This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Scammed by "Toshiba Tech Support?" [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, thank you for taking the time to look at this post. I bought a Toshiba laptop in November 2013. It has Windows 8 and I have been very unhappy with it since I purchased it. Today I thought that I would finally do something about it and called what I though to be Toshiba Tech Support [removed]). First thing she had me do was go to Showmypc.com (obvious mistake #1). After remotely logging in, she directed me to Run where she typed in "cmd" and I don't remember what she put after that but she showed me how something there wasn't functioning properly. Next she went to msconfig and under services pointed out how many operations had "stopped" and this wasn't a good thing. Long story short she kept opening things and pointing out things that were supposedly bad. Next she went to filehippo did some sort of what looked like to be a system scan and at the end stuff started showing up in red and said system was corrupt. She then began downloading a software and this is where I really started to become alarmed. This is when I asked her if she had a case# and call back because I had to go (40 minutes later). She tried to talk me into leaving my computer logged in so that the Tech guy (she just did diagnostic) could continue to work on it. I hung up on her and disconnected from the internet. As far as downloads the only thing I can see is SUPERAntiSpyware. I want to make sure there is nothing else on my system. I have already changed my most of my passwords and am using a different computer until I make sure the other one is clean. I appreciate any assistance on this!
Hi,

It does look like you are being scammed by a third party support. There are support companies that do support for various companies and quite often the "Techs" use scare tactics to sell support packages or fix your computer for a feE. The parent company, Toshiba in your case, is not part of this process. They did contract out the support but unless someone reports this to them they are unaware of this happening.

They point out things like services not running. This is normal as all windows services are not required to run all of the time. They will also show you the Event log and all of the errors. All computers have errors reported in the event log. Most are not really errors, just an event.

Does this sound familar?
http://forums.whatthetech.com/index.php?sh…st&p=817616
Yes, it does sound somewhat familiar. I do have the feeling that they were getting ready to try to sell me something. I just want to be reassured that they were not able to do anything to my computer before I disconnected.
Hi Shinelikestars,

With these types of scams using what is all ready on the computer is usually enough to scare the unwary into buying a support package. They are smart enough not to leave anything that can be traced back to them. The remote access is easily explained as a way to have a better look at the system. The link they used to log onto your computer is probably dead now.


We can have a look and see if anything shows in this scan.


Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTL logfile created on: 4/15/2013 5:16:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deanna\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16384)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.89 Gb Total Physical Memory | 2.11 Gb Available Physical Memory | 54.35% Memory free
7.39 Gb Paging File | 5.71 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.04 Gb Total Space | 523.96 Gb Free Space | 89.41% Space Free | Partition Type: NTFS

Computer Name: DEANNA | User Name: Deanna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\NortonInstaller\{CCC44C7A-717C-4ea0-A378-79ADF863BF19}\NAT\562C4DD5\1.6.0.17\InstStub.exe (Symantec Corporation)
PRC - C:\Users\Deanna\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Toshiba\System Setting\TSleepSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\wincfi39.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\Toshiba\Teco\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\Toshiba\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV:64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV - (NAT) – C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe (Symantec Corporation)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (taisregispinger) – C:\Program Files (x86)\Toshiba\ToshibaRegistration\TaisRegistPinger.exe (Toshiba America Information Systems.)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (PCCUJobMgr) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.15\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GFNEXSrv) – C:\Program Files (x86)\Toshiba\Password Utility\GFNEXSrv.exe ()
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\Drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (RTWlanE) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (ccSet_NAT) – C:\Windows\SysNative\Drivers\NATx64\0106000.011\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\Drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (Thotkey) – C:\Windows\SysNative\Drivers\Thotkey.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (iaStorA) – C:\Windows\SysNative\Drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (RTL8168) – C:\Windows\SysNative\Drivers\Rt630x64.sys (Realtek )
DRV:64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\Drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\Drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\Drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\Drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\Drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SymELAM) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymELAM.sys (Symantec Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\Drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\Drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\Drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ccSet_NARA) – C:\Windows\SysNative\Drivers\NARAx64\0401000.00B\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\symnets.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\Drivers\NISx64\1400000.088\srtspx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130415.003\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130415.003\eng64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20120611.002\IDSVia64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20120615.003\BHDrvx64.sys (Symantec Corporation)
DRV - (PEGAGFN) – C:\Program Files (x86)\Toshiba\Password Utility\PEGAGFN.sys (PEGATRON)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.toshiba.com [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://mystart.toshiba.com [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE:64bit: - HKLM\..\SearchScopes\{7FC83991-43C2-44C5-9B60-3A06ADC52B7A}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc=MATBJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.toshiba.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://mystart.toshiba.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE - HKLM\..\SearchScopes\{7FC83991-43C2-44C5-9B60-3A06ADC52B7A}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc=MATBJS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.toshiba.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://mystart.toshiba.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {7FC83991-43C2-44C5-9B60-3A06ADC52B7A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ [2013/04/12 21:43:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ [2013/04/12 21:43:15 | 000,000,000 | —D | M]


O1 HOSTS File: ([2012/07/26 01:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\IPS\IPSBHO.dll (Symantec Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SRS Premium Sound HD] C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TecoResident] C:\Program Files\Toshiba\Teco\TecoResident.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TODDMain] C:\Program Files (x86)\Toshiba\System Setting\TODDMain.exe ()
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TSleepSrv] C:\Program Files (x86)\Toshiba\System Setting\TSleepSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
O4 - HKLM..\Run: [TPUReg] C:\Program Files (x86)\TOSHIBA\Password Utility\Reg.exe (TODO: <公司名稱>)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DFB04FD-8F27-47E8-B38B-C2F6762CE8DA}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/14 06:00:46 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2013/04/15 17:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2013/04/15 17:09:43 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Macromedia
[2013/04/15 17:07:26 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\TOSHIBA
[2013/04/15 17:07:24 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\SRS Labs
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\Searches
[2013/04/15 17:06:49 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/04/15 17:06:49 | 000,000,000 | -H-D | C] – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2013/04/15 17:06:44 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Adobe
[2013/04/15 17:06:38 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\WinBatch
[2013/04/15 17:05:30 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\VirtualStore
[2013/04/15 17:04:41 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Uninstall Information
[2013/04/13 01:38:59 | 000,000,000 | —D | C] – C:\Windows.old
[2013/04/12 22:07:36 | 000,000,000 | —D | C] – C:\windows\SoftwareDistribution
[2013/04/12 21:40:51 | 000,000,000 | –SD | C] – C:\Users\Deanna\AppData\Roaming\Microsoft
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\Favorites
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\Desktop
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/04/12 21:40:51 | 000,000,000 | R–D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\Temporary Internet Files
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Templates
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Start Menu
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\SendTo
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Recent
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\PrintHood
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\NetHood
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Videos
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Pictures
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Documents\My Music
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\My Documents
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Local Settings
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\History
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Cookies
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\Application Data
[2013/04/12 21:40:51 | 000,000,000 | -HSD | C] – C:\Users\Deanna\AppData\Local\Application Data
[2013/04/12 21:40:51 | 000,000,000 | -H-D | C] – C:\Users\Deanna\AppData
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\Temp
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Local\Microsoft
[2013/04/12 21:40:51 | 000,000,000 | —D | C] – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/04/12 21:10:48 | 000,000,000 | -H-D | C] – C:\$SysReset

========== Files - Modified Within 30 Days ==========

[2013/04/15 17:09:12 | 000,001,439 | —- | M] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/04/15 17:07:09 | 000,010,256 | —- | M] () – C:\Users\Deanna\Desktop\Removed Apps.html
[2013/04/15 17:03:11 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/04/12 22:12:40 | 000,000,013 | RHS- | M] () – C:\windows\SysNative\drivers\fbd.sys
[2013/04/12 21:46:08 | 000,848,230 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2013/04/12 21:46:08 | 000,719,418 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2013/04/12 21:46:08 | 000,132,748 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2013/04/12 21:41:08 | 000,017,148 | —- | M] () – C:\windows\diagwrn.xml
[2013/04/12 21:41:08 | 000,017,148 | —- | M] () – C:\windows\diagerr.xml
[2013/04/12 21:39:34 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/04/12 21:39:32 | 3338,006,528 | -HS- | M] () – C:\hiberfil.sys
[2013/04/12 17:18:40 | 000,000,600 | —- | M] () – C:\Users\Deanna\PUTTY.RND

========== Files Created - No Company Name ==========

[2013/04/15 17:09:11 | 000,001,439 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/04/15 17:07:09 | 000,010,256 | —- | C] () – C:\Users\Deanna\Desktop\Removed Apps.html
[2013/04/15 17:06:44 | 000,001,445 | —- | C] () – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/04/12 22:12:40 | 000,000,013 | RHS- | C] () – C:\windows\SysNative\drivers\fbd.sys
[2013/04/12 21:40:51 | 000,002,107 | —- | C] () – C:\Users\Deanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
[2013/04/12 21:40:51 | 000,000,352 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/04/12 21:40:51 | 000,000,334 | —- | C] () – C:\Users\Deanna\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/04/12 21:40:49 | 000,017,148 | —- | C] () – C:\windows\diagwrn.xml
[2013/04/12 21:40:49 | 000,017,148 | —- | C] () – C:\windows\diagerr.xml
[2013/04/12 17:12:36 | 000,000,600 | —- | C] () – C:\Users\Deanna\PUTTY.RND
[2012/09/16 12:41:16 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2012/08/06 09:36:22 | 000,598,780 | —- | C] () – C:\windows\SysWow64\igvpkrng700.bin
[2012/08/06 09:36:08 | 000,064,512 | —- | C] () – C:\windows\SysWow64\igdde32.dll
[2012/08/06 09:36:06 | 000,755,048 | —- | C] () – C:\windows\SysWow64\igcodeckrng700.bin
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2012/07/25 20:48:53 | 000,083,968 | —- | C] () – C:\windows\SysWow64\OEMLicense.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2012/04/20 16:59:44 | 000,001,536 | —- | C] () – C:\windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/07/25 23:07:16 | 019,779,584 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/07/25 23:19:59 | 017,559,552 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/04/15 17:06:38 | 000,000,000 | —D | M] – C:\Users\Deanna\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/07/25 23:44:30 | 000,398,156 | RHS- | M] () – C:\bootmgr
[2012/06/02 10:30:55 | 000,000,001 | -HS- | M] () – C:\BOOTNXT
[2012/08/16 21:01:54 | 000,030,821 | —- | M] () – C:\DiagsCFG.dat
[2013/04/12 21:39:32 | 3338,006,528 | -HS- | M] () – C:\hiberfil.sys
[2013/04/12 21:39:34 | 3758,096,384 | -HS- | M] () – C:\pagefile.sys
[2013/04/12 21:39:34 | 268,435,456 | -HS- | M] () – C:\swapfile.sys

< %systemroot%\Fonts\*.com >
[2012/08/01 06:06:37 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2012/08/01 06:06:37 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2012/08/01 06:06:37 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2012/08/01 06:06:37 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2012/07/26 04:11:41 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/07/28 05:54:00 | 000,321,472 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2012/07/26 04:11:35 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.0.LOCALSETTINGUNIT >
[2013/04/15 17:08:45 | 000,000,359 | -HS- | M] () MD5=1135FB5CFFDCA1707FEB5E3EC4D904B2 – C:\Users\Deanna\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit
[2012/11/03 11:00:45 | 000,000,359 | -HS- | M] () MD5=1135FB5CFFDCA1707FEB5E3EC4D904B2 – C:\Windows.old\Users\Deanna\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit

< MD5 for: EXPLORER.ADML >
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16384_en-us_7bca26f6f419a854\Explorer.adml
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16433_en-us_7bff382ef3f2006f\Explorer.adml
[2012/07/26 03:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.20534_en-us_7c89d5440d0eb990\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16384_none_6e8451187a9a1607\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16420_none_6ec1315e7a6d062c\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16433_none_6eb962507a726e22\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20521_none_6f4bce739389bf4d\Explorer.admx
[2012/06/02 10:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20534_none_6f43ff65938f2743\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2012/10/11 01:53:24 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2012/10/11 04:09:58 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2012/07/25 23:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\SysWOW64\explorer.exe
[2012/07/25 23:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012/07/26 00:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\explorer.exe
[2012/07/26 00:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
[2012/10/11 01:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows.old\windows\SysWOW64\explorer.exe
[2012/10/11 01:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2012/10/11 03:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows.old\windows\explorer.exe
[2012/10/11 03:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe

< MD5 for: EXPLORER.EXE.1760.DMP >
[2012/11/16 11:01:22 | 003,987,801 | —- | M] () MD5=20862EE58AF50DE86CBC19C1EBAC6691 – C:\Windows.old\Users\Deanna\AppData\Local\CrashDumps\explorer.exe.1760.dmp

< MD5 for: EXPLORER.EXE.2224.DMP >
[2012/12/14 13:58:51 | 003,753,558 | —- | M] () MD5=0197D93682B7CE0779A559D1A947E765 – C:\Windows.old\Users\Deanna\AppData\Local\CrashDumps\explorer.exe.2224.dmp

< MD5 for: EXPLORER.EXE.MUI >
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows.old\windows\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows.old\windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_5ebc2e81fd6600eb\explorer.exe.mui
[2012/07/26 03:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_6910d8d431c6c2e6\explorer.exe.mui

< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/04/15 17:06:46 | 000,016,902 | —- | M] () MD5=91905F9B30E41B85E7CC475EF8D0E9F5 – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
[2013/04/11 22:11:13 | 000,419,326 | —- | M] () MD5=D783CDCFB1625E1832FD2BCEAE423664 – C:\Windows.old\windows\Prefetch\EXPLORER.EXE-03C49D11.pf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Windows.old\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/10/11 02:34:54 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=06E77B5F6BB60E11A377B68BA4AA1DA7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_2b74d7cd3a353a33\iexplore.exe
[2013/02/21 07:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_2b6b082b3a3c6f7b\iexplore.exe
[2012/10/11 03:33:47 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=0A5074651C95792D32BCF536D64D0463 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_21202d7b05d47838\iexplore.exe
[2012/07/25 23:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/07/25 23:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_425d1fb32079214f\iexplore.exe
[2012/10/11 03:24:22 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=13F97D5006C3E37D0A4AABC767C0E553 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_37f8bacaec24e2f1\iexplore.exe
[2012/07/26 00:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/07/26 00:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_38087560ec185f54\iexplore.exe
[2012/11/08 02:58:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=2F92EE7EE7E189EBDDADD5BEEB7E9DE0 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_37fabb5eec23159f\iexplore.exe
[2012/12/19 20:51:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=328569E3CA8BDB3FF74A3DBB8A1FE827 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2b7967573a31390b\iexplore.exe
[2012/10/23 23:14:41 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=39F90724C1A98648CCCDDF13631F2D4A – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_424e7c2f2084a4a2\iexplore.exe
[2013/02/05 01:23:09 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=4B20825770C794AF430529FCD962FDF5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_2b6907973a3e3ccd\iexplore.exe
[2012/11/08 02:48:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=4B33704E4B071EC44806846CBE50EB2A – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2121e9b705d2f7c9\iexplore.exe
[2013/02/04 18:49:56 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=50BB41EF1CBC08E10CAB2993EEA15586 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_37eb619aec2f65fa\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows.old\Program Files\Internet Explorer\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_37ef2f80ec2bcb56\iexplore.exe
[2012/10/23 23:20:45 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=79FF6755B94FF918441D8F8162E5AC9C – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_2b75d8173a34538a\iexplore.exe
[2012/12/19 22:27:37 | 000,775,128 | —- | M] (Microsoft Corporation) MD5=7C4D4537048B255A851F19EA2C656BCB – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_37fda574ec207b45\iexplore.exe
[2012/11/08 00:52:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=7EBFC838C815C3DACA135837D8F7906E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2b7694093a33b9c4\iexplore.exe
[2012/10/24 00:43:41 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=8E1B68702CDB0DDC6597357766E941D9 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_37f9d1dcec23e2a7\iexplore.exe
[2013/02/05 02:45:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=97808A1A701DC42B07725F8C3D3BDF8D – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_21145d4505dd7ad2\iexplore.exe
[2012/12/19 21:00:31 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=B8B50206CEA0791C26B63B753BCFB1D4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_42524fc720813d40\iexplore.exe
[2012/10/11 01:41:41 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=BCF25D644DF1288CD9A6524FF7AB23C8 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_424d651d2085a4ec\iexplore.exe
[2012/11/08 00:45:20 | 000,770,520 | —- | M] (Microsoft Corporation) MD5=D05965C02FD5781503968225B22189F4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_424f65b12083d79a\iexplore.exe
[2012/12/19 22:55:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=D865B906C71BD10633BA0E9627050943 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2124bd0505d07710\iexplore.exe
[2013/02/05 01:23:07 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=DEAE808A574CF9FC667D6939387FC1CE – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_42400bed209027f5\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows.old\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_4243d9d3208c8d51\iexplore.exe
[2013/02/21 09:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_21165dd905dbad80\iexplore.exe
[2012/10/24 02:08:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=F78F14096EB41341C4D880CEA6D681A2 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_21212dc505d3918f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows.old\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows.old\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\WinSxS\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_31b50ad823c5a03b\iexplore.exe.mui
[2012/07/26 03:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_3c09b52a58266236\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-6C28DB75.PF >
[2012/11/18 19:30:13 | 000,073,556 | —- | M] () MD5=F083377854D99A96444F3057F2815753 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-6C28DB75.pf

< MD5 for: IEXPLORE.EXE-6C28DB76.PF >
[2012/11/18 19:30:13 | 000,131,702 | —- | M] () MD5=9F8ADD236CDF8A9D488168CC75839823 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-6C28DB76.pf

< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/04/15 17:09:42 | 000,094,082 | —- | M] () MD5=CAAB89892A490ACC3A0F39B53450F232 – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
[2013/04/12 17:57:18 | 000,136,230 | —- | M] () MD5=EAE12BB7B3DEF0549719CD702BF9FD96 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf

< MD5 for: IEXPLORE.EXE-F4FB5D2F.PF >
[2013/04/15 17:14:21 | 000,217,758 | —- | M] () MD5=30E17B09895CF3032062765343BF4BC4 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
[2013/04/12 17:57:18 | 000,131,032 | —- | M] () MD5=5AF8A34E22F450A1F7D161EE1BFF8512 – C:\Windows.old\windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf

< MD5 for: SERVICES >
[2012/07/26 01:26:49 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows.old\windows\System32\Drivers\etc\services
[2012/07/26 01:26:47 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services

< MD5 for: SERVICES.CFG >
[2012/04/04 01:53:54 | 000,585,987 | —- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2012/12/18 10:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Windows.old\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 15:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows.old\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
[2011/06/06 15:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2012/09/20 02:33:11 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=581190907DA1CF8CB7B87B35FFE64A07 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
[2012/07/26 01:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\windows\SysNative\services.exe
[2012/07/26 01:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012/09/20 02:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows.old\windows\System32\services.exe
[2012/09/20 02:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows.old\windows\System32\en-US\services.exe.mui
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\windows\SysNative\en-US\services.exe.mui
[2012/07/26 03:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui

< MD5 for: SERVICES.HEARSTMAGS[1].XML >
[2012/12/05 20:38:39 | 000,000,113 | —- | M] () MD5=105BFB16CCB1387DC66D35D18C69FE86 – C:\Windows.old\Users\Deanna\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\WF086D9A\services.hearstmags[1].xml

< MD5 for: SERVICES.JS >
[2012/07/26 03:54:02 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:53 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:50 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:54:33 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 03:53:57 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/12/30 15:34:40 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2012/12/30 15:34:14 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/22 20:45:52 | 000,069,359 | —- | M] () MD5=80CE8A6918A7BDB5328F93F4A3BB26B0 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.8.0.51_x64__8wekyb3d8bbwe\common\js\services.js

< MD5 for: SERVICES.LNK >
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows.old\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 16:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk

< MD5 for: SERVICES.MOF >
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows.old\windows\System32\wbem\services.mof
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2012/06/02 10:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof

< MD5 for: SERVICES.MSC >
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\System32\en-US\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\System32\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\SysWOW64\en-US\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows.old\windows\SysWOW64\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\windows\SysNative\en-US\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\windows\SysNative\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\en-US\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
[2012/06/02 10:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
[2012/06/02 10:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
[2012/07/26 03:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc

< MD5 for: SERVICES.PTXML >
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows.old\windows\System32\wdi\perftrack\Services.ptxml
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2012/07/25 16:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2012/07/26 03:49:05 | 000,008,017 | —- | M] () MD5=C270056255498A723E7331EFF1AA162F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.2.9200.16384_en-us_edcdb8ec66a62fc0\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2012/06/02 10:34:22 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.2.9200.16384_none_d3d704270306719d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2012/09/20 02:33:55 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2012/09/20 02:33:17 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2012/07/25 23:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\windows\SysNative\winlogon.exe
[2012/07/25 23:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2012/10/11 01:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows.old\windows\System32\winlogon.exe
[2012/10/11 01:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
[2012/10/11 01:45:27 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows.old\windows\System32\en-US\winlogon.exe.mui
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\windows\SysNative\en-US\winlogon.exe.mui
[2012/07/26 03:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.2.9200.16384_en-us_23c238ef8ddaa831\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows.old\windows\System32\wbem\en-US\winlogon.mfl
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2012/07/26 03:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.2.9200.16384_en-us_81848abaa91301c6\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows.old\windows\System32\wbem\winlogon.mof
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2012/07/25 16:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.2.9200.16384_none_d9027134ffac135f\winlogon.mof

< End of report >
OTL Extras logfile created on: 4/15/2013 5:16:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deanna\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16384)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.89 Gb Total Physical Memory | 2.11 Gb Available Physical Memory | 54.35% Memory free
7.39 Gb Paging File | 5.71 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.04 Gb Total Space | 523.96 Gb Free Space | 89.41% Space Free | Partition Type: NTFS

Computer Name: DEANNA | User Name: Deanna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{BA452B9C-1587-4EDC-B2CC-BC2955E82B64}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{F5135599-F3D4-4A8B-8D6E-F58E0D6D62A3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026CA6FA-D822-4248-AC2A-70F1EBF654E1}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{06132DD1-EE24-463E-B89B-2355D5F93917}" = dir=out | name=windows_ie_ac_001 |
"{06AD9964-2BF9-4368-B94F-ADABC59968E9}" = dir=out | name=vimeo |
"{0BD3FF65-397F-4E98-82ED-4F64A38AF919}" = dir=in | name=allrecipes |
"{1AA7B654-9CFB-4EB6-8C89-3B538739980B}" = dir=out | name=encyclopaedia britannica |
"{1B1A7513-A5BA-45E2-BEED-FB91C6D18D1E}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{1BC8AE78-7F8A-40EE-8016-F99623591385}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{21F1304A-741B-4B8C-A861-84015B8F31FE}" = dir=out | name=fox news |
"{22270B30-E54D-4268-ACF2-572BD0AE95E1}" = dir=out | name=google search |
"{22C598E7-3D3F-4A36-AAF2-7F9C3098D942}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{25DF646D-C13E-4E58-A610-ECB324106EE9}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{2A028731-309D-4BC5-886C-6B0F94B326BE}" = dir=out | name=amazon for windows |
"{3034A6BD-116E-4EB7-A8AD-2B37F1203F15}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{39A2D6FB-48BE-4134-904F-F480461BFA43}" = dir=out | name=news place |
"{40CE324F-312D-41C0-BCD7-4D62583FBAEF}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{4315766C-F88C-417A-B093-F6FADC6A51E5}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{4A5156D3-267E-43A6-956A-B734047F2C35}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{4F6B8AF4-F09A-4ECA-83C0-5F3EF69BDF8C}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{5109D091-BEC0-4790-BEE3-C3B75426E225}" = dir=out | name=- games app - |
"{57329F6A-BF3A-431E-BA66-8CA96A5BC4D1}" = dir=out | name=iheartradio |
"{5D5D6B2E-4789-482E-9DE0-F5727B51DD94}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{68E65D64-235F-4E83-9CD6-E66EBCB4530E}" = dir=in | name=toshiba media player by smedio truelink+ |
"{69FE8441-DA9B-49C4-96E8-FAD51A7AF37F}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{74079E1D-DF1A-4674-ADFE-40A44FCF9055}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{75814C70-6287-45FA-AE15-ADC80154AC57}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{78726FD3-8CF7-4ACF-9876-944B2C197A07}" = dir=out | name=stumbleupon |
"{7A8BB043-AF64-4BBC-979A-EBF33785D91D}" = dir=out | name=ebay |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{840A4586-2BFC-482D-B430-DF22F819F216}" = dir=in | name=ebay |
"{932EBE11-BD47-4495-B61B-55337875F452}" = dir=out | name=netflix |
"{97BB1D66-D2CF-4059-8A9C-BA599C682412}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{BC3EC00F-428B-461E-BEAF-13AF741F8F16}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{BC454024-4453-4831-8428-6B1EF9BAE659}" = dir=out | name=norton studio |
"{BECC10F7-559D-45C3-9285-90F513D5643E}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{C6861AC3-1775-4070-9E14-F7CEBDDF6E0A}" = dir=in | name=hp printer control |
"{CB7DDBE5-0D4E-4F1A-A665-283EECA29AAA}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{D1DBE6E5-8D8A-4174-9806-61DABDD3F572}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{DB6517C2-E199-4C64-A20F-FD6B9A071F5E}" = dir=out | name=icookbook se |
"{DC1E6E1F-7D31-4EEA-BF5D-43DAF05C3A52}" = dir=out | name=hp printer control |
"{DC281529-24BA-4CE7-8A42-2FB8829D5498}" = dir=out | name=toshiba central |
"{E0974F27-1613-4FA7-AB99-C981A3EDA3AB}" = dir=out | name=toshiba media player by smedio truelink+ |
"{E27FBAF1-0877-4C72-A19C-63D57126BAAF}" = dir=out | name=merriam-webster dictionary |
"{E4D88A0E-9972-4C34-B7C9-64233C69FB46}" = dir=out | name=allrecipes |
"{E70627BA-CB81-44BA-B22E-8A8E7C3187A1}" = dir=in | name=amazon for windows |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{FA4D3329-C2C3-4C79-8D8F-1CC099E56E1D}" = dir=out | name=book place |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{16562A90-71BC-41A0-B890-D91B0C267120}" = TOSHIBA Function Key
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5944B9D4-3C2A-48DE-931E-26B31714A2F7}" = TOSHIBA eco Utility
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{94F03B8E-CB73-4653-AFE9-79112C01FED2}" = Premium Sound HD
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95CCACF0-010D-45F0-82BF-858643D8BC02}" = TOSHIBA Desktop Assist
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{B8C8422F-01F1-4791-B084-047AAFF9BFCC}" = TOSHIBA Service Station
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client
"{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64
"{FF07604E-C860-40E9-A230-E37FA41F103A}" = TOSHIBA VIDEO PLAYER
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05A55927-DB9B-4E26-BA44-828EBFF829F0}" = TOSHIBA System Settings
"{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform
"{1E6A96A1-2BAB-43EF-8087-30437593C66C}" = TOSHIBA System Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{24B45620-22B6-4E4A-B836-FF30A0B0404E}" = Toshiba Book Place
"{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform
"{2D416A80-0BB1-4D8B-B770-7BE8F53D5937}" = Windows Live UX Platform Language Pack
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3384E1D9-3F18-4A98-8655-180FEF0DFC02}" = TOSHIBA User's Guide
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40F55150-F43D-4C9F-9A00-1A0A6F1EB7F0}" = Movie Maker
"{46316411-80D8-4F68-8118-696E05FCE199}" = Windows Live Essentials
"{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE
"{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = TOSHIBARegistration
"{5CC4C963-F772-4766-BFF2-DE551E205EE9}" = Photo Common
"{60A1253C-2D51-4166-95C2-52E9CF4F8D64}" = Photo Gallery
"{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}" = TOSHIBA Resolution+ Plug-in for Windows Media Player
"{6D35FF17-A8B3-43D3-917E-5A1F2C3FB628}" = Toshiba Password Utility
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B2E55F8-5BA8-4A45-9682-ACB6F2CC0DA5}" = Photo Gallery
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform
"{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}" = Movie Maker
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}" = Toshiba App Place
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® SDK for OpenCL - CPU Only Runtime Package
"InstallShield_{6D35FF17-A8B3-43D3-917E-5A1F2C3FB628}" = Toshiba Password Utility
"NARA" = Norton Online Backup ARA
"NAT" = Norton Anti-Theft
"NIS" = Norton Internet Security
"NortonPCCheckup" = Norton PC Checkup
"NortonSD" = Norton Security Dashboard
"Origin" = Origin
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WTA-2265c128-464e-4ff1-8e4d-d849d827d168" = Virtual Villagers 4 - The Tree of Life
"WTA-76da1b35-48fc-479b-baa9-818e6a5ef58c" = Bejeweled 3
"WTA-9fa4fc38-6ac9-48e7-a74d-1584863167da" = Farmscapes
"WTA-db584d3f-28e1-4813-8869-1f845592420f" = FATE
"WTA-e609a566-b9f7-4813-9861-bb644ce22802" = Polar Bowler
"WTA-ea624cfb-df4a-4b49-be2b-cf9fcbce6ae4" = Penguins!
"WTA-f39b1b02-84b9-4821-89d1-354375329a6f" = Plants vs. Zombies - Game of the Year

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/15/2013 5:07:39 PM | Computer Name = Deanna | Source = Toshiba App Place | ID = 0
Description =

Error - 4/15/2013 5:12:09 PM | Computer Name = Deanna | Source = Customer Experience Improvement Program | ID = 1008
Description =

[ System Events ]
Error - 9/16/2012 1:04:35 PM | Computer Name = Deanna | Source = DCOM | ID = 10010
Description =

Error - 4/12/2013 9:47:04 PM | Computer Name = Deanna | Source = Service Control Manager | ID = 7022
Description = The Windows Search service hung on starting.


< End of report >
I just started using it again yesterday after your post so I haven't tried anything yet. I was having issues with Adobe freezing up and things not printing from our network printer. Not sure if it's the computer or the windows 8. I hate Windows 8! Thank you for all your help!
Hi Shinelikestars,

You are more than welcome.

I hate Windows 8!

I haven't used it yet. I just bounce back and forth between XP an Win7. There a lot of Win8 users on the forum. They may be able to assist you if you are still having problems. It just may be a matter of a few tweaks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI