-0060B0CE6BBA}" = AutoCAD 2013 - English
"{5783F2D7-B001-0409-1002-0060B0CE6BBA}" = AutoCAD 2013 Language Pack - English
"{5783F2D7-B001-0409-2002-0060B0CE6BBA}" = AutoCAD 2013 - English
"{57CC1C55-00A6-4D98-9188-CA43C47B5CF4}" = Wide Format Scan Service
"{58760EEC-8B6A-43F4-81AA-696E381DFADD}" = Autodesk Material Library Medium Resolution Image Library 2013
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{62F029AB-85F2-0000-866A-9FC0DD99DDBC}" = Autodesk Content Service
"{65420DC9-306E-4371-905F-F4DC3B418E52}" = Autodesk Material Library Base Resolution Image Library 2012
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7346B4A0-1200-0100-0409-705C0D862004}" = Revit Architecture 2012
"{7346B4A0-1200-0101-0409-705C0D862004}" = Revit Architecture 2012 Language Pack - English
"{7346B4A0-1200-0200-0409-705C0D862004}" = Revit Structure 2012
"{7346B4A0-1200-0201-0409-705C0D862004}" = Revit Structure 2012 Language Pack - English
"{7346B4A0-1200-0300-0409-705C0D862004}" = Revit MEP 2012
"{7346B4A0-1200-0301-0409-705C0D862004}" = Revit MEP 2012 Language Pack - English
"{7346B4A0-1300-0500-0409-705C0D862004}" = Revit 2013
"{7346B4A0-1300-0501-0409-705C0D862004}" = Revit 2013 Language Pack - English
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7950CCD4-D8FE-4636-B827-E8502E310FA8}" = PDFIn PDF to DWG Converter
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{867DA348-D324-4764-AA7B-FF491E83DD1F}" = Xerox Corporation Wide Format Scan Service
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}" = Autodesk Material Library 2012
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91221AAC-F2A0-4028-8016-C7DAF63CB6CC}" = FARO LS 1.1.408.2
"{92FD71D5-ED7E-40B2-8DF3-4B5E6F684367}" = Dell ETS Factory Installation
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F366B0-5849-4498-B126-548A6743F459}_is1" = PDF to HTML
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}" = Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729
"{B5751715-EC10-43D9-8C95-62E1368433EF}" = Autodesk Material Library Medium Resolution Image Library 2012
"{B5A4F029-E503-4E72-9397-AFD852E49EB8}" = VGEdit
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BBAB3188-EDC7-0409-A849-659E379CB00A}" = Autodesk 3ds Max Design 2012 32-bit - English
"{BDBE1816-0010-1033-84D4-F3AD7870A018}" = Autodesk SketchBook Designer 2012 - English
"{BDBE1816-9EFC-49E5-84D4-F3AD7870A018}" = Autodesk SketchBook Designer 2012 - English
"{BEF106F8-2689-4530-925A-E1117836E8CD}" = Google SketchUp 7
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C732C76D-0010-1033-99BD-DDB8254216B8}" = Autodesk Showcase 2012 32-bit - English
"{C732C76D-7C3D-4DEB-99BD-DDB8254216B8}" = Autodesk Showcase 2012 32-bit - English
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-11AF-B2CC-ABCD21A325B4}" = WinZip Courier
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE33EC58-5DFB-4560-9D33-1E7942E0554F}" = HP Deskjet 9800
"{D672018C-BCC5-4994-94FD-BF2EF24865F4}" = Autodesk Download Manager
"{E1423608-F529-40A1-93CA-C7F396F30DF0}" = Google SketchUp
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4478A0E-53A8-42B8-840E-05B2228ECAB9}" = W6400PG Printer Driver Extra Kit
"{E56D5DC8-4C73-44B1-B650-AAD75C7A2701}" = Broadcom ASF Management Applications
"{e7394a0f-3f80-45b1-87fc-abcd51893246}" = Python 2.6.4
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F63F15F6-2505-4B57-91AA-7EBD75C5477C}" = Autodesk DirectConnect 2013 32-bit
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{FEC02973-0781-49C7-9F04-28DA9BAF0372}" = Composite 2012
"{FFF5619F-6669-4EC5-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2012
"{FFF7F80F-929E-497F-A112-B070DE816128}" = Autodesk Inventor Fusion 2012 Language Pack
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Akamai" = Akamai NetSession Interface Service
"AutoCAD 2012 - English" = AutoCAD 2012 - English
"AutoCAD 2012 - English SP1" = AutoCAD 2012 - English SP1
"AutoCAD 2013 - English" = AutoCAD 2013 - English
"AutoCAD 2013 - English SP1.1" = AutoCAD 2013 - English SP1.1
"AutoCAD Architecture 2012 - English" = AutoCAD Architecture 2012 - English
"Autodesk 3ds Max Design 2012 32-bit - English" = Autodesk 3ds Max Design 2012 32-bit - English
"Autodesk 3ds Max Design 2013 32-bit" = Autodesk 3ds Max Design 2013 32-bit
"Autodesk Content Service" = Autodesk Content Service
"Autodesk DirectConnect 2013 32-bit" = Autodesk DirectConnect 2013 32-bit
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Autodesk FBX Plug-in 2012.0 - 3ds Max Design 2012" = Autodesk FBX Plug-in 2012.0 - 3ds Max Design 2012
"Autodesk FBX Plug-in 2013.1 - 3ds Max Design 2013" = Autodesk FBX Plug-in 2013.1 - 3ds Max Design 2013
"Autodesk Inventor Fusion 2012" = Autodesk Inventor Fusion 2012
"Autodesk Revit 2013" = Autodesk Revit 2013
"Autodesk Revit Architecture 2012" = Autodesk Revit Architecture 2012
"Autodesk Revit MEP 2012" = Autodesk Revit MEP 2012
"Autodesk Revit Structure 2012" = Autodesk Revit Structure 2012
"Autodesk Showcase 2012 32-bit - English" = Autodesk Showcase 2012 32-bit - English
"Autodesk SketchBook Designer 2012 - English" = Autodesk SketchBook Designer 2012 - English
"AviSynth" = AviSynth 2.5
"Basalite Online" = Basalite Online
"Belden Online" = Belden Online
"Blender" = Blender (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Core FTP LE 2.1" = Core FTP LE 2.1
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVDStyler_is1" = DVDStyler v1.7.4-1
"DWG TrueView 2011" = DWG TrueView 2011
"Easy DVD Creator_is1" = Easy DVD Creator 2.3.0
"ESET Online Scanner" = ESET Online Scanner v3
"FARO LS_is1" = FARO LS 4.8.2.25521
"FBX Converter 2006.11.2" = FBX Converter 2006.11.2
"FileZilla Client" = FileZilla Client 3.4.0
"FontCreator55_is1" = FontCreator 5.6
"Forest Pack Lite" = Forest Pack Lite 3.2.4
"Fotosizer" = Fotosizer 1.31
"Free RAR Extract Frog 1.00" = Free RAR Extract Frog 1.00
"Free WMA to MP3 Converter_is1" = Free WMA to MP3 Converter 1.16
"Gogo MP3 To CD Burner_is1" = Gogo MP3 To CD Burner
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"hp Deskjet 9800 series" = HP Deskjet 9800 Series
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"Inkscape" = Inkscape 0.48.0
"InstallShield_{09A02B7A-45A5-4E24-9AF3-14B8A86E18CA}" = Dell SAS RAID Storage Manager v2.16-00
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.1.0 (Basic)
"Lights and Plants Sample_is1" = Lights and Plants Sample 1.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"Oce 9400-II" = Oce 9400-II
"PDF reDirect" = PDF reDirect (remove only)
"Podium_is1" = Podium
"pstoedit and importps_is1" = pstoedit and importps 3.60
"RADVideo" = RAD Video Tools
"Recuva" = Recuva (remove only)
"Slow Motion" = Slow Motion
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"substance_player_2_x" = Allegorithmic Substance Player 2.x
"SWF Decompiler Premium_is1" = SWF Decompiler Premium [removed]
"Texporter_max7_x86" = Texporter v3.5.18.7_x86
"Vue 8 Infinite PLE 32bit" = Vue 8 Infinite PLE 32bit
"Vue 8 xStream PLE 32bit" = Vue 8 xStream PLE 32bit
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"wm8eutil" = Windows Media 8 Encoding Utility
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"MDO Desktop" = MDO Desktop
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/16/2013 10:27:34 PM | Computer Name = MODEL | Source = .NET Runtime | ID = 1026
Description = Application: Connect.Service.ContentService.exe Framework Version:
v4.0.30319 Description: The process was terminated due to an unhandled exception.
Exception
Info: exception code 80000003, exception address 7C90120E Stack: at Autodesk.AutoCAD.DatabaseServices.HostApplicationServices.FatalError(System.Stri
ng)

at .AcMgHostApplicationServices.fatalErrorWrapper(AcMgHostApplicationServices*,
Char*) at .acdbValidateSetup(Int32) at Autodesk.AutoCAD.Runtime.RuntimeSystem.Initialize(Autodesk.AutoCAD.DatabaseServi
ces.HostApplicationServices,
Int32) at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.InitializeObjectDBX()

at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.IndexFile(System.Stri
ng,
ACADIndexerOptions, Connect.Extraction.Extractors.AutoCADExtractor.IndexStatus
ByRef) at Connect.Extraction.Extractors.AutoCADExtractor.Extractor.GetFullContents(System.
String)

at Connect.Extraction.ExtractionManager.ExtractFullContents(System.String)
at Connect.Content.FileExtractor.ExtractFullContents(Boolean ByRef) at Connect.Content.FileFullContentsJob.OnExecute()

at Connect.Content.ObjectJob.Execute(System.Threading.ManualResetEvent) at
Connect.Content.ObjectJobWorker.DoWork() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object)

at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback,
System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext,
System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart()


Error - 1/16/2013 10:27:52 PM | Computer Name = MODEL | Source = .NET Runtime | ID = 1026
Description = Application: Connect.Service.ContentService.exe Framework Version:
v4.0.30319 Description: The process was terminated due to an unhandled exception.
Exception
Info: exception code 80000003, exception address 7C90120E Stack: at Autodesk.AutoCAD.DatabaseServices.HostApplicationServices.FatalError(System.Stri
ng)

at .AcMgHostApplicationServices.fatalErrorWrapper(AcMgHostApplicationServices*,
Char*) at .acdbValidateSetup(Int32) at Autodesk.AutoCAD.Runtime.RuntimeSystem.Initialize(Autodesk.AutoCAD.DatabaseServi
ces.HostApplicationServices,
Int32) at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.InitializeObjectDBX()

at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.IndexFile(System.Stri
ng,
ACADIndexerOptions, Connect.Extraction.Extractors.AutoCADExtractor.IndexStatus
ByRef) at Connect.Extraction.Extractors.AutoCADExtractor.Extractor.GetFullContents(System.
String)

at Connect.Extraction.ExtractionManager.ExtractFullContents(System.String)
at Connect.Content.FileExtractor.ExtractFullContents(Boolean ByRef) at Connect.Content.FileFullContentsJob.OnExecute()

at Connect.Content.ObjectJob.Execute(System.Threading.ManualResetEvent) at
Connect.Content.ObjectJobWorker.DoWork() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object)

at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback,
System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext,
System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart()


Error - 1/16/2013 10:28:19 PM | Computer Name = MODEL | Source = .NET Runtime | ID = 1026
Description = Application: Connect.Service.ContentService.exe Framework Version:
v4.0.30319 Description: The process was terminated due to an unhandled exception.
Exception
Info: exception code 80000003, exception address 7C90120E Stack: at Autodesk.AutoCAD.DatabaseServices.HostApplicationServices.FatalError(System.Stri
ng)

at .AcMgHostApplicationServices.fatalErrorWrapper(AcMgHostApplicationServices*,
Char*) at .acdbValidateSetup(Int32) at Autodesk.AutoCAD.Runtime.RuntimeSystem.Initialize(Autodesk.AutoCAD.DatabaseServi
ces.HostApplicationServices,
Int32) at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.InitializeObjectDBX()

at Connect.Extraction.Extractors.AutoCADExtractor.ACADIndexer.IndexFile(System.Stri
ng,
ACADIndexerOptions, Connect.Extraction.Extractors.AutoCADExtractor.IndexStatus
ByRef) at Connect.Extraction.Extractors.AutoCADExtractor.Extractor.GetFullContents(System.
String)

at Connect.Extraction.ExtractionManager.ExtractFullContents(System.String)
at Connect.Content.FileExtractor.ExtractFullContents(Boolean ByRef) at Connect.Content.FileFullContentsJob.OnExecute()

at Connect.Content.ObjectJob.Execute(System.Threading.ManualResetEvent) at
Connect.Content.ObjectJobWorker.DoWork() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object)

at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback,
System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext,
System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart()


Error - 1/25/2013 1:03:07 PM | Computer Name = MODEL | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 10.1.5.33, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/29/2013 6:05:41 PM | Computer Name = MODEL | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 24.0.1312.56, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/6/2013 12:29:37 PM | Computer Name = MODEL | Source = Application Error | ID = 1000
Description = Faulting application photoshop.exe, version 7.0.0.0, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00010cce.

Error - 2/6/2013 3:37:08 PM | Computer Name = MODEL | Source = Application Error | ID = 1000
Description = Faulting application photoshop.exe, version 7.0.0.0, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00011780.

Error - 2/14/2013 4:42:37 PM | Computer Name = MODEL | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 4.1.522.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 2/18/2013 8:40:39 AM | Computer Name = MODEL | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

Error - 2/25/2013 9:36:33 AM | Computer Name = MODEL | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile,
P4 [removed], P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ OSession Events ]
Error - 6/24/2009 5:42:07 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 32970
seconds with 2280 seconds of active time. This session ended with a crash.

Error - 3/12/2010 9:38:04 AM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 78
seconds with 60 seconds of active time. This session ended with a crash.

Error - 3/25/2010 10:37:02 AM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7136
seconds with 720 seconds of active time. This session ended with a crash.

Error - 5/26/2010 11:01:19 AM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 76
seconds with 60 seconds of active time. This session ended with a crash.

Error - 12/9/2010 6:41:08 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 44
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/20/2010 2:03:42 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 38
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/20/2010 2:04:30 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 23
seconds with 0 seconds of active time. This session ended with a crash.

Error - 3/1/2011 9:44:06 AM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 78
seconds with 60 seconds of active time. This session ended with a crash.

Error - 8/18/2011 5:20:55 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 31499
seconds with 1800 seconds of active time. This session ended with a crash.

Error - 9/16/2011 2:30:36 PM | Computer Name = MODEL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 20228
seconds with 2100 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 3/6/2013 8:50:33 AM | Computer Name = MODEL | Source = Service Control Manager | ID = 7022
Description = The Autodesk Content Service service hung on starting.


< End of report >
Sorry for any delay… :)

Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it


[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
Hi Jeff,
No problem on the delay, certainly take your time. We're all busy, just glad to get some help :)
Both scans complete and Logs pasted below:

aswMRB:

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-03-08 07:39:40
—————————–
07:39:40.765 OS Version: Windows 5.1.2600 Service Pack 3
07:39:40.765 Number of processors: 4 586 0x1706
07:39:40.765 ComputerName: MODEL UserName: Andy
07:39:46.468 Initialize success
07:42:58.515 AVAST engine defs: 13030703
07:43:05.453 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\SYMMPI1Port1Path0Target0Lun0
07:43:05.468 Disk 0 Vendor: ATA_____ A5BA Size: 238418MB BusType: 1
07:43:05.484 Disk 0 MBR read successfully
07:43:05.484 Disk 0 MBR scan
07:43:05.546 Disk 0 Windows VISTA default MBR code
07:43:05.546 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 62 MB offset 63
07:43:05.593 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238347 MB offset 128520
07:43:05.609 Disk 0 scanning sectors +488263545
07:43:05.703 Disk 0 scanning C:\WINDOWS\system32\drivers
07:43:24.234 Service scanning
07:43:51.625 Service MpKslcae5b51a c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A32E6CF1-A3DF-4D94-B466-414F2751D461}\MpKslcae5b51a.sys **LOCKED** 32
07:44:16.343 Modules scanning
07:44:27.046 Disk 0 trace - called modules:
07:44:27.078 ntkrnlpa.exe CLASSPNP.SYS disk.sys SCSIPORT.SYS hal.dll symmpi.sys
07:44:27.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8994c9c0]
07:44:27.078 3 CLASSPNP.SYS[ba0f8fd7] -> nt!IofCallDriver -> \Device\Scsi\SYMMPI1Port1Path0Target0Lun0[0x8a3be030]
07:44:28.156 AVAST engine scan C:\WINDOWS
07:44:51.828 AVAST engine scan C:\WINDOWS\system32
07:52:56.843 AVAST engine scan C:\WINDOWS\system32\drivers
07:53:13.296 AVAST engine scan C:\Documents and Settings\Andy
09:44:54.109 File: C:\Documents and Settings\Andy\My Documents\Downloads\Google Updater.exe **INFECTED** Win32:Malware-gen
10:08:34.500 AVAST engine scan C:\Documents and Settings\All Users
11:10:21.671 Scan finished successfully
11:21:03.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Andy\Desktop\OTL\2nd\MBR.dat"
11:21:03.375 The log file has been saved successfully to "C:\Documents and Settings\Andy\Desktop\OTL\2nd\aswMBR.txt"

AdwCleaner:

# AdwCleaner v2.114 - Logfile created 03/08/2013 at 11:24:31
# Updated 05/03/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Andy - MODEL
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Andy\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v6.0.2 (en-US)

File : C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v25.0.1364.152

File : C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [1204 octets] - [08/03/2013 11:24:31]

########## EOF - C:\AdwCleaner[S1].txt - [1264 octets] ##########
Hi there, Sorry….doing some house work today….before we continue, is this system set up to connect to work or school or a proxy server?
No problem, that's what weekends are for. Office computer, so usually not here on the weekends anyway. Unfortunately for me today (Sunday) I am here :( No to your questions… shouldn't be anyway. We're set up on a simple "home" type network and that's about it. I do use Remote Desktop to connect to our other office, and I believe I also have a VPN set up to connect to them too, but I can't remember the last time I used VPN.
Ok thanks for letting me know… :)

Please go to: VirusTotal
On the page you'll find a "Choose File" button.
Click on the Choose File button.
In the Choose File to Upload window which opens, copy and paste this into the File Name box.

C:\WINDOWS\FXEZQJV.INI


Next, click the Open button.
Then click the "Scan It!" button just below.
This will scan the file. Please be patient.
If you get a message saying File has already been analyzed: click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.
———-
Hi,

Thanks! :)

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
    IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…id=ie7&rlz=
    IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=fZsQXPl…q={searchTerms}
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
    O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2008/12/12 09:34:03 | 000,043,520 | —- | C] () – C:\Documents and Settings\Andy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/08/29 13:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Andy\Application Data\GetRightToGo
    
    :Files
    C:\Documents and Settings\Andy\My Documents\Downloads\Google Updater.exe
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new OTL log and let me know how your system is running now. :)
Done and done! Seems to be doing alright. My AutoCAD hasn't crashed yet today and start up took way less than the usual 20-25 minutes!
Below are the logs OTL spit out. The first being after running the fix and rebooting, the second a fresh scan.

Kill Log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
C:\WINDOWS\241E2DF6792B42B69B79B0DF73D5A69D.TMP\WiseCustomCalla3.exe deleted successfully.
C:\WINDOWS\241E2DF6792B42B69B79B0DF73D5A69D.TMP folder deleted successfully.
C:\WINDOWS\CD95F661A5C411AFB2CCABCD21A325B4.TMP folder deleted successfully.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\Documents and Settings\Andy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Documents and Settings\Andy\Application Data\GetRightToGo folder moved successfully.
========== FILES ==========
C:\Documents and Settings\Andy\My Documents\Downloads\Google Updater.exe moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Andy\Desktop\OTL\cmd.bat deleted successfully.
C:\Documents and Settings\Andy\Desktop\OTL\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Andy
->Temp folder emptied: 4439129228 bytes
->Temporary Internet Files folder emptied: 191386935 bytes
->Java cache emptied: 8650657 bytes
->FireFox cache emptied: 45459042 bytes
->Google Chrome cache emptied: 433900371 bytes
->Flash cache emptied: 2037237 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 1590802 bytes
->Temporary Internet Files folder emptied: 1408211 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 29175235 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 469424008 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 390026 bytes
RecycleBin emptied: 2720725263 bytes

Total Files Cleaned = 7,957.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 03112013_124958

Files\Folders moved on Reboot…
C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.Word\~WRS{0636DAE3-CF8E-4F24-B196-122CE356E74A}.tmp moved successfully.
C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.Word\~WRS{144A52F7-43E3-48B4-93B4-6E40DC02866F}.tmp moved successfully.
C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.Word\~WRS{96FD7FC2-0670-4F5E-8CAD-DC7FF461BC8A}.tmp moved successfully.
C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.Word\~WRS{CC5F05C5-7C32-4F4D-865D-30E910FB9169}.tmp moved successfully.
File\Folder C:\Documents and Settings\Andy\Local Settings\Temporary Internet Files\Content.MSO\mso3E7.tmp not found!
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_2b8.dat not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


OTL Scan:

OTL logfile created on: 3/11/2013 1:09:17 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Andy\Desktop\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.26 Gb Available Physical Memory | 62.97% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.07% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.76 Gb Total Space | 130.04 Gb Free Space | 55.87% Space Free | Partition Type: NTFS
Drive D: | 50.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MODEL | User Name: Andy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Andy\Desktop\OTL\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Andy\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Autodesk, Inc.)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
PRC - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
PRC - C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
PRC - C:\xampplite\mysql\bin\mysqld.exe (MySQL AB)
PRC - C:\xampplite\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\popup.exe ( )
PRC - C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
PRC - C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
PRC - C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\javaw.exe ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\pdf995mon.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\74e83f69320f01190c6067c2f8b30489\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\4edc2adecbaab74f9975be6c69167e15\System.ServiceModel.Routing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\2ce0a49fbfc6924594dd5967a616eb06\System.ServiceModel.Discovery.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\85138a3833f1f6c7db57e09de3deee27\System.ServiceModel.Channels.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\9b61f1ff6391792692c432394c26c79c\System.ServiceModel.Activities.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\6a69d4225b391d3c9a63b82c707f68df\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\252adcaff1070555538f68e50f52c055\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f7fb007b77205f93cac30408a5bea10f\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\65acd066ece0048520819cb160ebaae5\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Web.Services\1a39e50cf087aa4d71d93ddf2199b3fa\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\6b04f4c4bd0a6e6bf91e8eb5fccb045a\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\6b04f4c4bd0a6e6bf91e8eb5fccb045a\System.EnterpriseServices.Wrapper.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\79d3ecc74b6814032c800db49534e153\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\ee7b13803a539a8e268e137284cf3560\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\f749bd80cadc8925dac6e7a37705e411\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a31756f7a2c2b2b884815da8a87fe4da\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\06b973a6644eeaef2a6d1617fba5ca54\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\9f782ec14c759c492ac76056b05f11e7\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\35d23b34d83acc8d52858c89169a312e\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\661b58707b02cb70078e50273ac91633\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\8b906332417c7790e19b663d157f9d72\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8e12f4f895975a109ef745043f4d0c62\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
MOD - C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\WINDOWS\system32\PDFreDirectMonNT.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\aloaha_prntproc.dll ()
MOD - C:\WINDOWS\system32\aloaha_prntmon.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\AlertStrings.dll ()
MOD - C:\WINDOWS\system32\ssleay32.dll ()
MOD - C:\WINDOWS\system32\libeay32.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\systype.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\storelibirjni.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\storelibjni.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\Authenticate.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\net.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\zip.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\javaw.exe ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\java.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\verify.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\hpi.dll ()


========== Services (SafeList) ==========

SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_ce5ba24.dll ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (Autodesk Content Service) – C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
SRV - (mi-raysat_3dsmax2013_32) – C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
SRV - (mi-raysat_3dsmax2012_32) – C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
SRV - (pdfprint) – C:\Program Files\Wrocklage\pdfprint.exe (Wrocklage Intermedia GmbH)
SRV - (MySQL) – C:\xampplite\mysql\bin\mysqld.exe (MySQL AB)
SRV - (Apache2.2) – C:\xampplite\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (SWGVCSvc) – C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MegaMonitorSrv) – C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
SRV - (ASFIPmon) – C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (MSMFramework) – C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (RTLWUSB) – system32\DRIVERS\wg111v2.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (nielprt) – system32\DRIVERS\nielprt.sys File not found
DRV - (NielGfx) – system32\drivers\nielgfx.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SWIPsec) – C:\WINDOWS\system32\drivers\SWIPsec.sys (SonicWALL, Inc.)
DRV - (SWVNIC) – C:\WINDOWS\system32\drivers\SWVNIC.sys (SonicWALL, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (SYMMPI) – C:\WINDOWS\system32\drivers\symmpi.sys (LSI Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (BASFND) – C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (AR5523) – C:\WINDOWS\system32\drivers\WG11TND5.sys (NETGEAR, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7DKUS_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [removed]:1.9.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@winzip.com/Winzip Courier: C:\Program Files\WinZip Courier\npwzwmc.dll (WinZip Computing, S.L.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{74c841e3-b59f-479e-8d7a-e26a942a87c8}: C:\Program Files\WinZip Courier\FFExt [2011/07/07 09:52:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/17 17:51:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/02/21 10:27:25 | 000,000,000 | —D | M]

[2011/03/16 09:38:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Extensions
[2012/06/01 10:14:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions
[2012/06/01 10:14:34 | 001,335,949 | —- | M] () (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions\[removed]
[2011/09/17 17:52:01 | 000,019,153 | —- | M] () (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/02/20 10:03:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/09/03 02:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/13 17:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/13 17:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/09/02 19:25:59 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - homepage: http://yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: WinZip Courier (Enabled) = C:\Program Files\WinZip Courier\npwzwmc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 7.0.30.255 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: WinZip Courier = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ilckobikkmajlmhhdenkhonjkoaneclk\3.0.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/03/11 12:57:30 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [ADSK DLMSession] C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Autodesk, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPWQTOOLBOX] C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Popup] C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\Popup.exe ( )
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Andy\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0FCB27D0-3397-498B-ACA6-E881421153AD} https://plansonline.ggp.com/Plans/Resources…elpLauncher.cab (HelpLauncher.ProjectDoxHelp)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1229092540562 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{175C2E08-AC7C-4EC7-AF15-EA68A9E815C8}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Andy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/10 18:17:04 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/03/11 12:49:58 | 000,000,000 | —D | C] – C:\_OTL
[2013/03/11 12:19:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\HIgh School
[2013/03/11 11:39:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/03/11 11:39:55 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/03/11 11:17:39 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Andy\Desktop\erunt-setup.exe
[2013/03/08 08:37:31 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Andy\Desktop\aswMBR.exe
[2013/03/06 17:17:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Application Data\pdf995
[2013/03/06 15:48:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\pdf995
[2013/03/06 15:48:05 | 001,672,192 | —- | C] (TODO: ) – C:\WINDOWS\System32\pdfmona.dll
[2013/03/06 15:48:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Software995
[2013/03/06 15:48:02 | 000,000,000 | —D | C] – C:\Program Files\pdf995
[2013/03/06 09:11:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\OTL
[2013/03/06 09:04:52 | 025,782,728 | —- | C] (Autodesk, Inc.) – C:\Documents and Settings\Andy\Desktop\AutoCAD_2013_SP1.1_32bit.exe
[2013/03/01 11:07:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\IP2
[2013/02/28 09:00:57 | 000,000,000 | —D | C] – C:\Marlette
[2013/02/20 13:18:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4
[2013/02/19 16:04:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1
[2013/02/12 13:08:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\biggby social
[2013/02/12 11:02:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1
[2013/02/11 12:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\Marlette addition

========== Files - Modified Within 30 Days ==========

[2013/03/11 13:07:17 | 000,542,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/03/11 13:07:17 | 000,104,144 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/03/11 13:04:58 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/03/11 13:04:55 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/11 13:03:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/03/11 13:03:01 | 2145,013,760 | -HS- | M] () – C:\hiberfil.sys
[2013/03/11 13:01:47 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/03/11 12:57:30 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2013/03/11 12:39:01 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005UA.job
[2013/03/11 12:33:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/11 11:40:00 | 000,000,649 | —- | M] () – C:\Documents and Settings\Andy\Desktop\NTREGOPT.lnk
[2013/03/11 11:40:00 | 000,000,630 | —- | M] () – C:\Documents and Settings\Andy\Desktop\ERUNT.lnk
[2013/03/11 11:18:02 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Andy\Desktop\erunt-setup.exe
[2013/03/11 07:24:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/03/11 05:38:01 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005Core.job
[2013/03/10 14:21:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2013/03/08 16:46:56 | 000,183,015 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Lintel.pdf
[2013/03/08 16:44:20 | 000,245,455 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Lintel.psd
[2013/03/08 16:39:04 | 000,013,154 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Plan.pdf
[2013/03/08 12:24:09 | 000,597,667 | —- | M] () – C:\Documents and Settings\Andy\Desktop\AdwCleaner.exe
[2013/03/08 08:38:54 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Andy\Desktop\aswMBR.exe
[2013/03/08 08:38:45 | 000,014,700 | —- | M] () – C:\Documents and Settings\Andy\Desktop\download.htm
[2013/03/07 13:08:45 | 000,041,494 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Office Layout.pdf
[2013/03/06 17:15:38 | 000,000,059 | —- | M] () – C:\WINDOWS\wpd99.drv
[2013/03/06 16:08:27 | 000,132,232 | —- | M] () – C:\Documents and Settings\Andy\Desktop\background.jpg
[2013/03/06 15:48:06 | 001,672,192 | —- | M] (TODO: ) – C:\WINDOWS\System32\pdfmona.dll
[2013/03/06 15:48:05 | 000,036,864 | —- | M] () – C:\WINDOWS\System32\pdf995mon.dll
[2013/03/06 09:04:52 | 025,782,728 | —- | M] (Autodesk, Inc.) – C:\Documents and Settings\Andy\Desktop\AutoCAD_2013_SP1.1_32bit.exe
[2013/03/05 17:34:16 | 000,071,847 | —- | M] () – C:\Documents and Settings\Andy\Desktop\COOP.skp
[2013/03/05 04:43:35 | 000,002,333 | —- | M] () – C:\Documents and Settings\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/04 11:33:46 | 000,018,733 | —- | M] () – C:\Documents and Settings\Andy\Desktop\LAMP.jpg
[2013/02/27 10:13:35 | 000,385,349 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 08:45:39 | 000,475,014 | —- | M] () – C:\Documents and Settings\Andy\Desktop\instagram.jpg
[2013/02/25 18:26:50 | 000,336,097 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 18:26:11 | 000,474,673 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 17:51:15 | 000,391,153 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 17:00:53 | 000,000,138 | —- | M] () – C:\Documents and Settings\Andy\Desktop\tube.htm
[2013/02/21 14:01:21 | 000,060,032 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Marlette Elementary Frost Slabs.pdf
[2013/02/21 12:18:38 | 000,359,943 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A5.1 - Roof Details.pdf
[2013/02/21 12:18:09 | 000,234,202 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A5.0 - Roof Plans.pdf
[2013/02/20 17:15:21 | 000,366,036 | —- | M] () – C:\Documents and Settings\Andy\Desktop\truck-single.jpg
[2013/02/20 14:31:43 | 000,304,118 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Elevations.dwg
[2013/02/20 13:17:14 | 001,527,671 | —- | M] () – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4.zip
[2013/02/20 11:56:52 | 000,051,344 | —- | M] () – C:\Documents and Settings\Andy\Desktop\snow in mqt.jpg
[2013/02/20 11:10:38 | 000,298,143 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Existing Windows.jpg
[2013/02/20 11:04:18 | 000,324,577 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Elevations.bak
[2013/02/19 16:25:04 | 000,079,423 | —- | M] () – C:\Documents and Settings\Andy\Desktop\midlandfacade.jpg
[2013/02/19 16:24:59 | 000,072,736 | —- | M] () – C:\Documents and Settings\Andy\Desktop\flatrock.jpg
[2013/02/19 16:24:55 | 000,398,359 | —- | M] () – C:\Documents and Settings\Andy\Desktop\woodland-park-1.jpg
[2013/02/19 16:03:41 | 000,447,147 | —- | M] () – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1.zip
[2013/02/18 08:37:37 | 000,380,040 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/02/15 19:27:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/02/15 19:08:22 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/02/14 08:53:01 | 000,181,901 | —- | M] () – C:\Documents and Settings\Andy\Desktop\MARLETTE JR SR.dwg
[2013/02/13 09:36:19 | 000,645,574 | —- | M] () – C:\Documents and Settings\Andy\My Documents\Architectural 2-1-13 dd reveiw.dwf
[2013/02/12 17:56:04 | 001,615,313 | —- | M] () – C:\Documents and Settings\Andy\My Documents\SLED.skp
[2013/02/12 17:51:26 | 000,054,474 | —- | M] () – C:\Documents and Settings\Andy\Desktop\SLED.jpg
[2013/02/12 13:07:03 | 000,007,576 | —- | M] () – C:\Documents and Settings\Andy\Desktop\wordpress-logo.png
[2013/02/12 13:05:03 | 000,017,910 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Biggby_Coffee_Logo.png
[2013/02/12 12:57:29 | 000,000,184 | —- | M] () – C:\Documents and Settings\Andy\Desktop\php.ini
[2013/02/12 12:43:45 | 000,028,331 | —- | M] () – C:\Documents and Settings\Andy\Desktop\andy.jpg
[2013/02/12 11:32:35 | 000,262,546 | —- | M] () – C:\Documents and Settings\Andy\Desktop\buddypress-group-documents.zip
[2013/02/12 11:01:09 | 005,440,753 | —- | M] () – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1.zip
[2013/02/12 10:26:35 | 000,078,195 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Sidewalk.skp
[2013/02/11 12:23:23 | 000,445,908 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.dwg
[2013/02/11 12:23:07 | 000,620,974 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.bak

========== Files Created - No Company Name ==========

[2013/03/11 11:40:00 | 000,000,649 | —- | C] () – C:\Documents and Settings\Andy\Desktop\NTREGOPT.lnk
[2013/03/11 11:40:00 | 000,000,630 | —- | C] () – C:\Documents and Settings\Andy\Desktop\ERUNT.lnk
[2013/03/08 16:44:20 | 000,245,455 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Lintel.psd
[2013/03/08 16:39:03 | 000,013,154 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Plan.pdf
[2013/03/08 16:38:16 | 000,183,015 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Lintel.pdf
[2013/03/08 12:24:01 | 000,597,667 | —- | C] () – C:\Documents and Settings\Andy\Desktop\AdwCleaner.exe
[2013/03/08 08:38:42 | 000,014,700 | —- | C] () – C:\Documents and Settings\Andy\Desktop\download.htm
[2013/03/07 13:08:34 | 000,041,494 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Office Layout.pdf
[2013/03/06 15:48:07 | 000,000,059 | —- | C] () – C:\WINDOWS\wpd99.drv
[2013/03/06 15:48:05 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2013/03/05 17:34:16 | 000,071,847 | —- | C] () – C:\Documents and Settings\Andy\Desktop\COOP.skp
[2013/03/04 11:33:43 | 000,018,733 | —- | C] () – C:\Documents and Settings\Andy\Desktop\LAMP.jpg
[2013/02/27 10:13:30 | 000,385,349 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 08:45:38 | 000,475,014 | —- | C] () – C:\Documents and Settings\Andy\Desktop\instagram.jpg
[2013/02/25 18:26:49 | 000,336,097 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 18:26:09 | 000,474,673 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 17:51:13 | 000,391,153 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 16:53:20 | 000,000,138 | —- | C] () – C:\Documents and Settings\Andy\Desktop\tube.htm
[2013/02/21 14:01:18 | 000,060,032 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Marlette Elementary Frost Slabs.pdf
[2013/02/21 12:18:37 | 000,359,943 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A5.1 - Roof Details.pdf
[2013/02/21 12:17:57 | 000,234,202 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A5.0 - Roof Plans.pdf
[2013/02/20 17:15:14 | 000,366,036 | —- | C] () – C:\Documents and Settings\Andy\Desktop\truck-single.jpg
[2013/02/20 13:16:50 | 001,527,671 | —- | C] () – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4.zip
[2013/02/20 11:56:39 | 000,051,344 | —- | C] () – C:\Documents and Settings\Andy\Desktop\snow in mqt.jpg
[2013/02/20 11:10:37 | 000,298,143 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Existing Windows.jpg
[2013/02/19 16:25:04 | 000,079,423 | —- | C] () – C:\Documents and Settings\Andy\Desktop\midlandfacade.jpg
[2013/02/19 16:24:59 | 000,072,736 | —- | C] () – C:\Documents and Settings\Andy\Desktop\flatrock.jpg
[2013/02/19 16:24:53 | 000,398,359 | —- | C] () – C:\Documents and Settings\Andy\Desktop\woodland-park-1.jpg
[2013/02/19 16:03:36 | 000,447,147 | —- | C] () – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1.zip
[2013/02/19 11:20:52 | 000,324,577 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Elevations.bak
[2013/02/19 11:20:52 | 000,304,118 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Elevations.dwg
[2013/02/15 19:17:30 | 000,000,384 | -H– | C] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/02/14 08:53:01 | 000,181,901 | —- | C] () – C:\Documents and Settings\Andy\Desktop\MARLETTE JR SR.dwg
[2013/02/13 09:36:19 | 000,645,574 | —- | C] () – C:\Documents and Settings\Andy\My Documents\Architectural 2-1-13 dd reveiw.dwf
[2013/02/12 17:56:03 | 001,615,313 | —- | C] () – C:\Documents and Settings\Andy\My Documents\SLED.skp
[2013/02/12 17:51:26 | 000,054,474 | —- | C] () – C:\Documents and Settings\Andy\Desktop\SLED.jpg
[2013/02/12 13:05:01 | 000,017,910 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Biggby_Coffee_Logo.png
[2013/02/12 12:43:38 | 000,028,331 | —- | C] () – C:\Documents and Settings\Andy\Desktop\andy.jpg
[2013/02/12 12:16:45 | 000,000,184 | —- | C] () – C:\Documents and Settings\Andy\Desktop\php.ini
[2013/02/12 11:32:34 | 000,262,546 | —- | C] () – C:\Documents and Settings\Andy\Desktop\buddypress-group-documents.zip
[2013/02/12 11:13:41 | 000,007,576 | —- | C] () – C:\Documents and Settings\Andy\Desktop\wordpress-logo.png
[2013/02/12 11:00:20 | 005,440,753 | —- | C] () – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1.zip
[2013/02/12 10:26:35 | 000,078,195 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Sidewalk.skp
[2013/02/11 10:07:01 | 000,620,974 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.bak
[2013/02/11 10:07:01 | 000,445,908 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.dwg
[2012/12/06 13:01:56 | 000,000,248 | —- | C] () – C:\WINDOWS\FXEZQJV.INI
[2012/07/31 12:04:23 | 000,000,811 | —- | C] () – C:\Documents and Settings\Andy\.recently-used.xbel
[2012/02/15 02:12:11 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/11/28 18:22:23 | 000,000,000 | —- | C] () – C:\WINDOWS\TMonitor.INI
[2011/10/13 16:29:11 | 000,110,456 | —- | C] () – C:\Documents and Settings\Andy\g2ax_customer_downloadhelper_win32_x86.exe
[2011/10/10 15:07:33 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/10 15:07:33 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/10 15:07:33 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/10 15:07:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/10 15:07:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/09/16 17:57:43 | 000,879,964 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1682135861-2545026859-4075531753-1005-0.dat
[2011/09/16 17:57:41 | 000,365,678 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/09/06 19:08:37 | 000,000,147 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/03/16 09:38:22 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/06/12 08:40:32 | 000,120,838 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_flv.cab
[2009/06/11 14:33:29 | 000,001,636 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_3gp.cab
[2009/03/20 10:57:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_avi.cab
[2009/03/20 10:57:42 | 000,001,539 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_mpg.dat
[2009/03/12 10:56:41 | 000,001,541 | —- | C] () – C:\Documents and Settings\Andy\Application Data\update_sp1v1.cab
[2009/03/12 10:56:41 | 000,000,016 | —- | C] () – C:\Documents and Settings\Andy\Application Data\update_sp1v2.cab

========== ZeroAccess Check ==========

[2008/04/25 17:34:35 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/09/09 10:16:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4096C9B2
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24975D5E

< End of report >
That doesn't sound or look familiar to me at all… Certainly not something I've done. The only thing to connect to anything other than our simple network is the remote desktop and that's not it..
Ok thanks….

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;
    @Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4096C9B2
    @Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24975D5E
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new logs made by OTL and let me know how your system is behaving now. :)
Seems to be good…
So far so good anyway, I guess a day or two sitting in front of the machine will tell the tale…
Logs Below:

Kill Log

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
ADS C:\Documents and Settings\All Users\Application Data\TEMP:4096C9B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:24975D5E deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Andy
->Temp folder emptied: 41282 bytes
->Temporary Internet Files folder emptied: 95829 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 11082198 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 7966 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6433 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 11.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03112013_135657

Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_30c.dat not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


OTL log

OTL logfile created on: 3/11/2013 2:04:39 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Andy\Desktop\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.25 Gb Available Physical Memory | 62.66% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.18% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.76 Gb Total Space | 130.04 Gb Free Space | 55.87% Space Free | Partition Type: NTFS
Drive D: | 50.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MODEL | User Name: Andy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Andy\Desktop\OTL\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Andy\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Autodesk, Inc.)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
PRC - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
PRC - C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
PRC - C:\xampplite\mysql\bin\mysqld.exe (MySQL AB)
PRC - C:\xampplite\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\popup.exe ( )
PRC - C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
PRC - C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
PRC - C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\javaw.exe ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\pdf995mon.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\74e83f69320f01190c6067c2f8b30489\System.WorkflowServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\4edc2adecbaab74f9975be6c69167e15\System.ServiceModel.Routing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\2ce0a49fbfc6924594dd5967a616eb06\System.ServiceModel.Discovery.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\85138a3833f1f6c7db57e09de3deee27\System.ServiceModel.Channels.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\9b61f1ff6391792692c432394c26c79c\System.ServiceModel.Activities.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\6a69d4225b391d3c9a63b82c707f68df\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\252adcaff1070555538f68e50f52c055\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\f7fb007b77205f93cac30408a5bea10f\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\65acd066ece0048520819cb160ebaae5\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Web.Services\1a39e50cf087aa4d71d93ddf2199b3fa\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\6b04f4c4bd0a6e6bf91e8eb5fccb045a\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\6b04f4c4bd0a6e6bf91e8eb5fccb045a\System.EnterpriseServices.Wrapper.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\79d3ecc74b6814032c800db49534e153\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\ee7b13803a539a8e268e137284cf3560\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\f749bd80cadc8925dac6e7a37705e411\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a31756f7a2c2b2b884815da8a87fe4da\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\06b973a6644eeaef2a6d1617fba5ca54\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\9f782ec14c759c492ac76056b05f11e7\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\35d23b34d83acc8d52858c89169a312e\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\661b58707b02cb70078e50273ac91633\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\8b906332417c7790e19b663d157f9d72\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8e12f4f895975a109ef745043f4d0c62\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
MOD - C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
MOD - C:\WINDOWS\system32\PDFreDirectMonNT.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\aloaha_prntproc.dll ()
MOD - C:\WINDOWS\system32\aloaha_prntmon.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\AlertStrings.dll ()
MOD - C:\WINDOWS\system32\ssleay32.dll ()
MOD - C:\WINDOWS\system32\libeay32.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\systype.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\storelibirjni.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\storelibjni.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\Framework\Authenticate.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\net.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\zip.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\javaw.exe ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\java.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\verify.dll ()
MOD - C:\Program Files\Dell SAS RAID Storage Manager\JRE\bin\hpi.dll ()


========== Services (SafeList) ==========

SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_ce5ba24.dll ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (Autodesk Content Service) – C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
SRV - (mi-raysat_3dsmax2013_32) – C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe ()
SRV - (mi-raysat_3dsmax2012_32) – C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
SRV - (pdfprint) – C:\Program Files\Wrocklage\pdfprint.exe (Wrocklage Intermedia GmbH)
SRV - (MySQL) – C:\xampplite\mysql\bin\mysqld.exe (MySQL AB)
SRV - (Apache2.2) – C:\xampplite\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (SWGVCSvc) – C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MegaMonitorSrv) – C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe ()
SRV - (ASFIPmon) – C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (MSMFramework) – C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (RTLWUSB) – system32\DRIVERS\wg111v2.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (nielprt) – system32\DRIVERS\nielprt.sys File not found
DRV - (NielGfx) – system32\drivers\nielgfx.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SWIPsec) – C:\WINDOWS\system32\drivers\SWIPsec.sys (SonicWALL, Inc.)
DRV - (SWVNIC) – C:\WINDOWS\system32\drivers\SWVNIC.sys (SonicWALL, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (SYMMPI) – C:\WINDOWS\system32\drivers\symmpi.sys (LSI Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (BASFND) – C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (AR5523) – C:\WINDOWS\system32\drivers\WG11TND5.sys (NETGEAR, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=0081207
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7DKUS_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [removed]:1.9.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@winzip.com/Winzip Courier: C:\Program Files\WinZip Courier\npwzwmc.dll (WinZip Computing, S.L.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{74c841e3-b59f-479e-8d7a-e26a942a87c8}: C:\Program Files\WinZip Courier\FFExt [2011/07/07 09:52:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/17 17:51:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/02/21 10:27:25 | 000,000,000 | —D | M]

[2011/03/16 09:38:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Extensions
[2012/06/01 10:14:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions
[2012/06/01 10:14:34 | 001,335,949 | —- | M] () (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions\[removed]
[2011/09/17 17:52:01 | 000,019,153 | —- | M] () (No name found) – C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\0ztaw4bn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/02/20 10:03:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/09/03 02:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/13 17:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/13 17:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/09/02 19:25:59 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - homepage: http://yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: WinZip Courier (Enabled) = C:\Program Files\WinZip Courier\npwzwmc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 7.0.30.255 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: WinZip Courier = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ilckobikkmajlmhhdenkhonjkoaneclk\3.0.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/03/11 12:57:30 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [ADSK DLMSession] C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Autodesk, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPWQTOOLBOX] C:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Popup] C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\Popup.exe ( )
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Andy\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0FCB27D0-3397-498B-ACA6-E881421153AD} https://plansonline.ggp.com/Plans/Resources…elpLauncher.cab (HelpLauncher.ProjectDoxHelp)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1229092540562 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{175C2E08-AC7C-4EC7-AF15-EA68A9E815C8}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Andy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/10 18:17:04 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/03/11 12:49:58 | 000,000,000 | —D | C] – C:\_OTL
[2013/03/11 12:19:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\HIgh School
[2013/03/11 11:39:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/03/11 11:39:55 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/03/11 11:17:39 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Andy\Desktop\erunt-setup.exe
[2013/03/08 08:37:31 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Andy\Desktop\aswMBR.exe
[2013/03/06 17:17:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Application Data\pdf995
[2013/03/06 15:48:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\pdf995
[2013/03/06 15:48:05 | 001,672,192 | —- | C] (TODO: ) – C:\WINDOWS\System32\pdfmona.dll
[2013/03/06 15:48:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Software995
[2013/03/06 15:48:02 | 000,000,000 | —D | C] – C:\Program Files\pdf995
[2013/03/06 09:11:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\OTL
[2013/03/06 09:04:52 | 025,782,728 | —- | C] (Autodesk, Inc.) – C:\Documents and Settings\Andy\Desktop\AutoCAD_2013_SP1.1_32bit.exe
[2013/03/01 11:07:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\IP2
[2013/02/28 09:00:57 | 000,000,000 | —D | C] – C:\Marlette
[2013/02/20 13:18:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4
[2013/02/19 16:04:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1
[2013/02/12 13:08:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\biggby social
[2013/02/12 11:02:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1
[2013/02/11 12:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Andy\Desktop\Marlette addition

========== Files - Modified Within 30 Days ==========

[2013/03/11 14:04:19 | 000,542,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/03/11 14:04:19 | 000,104,144 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/03/11 14:02:01 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/03/11 14:01:57 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/11 14:00:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/03/11 14:00:06 | 2145,013,760 | -HS- | M] () – C:\hiberfil.sys
[2013/03/11 13:39:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005UA.job
[2013/03/11 13:33:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/11 13:13:27 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/03/11 12:57:30 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2013/03/11 11:40:00 | 000,000,649 | —- | M] () – C:\Documents and Settings\Andy\Desktop\NTREGOPT.lnk
[2013/03/11 11:40:00 | 000,000,630 | —- | M] () – C:\Documents and Settings\Andy\Desktop\ERUNT.lnk
[2013/03/11 11:18:02 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Andy\Desktop\erunt-setup.exe
[2013/03/11 07:24:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/03/11 05:38:01 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1682135861-2545026859-4075531753-1005Core.job
[2013/03/10 14:21:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2013/03/08 16:46:56 | 000,183,015 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Lintel.pdf
[2013/03/08 16:44:20 | 000,245,455 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Lintel.psd
[2013/03/08 16:39:04 | 000,013,154 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Plan.pdf
[2013/03/08 12:24:09 | 000,597,667 | —- | M] () – C:\Documents and Settings\Andy\Desktop\AdwCleaner.exe
[2013/03/08 08:38:54 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Andy\Desktop\aswMBR.exe
[2013/03/08 08:38:45 | 000,014,700 | —- | M] () – C:\Documents and Settings\Andy\Desktop\download.htm
[2013/03/07 13:08:45 | 000,041,494 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Office Layout.pdf
[2013/03/06 17:15:38 | 000,000,059 | —- | M] () – C:\WINDOWS\wpd99.drv
[2013/03/06 16:08:27 | 000,132,232 | —- | M] () – C:\Documents and Settings\Andy\Desktop\background.jpg
[2013/03/06 15:48:06 | 001,672,192 | —- | M] (TODO: ) – C:\WINDOWS\System32\pdfmona.dll
[2013/03/06 15:48:05 | 000,036,864 | —- | M] () – C:\WINDOWS\System32\pdf995mon.dll
[2013/03/06 09:04:52 | 025,782,728 | —- | M] (Autodesk, Inc.) – C:\Documents and Settings\Andy\Desktop\AutoCAD_2013_SP1.1_32bit.exe
[2013/03/05 17:34:16 | 000,071,847 | —- | M] () – C:\Documents and Settings\Andy\Desktop\COOP.skp
[2013/03/05 04:43:35 | 000,002,333 | —- | M] () – C:\Documents and Settings\Andy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/04 11:33:46 | 000,018,733 | —- | M] () – C:\Documents and Settings\Andy\Desktop\LAMP.jpg
[2013/02/27 10:13:35 | 000,385,349 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 08:45:39 | 000,475,014 | —- | M] () – C:\Documents and Settings\Andy\Desktop\instagram.jpg
[2013/02/25 18:26:50 | 000,336,097 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 18:26:11 | 000,474,673 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 17:51:15 | 000,391,153 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 17:00:53 | 000,000,138 | —- | M] () – C:\Documents and Settings\Andy\Desktop\tube.htm
[2013/02/21 14:01:21 | 000,060,032 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Marlette Elementary Frost Slabs.pdf
[2013/02/21 12:18:38 | 000,359,943 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A5.1 - Roof Details.pdf
[2013/02/21 12:18:09 | 000,234,202 | —- | M] () – C:\Documents and Settings\Andy\Desktop\A5.0 - Roof Plans.pdf
[2013/02/20 17:15:21 | 000,366,036 | —- | M] () – C:\Documents and Settings\Andy\Desktop\truck-single.jpg
[2013/02/20 14:31:43 | 000,304,118 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Elevations.dwg
[2013/02/20 13:17:14 | 001,527,671 | —- | M] () – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4.zip
[2013/02/20 11:56:52 | 000,051,344 | —- | M] () – C:\Documents and Settings\Andy\Desktop\snow in mqt.jpg
[2013/02/20 11:10:38 | 000,298,143 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Existing Windows.jpg
[2013/02/20 11:04:18 | 000,324,577 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Elevations.bak
[2013/02/19 16:25:04 | 000,079,423 | —- | M] () – C:\Documents and Settings\Andy\Desktop\midlandfacade.jpg
[2013/02/19 16:24:59 | 000,072,736 | —- | M] () – C:\Documents and Settings\Andy\Desktop\flatrock.jpg
[2013/02/19 16:24:55 | 000,398,359 | —- | M] () – C:\Documents and Settings\Andy\Desktop\woodland-park-1.jpg
[2013/02/19 16:03:41 | 000,447,147 | —- | M] () – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1.zip
[2013/02/18 08:37:37 | 000,380,040 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/02/15 19:27:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/02/15 19:08:22 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/02/14 08:53:01 | 000,181,901 | —- | M] () – C:\Documents and Settings\Andy\Desktop\MARLETTE JR SR.dwg
[2013/02/13 09:36:19 | 000,645,574 | —- | M] () – C:\Documents and Settings\Andy\My Documents\Architectural 2-1-13 dd reveiw.dwf
[2013/02/12 17:56:04 | 001,615,313 | —- | M] () – C:\Documents and Settings\Andy\My Documents\SLED.skp
[2013/02/12 17:51:26 | 000,054,474 | —- | M] () – C:\Documents and Settings\Andy\Desktop\SLED.jpg
[2013/02/12 13:07:03 | 000,007,576 | —- | M] () – C:\Documents and Settings\Andy\Desktop\wordpress-logo.png
[2013/02/12 13:05:03 | 000,017,910 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Biggby_Coffee_Logo.png
[2013/02/12 12:57:29 | 000,000,184 | —- | M] () – C:\Documents and Settings\Andy\Desktop\php.ini
[2013/02/12 12:43:45 | 000,028,331 | —- | M] () – C:\Documents and Settings\Andy\Desktop\andy.jpg
[2013/02/12 11:32:35 | 000,262,546 | —- | M] () – C:\Documents and Settings\Andy\Desktop\buddypress-group-documents.zip
[2013/02/12 11:01:09 | 005,440,753 | —- | M] () – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1.zip
[2013/02/12 10:26:35 | 000,078,195 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Sidewalk.skp
[2013/02/11 12:23:23 | 000,445,908 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.dwg
[2013/02/11 12:23:07 | 000,620,974 | —- | M] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.bak

========== Files Created - No Company Name ==========

[2013/03/11 11:40:00 | 000,000,649 | —- | C] () – C:\Documents and Settings\Andy\Desktop\NTREGOPT.lnk
[2013/03/11 11:40:00 | 000,000,630 | —- | C] () – C:\Documents and Settings\Andy\Desktop\ERUNT.lnk
[2013/03/08 16:44:20 | 000,245,455 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Lintel.psd
[2013/03/08 16:39:03 | 000,013,154 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Plan.pdf
[2013/03/08 16:38:16 | 000,183,015 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Lintel.pdf
[2013/03/08 12:24:01 | 000,597,667 | —- | C] () – C:\Documents and Settings\Andy\Desktop\AdwCleaner.exe
[2013/03/08 08:38:42 | 000,014,700 | —- | C] () – C:\Documents and Settings\Andy\Desktop\download.htm
[2013/03/07 13:08:34 | 000,041,494 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Office Layout.pdf
[2013/03/06 15:48:07 | 000,000,059 | —- | C] () – C:\WINDOWS\wpd99.drv
[2013/03/06 15:48:05 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2013/03/05 17:34:16 | 000,071,847 | —- | C] () – C:\Documents and Settings\Andy\Desktop\COOP.skp
[2013/03/04 11:33:43 | 000,018,733 | —- | C] () – C:\Documents and Settings\Andy\Desktop\LAMP.jpg
[2013/02/27 10:13:30 | 000,385,349 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.2 - Enlarged Floor Plans - High School.pdf
[2013/02/26 08:45:38 | 000,475,014 | —- | C] () – C:\Documents and Settings\Andy\Desktop\instagram.jpg
[2013/02/25 18:26:49 | 000,336,097 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A2.0 - Interior Elevations - Elementary School.pdf
[2013/02/25 18:26:09 | 000,474,673 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.1 - Enlarged Floor Plan - Elementary School.pdf
[2013/02/25 17:51:13 | 000,391,153 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A1.0 - Floor Plans - Door Schedule.pdf
[2013/02/21 16:53:20 | 000,000,138 | —- | C] () – C:\Documents and Settings\Andy\Desktop\tube.htm
[2013/02/21 14:01:18 | 000,060,032 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Marlette Elementary Frost Slabs.pdf
[2013/02/21 12:18:37 | 000,359,943 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A5.1 - Roof Details.pdf
[2013/02/21 12:17:57 | 000,234,202 | —- | C] () – C:\Documents and Settings\Andy\Desktop\A5.0 - Roof Plans.pdf
[2013/02/20 17:15:14 | 000,366,036 | —- | C] () – C:\Documents and Settings\Andy\Desktop\truck-single.jpg
[2013/02/20 13:16:50 | 001,527,671 | —- | C] () – C:\Documents and Settings\Andy\Desktop\buddypress.1.6.4.zip
[2013/02/20 11:56:39 | 000,051,344 | —- | C] () – C:\Documents and Settings\Andy\Desktop\snow in mqt.jpg
[2013/02/20 11:10:37 | 000,298,143 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Existing Windows.jpg
[2013/02/19 16:25:04 | 000,079,423 | —- | C] () – C:\Documents and Settings\Andy\Desktop\midlandfacade.jpg
[2013/02/19 16:24:59 | 000,072,736 | —- | C] () – C:\Documents and Settings\Andy\Desktop\flatrock.jpg
[2013/02/19 16:24:53 | 000,398,359 | —- | C] () – C:\Documents and Settings\Andy\Desktop\woodland-park-1.jpg
[2013/02/19 16:03:36 | 000,447,147 | —- | C] () – C:\Documents and Settings\Andy\Desktop\thethe-image-slider.1.1.8.1.zip
[2013/02/19 11:20:52 | 000,324,577 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Elevations.bak
[2013/02/19 11:20:52 | 000,304,118 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Elevations.dwg
[2013/02/15 19:17:30 | 000,000,384 | -H– | C] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/02/14 08:53:01 | 000,181,901 | —- | C] () – C:\Documents and Settings\Andy\Desktop\MARLETTE JR SR.dwg
[2013/02/13 09:36:19 | 000,645,574 | —- | C] () – C:\Documents and Settings\Andy\My Documents\Architectural 2-1-13 dd reveiw.dwf
[2013/02/12 17:56:03 | 001,615,313 | —- | C] () – C:\Documents and Settings\Andy\My Documents\SLED.skp
[2013/02/12 17:51:26 | 000,054,474 | —- | C] () – C:\Documents and Settings\Andy\Desktop\SLED.jpg
[2013/02/12 13:05:01 | 000,017,910 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Biggby_Coffee_Logo.png
[2013/02/12 12:43:38 | 000,028,331 | —- | C] () – C:\Documents and Settings\Andy\Desktop\andy.jpg
[2013/02/12 12:16:45 | 000,000,184 | —- | C] () – C:\Documents and Settings\Andy\Desktop\php.ini
[2013/02/12 11:32:34 | 000,262,546 | —- | C] () – C:\Documents and Settings\Andy\Desktop\buddypress-group-documents.zip
[2013/02/12 11:13:41 | 000,007,576 | —- | C] () – C:\Documents and Settings\Andy\Desktop\wordpress-logo.png
[2013/02/12 11:00:20 | 005,440,753 | —- | C] () – C:\Documents and Settings\Andy\Desktop\wordpress-3.5.1.zip
[2013/02/12 10:26:35 | 000,078,195 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Sidewalk.skp
[2013/02/11 10:07:01 | 000,620,974 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.bak
[2013/02/11 10:07:01 | 000,445,908 | —- | C] () – C:\Documents and Settings\Andy\Desktop\Base Concepts.dwg
[2012/12/06 13:01:56 | 000,000,248 | —- | C] () – C:\WINDOWS\FXEZQJV.INI
[2012/07/31 12:04:23 | 000,000,811 | —- | C] () – C:\Documents and Settings\Andy\.recently-used.xbel
[2012/02/15 02:12:11 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/11/28 18:22:23 | 000,000,000 | —- | C] () – C:\WINDOWS\TMonitor.INI
[2011/10/13 16:29:11 | 000,110,456 | —- | C] () – C:\Documents and Settings\Andy\g2ax_customer_downloadhelper_win32_x86.exe
[2011/10/10 15:07:33 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/10 15:07:33 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/10 15:07:33 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/10 15:07:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/10 15:07:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/09/16 17:57:43 | 000,879,964 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1682135861-2545026859-4075531753-1005-0.dat
[2011/09/16 17:57:41 | 000,365,678 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/09/06 19:08:37 | 000,000,147 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/03/16 09:38:22 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/06/12 08:40:32 | 000,120,838 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_flv.cab
[2009/06/11 14:33:29 | 000,001,636 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_3gp.cab
[2009/03/20 10:57:43 | 000,000,000 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_avi.cab
[2009/03/20 10:57:42 | 000,001,539 | —- | C] () – C:\Documents and Settings\Andy\Application Data\msvideo_mpg.dat
[2009/03/12 10:56:41 | 000,001,541 | —- | C] () – C:\Documents and Settings\Andy\Application Data\update_sp1v1.cab
[2009/03/12 10:56:41 | 000,000,016 | —- | C] () – C:\Documents and Settings\Andy\Application Data\update_sp1v2.cab

========== ZeroAccess Check ==========

[2008/04/25 17:34:35 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/09/09 10:16:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Good…..glad to hear!

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Happy Tuesday :/
Mbam found nothing but Eset did..
Hey, thanks again for your help with this. Noticed yesterday that something else is apparently working better. There was one specific folder on our network which is accessed frequently (our active jobs). Whenever I went to open that specific folder there would be a long lag before it would display the contents of the folder.. It's almost instant now :)

Mbam

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.03.11.09

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Andy :: MODEL [administrator]

3/11/2013 2:25:13 PM
mbam-log-2013-03-11 (14-25-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 290882
Time elapsed: 19 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


ESET

C:\Documents and Settings\Andy\My Documents\Downloads\InstallFreeRARExtractFrog.exe a variant of Win32/Bundled.Toolbar.Ask application
C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1321\A0154338.exe a variant of Win32/InstallCore.D application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI