This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer will only boot in safe mode [Closed]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When starting under last good configuration my computer once again froze at the welcome screen pictured above. I went ahead and did the combofix in safe mode and here is the log. After combofix was finished I restarted my computer and FINALLY it has started in normal mode!!!!!

ComboFix 13-05-05.01 - Simpson 05/05/2013 17:46:54.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.2490 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\DRM\973D.tmp
c:\programdata\Microsoft\Windows\DRM\F6AF.tmp
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}
c:\users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}\chrome.manifest
c:\users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}\chrome\content\_cfg.js
c:\users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}\chrome\content\overlay.xul
c:\users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}\install.rdf
c:\users\Simpson\AppData\Local\yps.exe
c:\users\Simpson\Documents\~WRL2264.tmp
c:\users\Simpson\Documents\~WRL3054.tmp
c:\windows\system32\CBUTTON.OCX
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\pt
c:\windows\system32\pt\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Created from 2013-04-05 to 2013-05-05 )))))))))))))))))))))))))))))))
.
.
2013-05-05 21:56 . 2013-05-05 21:57 ——– d—–w- c:\users\Simpson\AppData\Local\temp
2013-05-05 21:56 . 2013-05-05 21:56 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-05-05 21:56 . 2013-05-05 21:56 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-04-22 20:46 . 2013-04-22 20:46 ——– d—–w- C:\FRST
2013-04-18 20:17 . 2000-01-01 00:00 53248 —-a-w- c:\windows\system32\CSVer.dll
2013-04-18 20:16 . 2000-01-01 00:00 675840 —-a-w- c:\windows\system32\NETwLc32.dll
2013-04-18 20:16 . 2000-01-01 00:00 6637056 —-a-w- c:\windows\system32\drivers\NETwLv32.sys
2013-04-18 20:16 . 2000-01-01 00:00 2756608 —-a-w- c:\windows\system32\NETwLr32.dll
2013-04-18 20:14 . 2000-01-01 00:00 80488 —-a-w- c:\windows\system32\RtNicProp32.dll
2013-04-18 20:14 . 2000-01-01 00:00 363112 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
2013-04-18 20:14 . 2013-04-18 20:14 ——– d—–w- C:\Intel
2013-04-18 20:13 . 2013-04-18 20:13 13464 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-04-18 20:13 . 2013-04-18 20:13 ——– d—–w- c:\users\Simpson\AppData\Local\SlimWare Utilities Inc
2013-04-18 20:12 . 2013-04-18 20:12 ——– d—–w- c:\program files\SlimDrivers
2013-04-16 01:33 . 2008-01-21 02:23 2730536 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B5E49CAE-EE31-4924-B329-10203B58454E}\mpengine.dll
2013-04-10 22:51 . 2013-04-10 23:12 ——– d—–w- c:\windows\system32\MpEngineStore
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-07-30 2363392]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-28 152872]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-24 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-05 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-05 129560]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-26 413696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"NDSTray.exe"="NDSTray.exe" [BU]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-14 1862144]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-12-08 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe" [2011-12-01 247968]
.
c:\users\Simpson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ECACHE
*NewlyCreated* - PXHELP20
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 14:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 21:57]
.
2013-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 21:57]
.
2013-04-22 c:\windows\Tasks\SlimDrivers Startup.job
- c:\program files\SlimDrivers\SlimDrivers.exe [2013-03-29 20:22]
.
2012-08-24 c:\windows\Tasks\update-S-1-5-21-2732826977-1390623016-2335831479-1000.job
- c:\program files\Skillbrains\Updater\Updater.exe [2010-07-18 02:09]
.
2013-04-16 c:\windows\Tasks\update-sys.job
- c:\program files\Skillbrains\Updater\Updater.exe [2010-07-18 02:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: wellmont.org\citrix-gw
TCP: DhcpNameServer = [removed] [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-RunOnce- - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-05 17:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i???????51K???`?????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2013-05-05 18:00:00
ComboFix-quarantined-files.txt 2013-05-05 21:59
.
Pre-Run: 117,886,681,088 bytes free
Post-Run: 118,855,565,312 bytes free
.
- - End Of File - - C8A76E8227A8CB56142BE505DB34C537
Hi ericaps ;)

Very good

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Next


[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Next
AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :
  • checkup.txt
  • JRT log
  • AdwCleaner[S1].txt
  • All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here is the checkup.txt

Results of screen317's Security Check version 0.99.63
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
CCleaner
Java™ 6 Update 3
Java version out of Date!
Adobe Reader 8 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows Vista ™ Home Premium x86 Ran by [removed] on Tue 05/07/2013 at 19:02:09.38 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\freeze.com Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\conduit Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\wmhelper.dll Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT2405280 Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} ~~~ Files Successfully deleted: [File] "C:\Windows\couponprinter.ocx" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\freerip" Successfully deleted: [Folder] "C:\Users\Simpson\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Program Files\coupons" Successfully deleted: [Empty Folder] C:\Users\Simpson\appdata\local\{0306042A-66A4-4942-AD9C-0A35C4200A12} Successfully deleted: [Empty Folder] C:\Users\Simpson\appdata\local\{9AC0F07C-BAB6-499E-B063-7995989D672B} Successfully deleted: [Empty Folder] C:\Users\Simpson\appdata\local\{A4421E96-080C-42F3-A49C-C1F3D36D0B29} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Tue 05/07/2013 at 19:14:59.73 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v2.300 - Logfile created 05/07/2013 at 19:19:01 # Updated 28/04/2013 by Xplode # Operating system : Windows Vista ™ Home Premium Service Pack 2 (32 bits) # User : Simpson - SIMPSON-PC # Boot Mode : Normal # Running from : C:\Users\Simpson\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16448 [OK] Registry is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\Simpson\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. -\\ Chromium vns:64 File : C:\Users\Simpson\AppData\Local\Chromium\User Data\Default\Preferences [OK] File is clean. -\\ Opera v [Unable to get version] File : C:\Users\Simpson\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[S1].txt - [3063 octets] - [07/05/2013 19:19:01] ########## EOF - C:\AdwCleaner[S1].txt - [3123 octets] ##########
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : Simpson [Admin rights]
Mode : Remove – Date : 05/07/2013 19:42:41
| ARK || FAK || MBR |

¤¤¤ Bad processes : 1 ¤¤¤
[SVCHOST] svchost.exe – C:\Windows\System32\svchost.exe [x] -> KILLED [TermProc]

¤¤¤ Registry Entries : 5 ¤¤¤
[HJPOL] HKCU\[…]\System : DisableTaskMgr (0) -> DELETED
[HJPOL] HKCU\[…]\System : DisableRegistryTools (0) -> DELETED
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
— User —
[MBR] 03ab699cbe7f4a77d224ccde7fce3999
[BSP] f0c52b0b4725f28f2222b1b44e950f9b : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 189280 Mo
User != LL1 … KO!
— LL1 —
[MBR] 763397830a407af5c45193ee16988c53
[BSP] 88c87db8a9cca0a75ef3639c95edfb61 : Windows Vista MBR Code
Partition table:
1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 189280 Mo
User != LL2 … KO!
— LL2 —
[MBR] 763397830a407af5c45193ee16988c53
[BSP] 88c87db8a9cca0a75ef3639c95edfb61 : Windows Vista MBR Code
Partition table:
1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 189280 Mo

Finished : << RKreport[2]_D_05072013_02d1942.txt >>
RKreport[1]_S_05072013_02d1940.txt ; RKreport[2]_D_05072013_02d1942.txt
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : Simpson [Admin rights]
Mode : Shortcuts HJfix – Date : 05/07/2013 19:46:59
| ARK || FAK || MBR |

¤¤¤ Bad processes : 1 ¤¤¤
[SVCHOST] svchost.exe – C:\Windows\System32\svchost.exe [x] -> KILLED [TermProc]

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 11 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 5 / Fail 0
Start menu: Success 1 / Fail 0
User folder: Success 1077 / Fail 0
My documents: Success 5 / Fail 5
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 10 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 85 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume2 – 0x3 –> Restored
[D:] \Device\CdRom0 – 0x5 –> Skipped

Finished : << RKreport[3]_SC_05072013_02d1946.txt >>
RKreport[1]_S_05072013_02d1940.txt ; RKreport[2]_D_05072013_02d1942.txt ; RKreport[3]_SC_05072013_02d1946.txt



Also my computer is wanting to do a windows update, it is saying there is 35 important updates. Should I go ahead and update.
Hi ericaps ;)

Also my computer is wanting to do a windows update, it is saying there is 35 important updates. Should I go ahead and update.

Not yet, you will be instructed to do so at a later time.

Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

=============================== Next =======================================


Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

On your next reply please post :
  • OTL.txt
  • Extras.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
OTL logfile created on: 5/8/2013 5:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simpson\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.79% Memory free
6.18 Gb Paging File | 4.47 Gb Available in Paging File | 72.36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 184.84 Gb Total Space | 107.27 Gb Free Space | 58.03% Space Free | Partition Type: NTFS

Computer Name: SIMPSON-PC | User Name: Simpson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Simpson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SlimDrivers\SlimDrivers.exe (SlimWare Utilities, Inc.)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
MOD - C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll ()
MOD - C:\Windows\System32\igfxTMM.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\TOSHIBA\TBS\NotifyTBS.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ()


========== Services (SafeList) ==========

SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (pinger) – C:\TOSHIBA\IVP\ISM\pinger.exe ()
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SVRPEDRV) – C:\Windows\System32\sysprep\UP_date\PEDrv.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (IO_Memory) – C:\WINDOWS\SYSTEM32\SYSPREP\Drivers\ioport.sys File not found
DRV - (Cdralw2k) – File not found
DRV - (Cdr4_xp) – File not found
DRV - (catchme) – C:\Users\Simpson\AppData\Local\Temp\catchme.sys File not found
DRV - (SWDUMon) – C:\Windows\System32\drivers\SWDUMon.sys ()
DRV - (ctxusbm) – C:\Windows\System32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\System32\drivers\KR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\System32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (NETwLv32) – C:\Windows\System32\drivers\NETwLv32.sys (Intel Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}: "URL" = http://www.google.com/search?q={searchTerm…ge={startPage};

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\y, = http://yandex.ru/yandsearch?win=29&cli…511&text=%s
IE - HKCU\..\SearchScopes,DefaultScope = {9D4555DE-9E0B-475D-BCE5-5021BF27458B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}: "URL" = http://yandex.ru/yandsearch?win=29&cli…t={searchTerms}
IE - HKCU\..\SearchScopes\{E5F5D888-2587-E012-A817-7038F5690F26}: "URL" = http://www.brotherstart.com/s/?q={searchTe…g=2-199-0-1tmBC
IE - HKCU\..\SearchScopes\yandex.ru-124739: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Яндекс"
FF - prefs.js..browser.search.selectedEngine: "Яндекс"
FF - prefs.js..browser.search.suggest.enabled: true
FF - prefs.js..browser.search.useDBForOrder: false
FF - prefs.js..keyword.enabled: true
FF - prefs.js..keyword.URL: "http://yandex.ru/yandsearch?win=29&clid=1855511&text="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Simpson\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/03 18:22:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Simpson\AppData\Roaming\Move Networks [2009/10/10 18:58:23 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{D450C550-6059-4C56-8765-776ACDB0F77B}: C:\Users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/03 18:22:06 | 000,000,000 | —D | M]

[2012/09/17 19:52:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Simpson\AppData\Roaming\mozilla\Firefox\Profiles\nahd6ha2.default\extensions
[2012/09/17 19:52:54 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\Simpson\AppData\Roaming\mozilla\Firefox\Profiles\nahd6ha2.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012/07/21 12:47:40 | 000,007,859 | —- | M] () – C:\Users\Simpson\AppData\Roaming\mozilla\firefox\profiles\nahd6ha2.default\searchplugins\yandex.ru-124740.xml

========== Chrome ==========

CHR - homepage: 21843,distribution:{create_all_shortcuts:true,do_not_launch_chrome:true,import_h
istory:false,import_search_engine:false,make_chrome_default:true,show_welcome_pag
e:true,skip_first_run_ui:true,verbose_logging:false},download:{directory_upgrade:
true,extensions_to_open:},extensions:{autoupdate:{next_check:12922471879315600},c
hrome_url_overrides:{bookmarks:[chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html]}},homepage:http://www.google.com/,homepage_is_newtabpage:false,ntp:{pref_version:1,shown_sections:64,tips_cache:{
current_tip:0,tips:[Did you know that there are over 450 browser themes in the Chrome extensions gallery? These include new http://chrome.google.com/extensions/featured/worldcup\>World Cup themes.,The https://chrome.google.com/extensions/\>Chrome extensions gallery has over 5,000 extensions! Explore extensions in different categories, such as blogging, shopping, web development, and more.,Parlez-vous français ? Google Chrome's built-in translation bar helps you read more of the Web. http://www.google.com/support/chrome/bin/answer.py?answer=173424&ctx=tip\>Learn more,Add extra features and functionality to your browser with extensions. Visit the https://chrome.google.com/extensions\ target=\_blank\>Chrome extensions gallery or http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=154007&ctx=tip\ target=\_blank\>learn more.\n,Click and hold down the back button to see your browsing history.,Customize Google Chrome with themes! Check out designs at the https://tools.google.com/chrome/intl/en/themes/index.html\ target=\_blank\>Themes Gallery.,When you use the find bar, yellow markers on the scrollbar help you quickly locate matches on the page. http://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\>Learn more,Search your bookmarks and browsing history from the address bar. http://www.google.com/support/chrome/bin/answer.py?answer=95440&ctx=tip\>Learn more,Have your tabs arranged your way. Click a tab and drag it to a new position along the top of the browser window. http://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\>Learn more,Quickly resize a tab by dragging it to a docking position on your monitor or browser window. http://www.google.com/support/chrome/bin/answer.py?answer=95622#resize&ctx=tip\>Learn more,Drag a link to the tab strip at the top of your browser window to open it in a new tab.,Press Ctrl+T to open a new tab. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press Ctrl+N to open a new browser window. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,To search a site, start typing the site's web address in the address bar and press Tab when prompted. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\>search tricks.,Create address bar keywords for search engines you frequently use. http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95653&ctx=tips\>Learn how,Press Ctrl and + to enlarge a page; Ctrl and - to make the page smaller; and Ctrl and 0 to return the page to its normal size. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press Ctrl+F to search the page you're viewing. Learn more about http://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\>using the find bar.\n,Press Ctrl+S to save your current webpage. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press Ctrl+P to print your current webpage. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press Ctrl+J to see a list of files you've downloaded. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press Ctrl+H to see your browsing history. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Click a tab and drag it out of the tab strip to open it in a new window. http://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\>Learn more\n,Press Ctrl+Shift+N to open a new window in incognito mode. Pages you visit while in incognito mode aren't stored in your browsing history. http://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\>Learn more,Press Ctrl+O to open a file in the browser. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press F11 to go full screen. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Click the star next to the address bar to bookmark the page you're viewing. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.\n,Place shortcuts for your favorite sites on your computer desktop. http://www.google.com/support/chrome/bin/answer.py?answer=95710&ctx=tip\>Learn more,Want to hide thumbnails on the New Tab page? Use the controls at the top of the page. http://www.google.com/support/chrome/bin/answer.py?answer=95451&ctx=tip\>Learn more,Drag the star to the bookmarks bar to create a bookmark for the page? Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.,Drag a link to the bookmarks bar to create an instant bookmark. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.,Press Ctrl+Shift+T repeatedly to reopen the last 10 tabs you closed. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Don't want to leave traces of your browsing history? Browse in incognito mode. http://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\>Learn more,Accidentally closed a window full of tabs? Find it again in the Recently closed section of the New Tab page.,Add a home button next to the address bar. http://www.google.com/support/chrome/bin/answer.py?answer=95314&ctx=tip\>Learn how,Search directly from the address bar. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\>search tips.\n,Press F6 to quickly place your cursor in the address bar. Learn more http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Switching between computers? Keep your Google Chrome settings, bookmarks, and themes in sync across computers. http://www.google.com/support/chrome/bin/answer.py?answer=165138&ctx=tip\>Learn how],topic_id:24013},tips_cache_update:1277936445.9828,tips_server:https://clients2.google.com/tools/service/npredir?r=chrometips_win&hl=en-US,shown_page:1024},profile:{content_settings:{pref_version:1},exited_cleanly:tr
ue},sync_promo:{user_skipped:true},bookmark_bar:{show_on_all_tabs:true}

O1 HOSTS File: ([2013/05/05 17:56:59 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: wellmont.org ([citrix-gw] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://atitesting.webex.com/client/T27LD/nbr/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1A6FA18D-A133-4F0D-A48E-F7827E031C06}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Simpson\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Simpson\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2013/05/08 16:59:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Simpson\Desktop\aswMBR.exe
[2013/05/08 16:58:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Simpson\Desktop\OTL.exe
[2013/05/07 19:30:01 | 000,000,000 | —D | C] – C:\Users\Simpson\Desktop\RK_Quarantine
[2013/05/07 19:01:58 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/05/07 19:01:43 | 000,000,000 | —D | C] – C:\JRT
[2013/05/07 18:54:36 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/05/07 18:54:30 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/05/07 18:54:30 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2013/05/07 18:54:29 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/05/07 18:54:29 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/05/07 18:54:29 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/05/07 18:50:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2013/05/07 18:45:24 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Simpson\Desktop\JRT.exe
[2013/05/05 18:00:03 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/05/05 18:00:03 | 000,000,000 | —D | C] – C:\Users\Simpson\AppData\Local\temp
[2013/05/05 17:59:26 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/05 17:42:18 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/05/05 17:42:18 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/05/05 17:42:18 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/05/05 17:40:18 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/05 17:38:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/04/22 16:46:03 | 000,000,000 | —D | C] – C:\FRST
[2013/04/18 16:19:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/04/18 16:17:08 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2013/04/18 16:16:04 | 006,637,056 | —- | C] (Intel Corporation) – C:\Windows\System32\drivers\NETwLv32.sys
[2013/04/18 16:16:04 | 002,756,608 | —- | C] (Intel Corporation) – C:\Windows\System32\NETwLr32.dll
[2013/04/18 16:16:04 | 000,675,840 | —- | C] (Intel Corporation) – C:\Windows\System32\NETwLc32.dll
[2013/04/18 16:14:49 | 000,363,112 | —- | C] (Realtek ) – C:\Windows\System32\drivers\Rtlh86.sys
[2013/04/18 16:14:49 | 000,080,488 | —- | C] (Realtek Semiconductor Corporation) – C:\Windows\System32\RtNicProp32.dll
[2013/04/18 16:14:15 | 000,000,000 | —D | C] – C:\Intel
[2013/04/18 16:13:02 | 000,000,000 | —D | C] – C:\Users\Simpson\AppData\Local\SlimWare Utilities Inc
[2013/04/18 16:12:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2013/04/18 16:12:57 | 000,000,000 | —D | C] – C:\Program Files\SlimDrivers
[2013/04/18 16:12:50 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Downloaded Installers
[2012/07/13 18:09:33 | 003,463,560 | —- | C] (Microsoft Corporation) – C:\Users\Simpson\AppData\Local\PackSetup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/08 17:00:37 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Simpson\Desktop\aswMBR.exe
[2013/05/08 16:58:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Simpson\Desktop\OTL.exe
[2013/05/08 16:33:17 | 000,000,390 | —- | M] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/05/08 16:33:13 | 000,000,374 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2013/05/08 16:33:10 | 000,013,464 | —- | M] () – C:\Windows\System32\drivers\SWDUMon.sys
[2013/05/08 16:32:57 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/08 16:32:42 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 16:32:42 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 16:32:42 | 000,000,380 | —- | M] () – C:\Windows\tasks\update-sys.job
[2013/05/08 16:32:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/08 16:32:05 | 3210,694,656 | -HS- | M] () – C:\hiberfil.sys
[2013/05/08 03:01:16 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/08 03:01:00 | 000,000,380 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-2732826977-1390623016-2335831479-1000.job
[2013/05/07 19:31:43 | 248,224,405 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/05/07 19:29:54 | 000,816,128 | —- | M] () – C:\Users\Simpson\Desktop\RogueKiller.exe
[2013/05/07 19:18:22 | 000,628,743 | —- | M] () – C:\Users\Simpson\Desktop\adwcleaner.exe
[2013/05/07 19:03:09 | 000,000,129 | —- | M] () – C:\Windows\System32\MRT.INI
[2013/05/07 18:51:40 | 000,604,752 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/05/07 18:51:40 | 000,104,420 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/05/07 18:50:50 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2013/05/07 18:50:50 | 000,001,878 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/05/07 18:45:24 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Simpson\Desktop\JRT.exe
[2013/05/07 18:41:22 | 000,890,825 | —- | M] () – C:\Users\Simpson\Desktop\SecurityCheck.exe
[2013/05/05 18:02:36 | 000,001,356 | —- | M] () – C:\Users\Simpson\AppData\Local\d3d9caps.dat
[2013/05/05 17:56:59 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/05/05 17:41:52 | 000,000,049 | —- | M] () – C:\Windows\NeroDigital.ini
[2013/05/02 02:06:08 | 000,238,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/04/18 16:19:37 | 000,002,040 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/04/18 16:12:58 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/07 19:29:48 | 000,816,128 | —- | C] () – C:\Users\Simpson\Desktop\RogueKiller.exe
[2013/05/07 19:18:21 | 000,628,743 | —- | C] () – C:\Users\Simpson\Desktop\adwcleaner.exe
[2013/05/07 19:03:09 | 000,000,129 | —- | C] () – C:\Windows\System32\MRT.INI
[2013/05/07 18:54:40 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/05/07 18:54:40 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/05/07 18:50:50 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2013/05/07 18:41:13 | 000,890,825 | —- | C] () – C:\Users\Simpson\Desktop\SecurityCheck.exe
[2013/05/05 18:04:02 | 3210,694,656 | -HS- | C] () – C:\hiberfil.sys
[2013/05/05 17:42:18 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/05/05 17:42:18 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/05/05 17:42:18 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/05/05 17:42:18 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/05/05 17:42:18 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/04/18 16:13:05 | 000,000,390 | —- | C] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/04/18 16:13:03 | 000,013,464 | —- | C] () – C:\Windows\System32\drivers\SWDUMon.sys
[2013/04/18 16:12:58 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[2011/10/29 18:42:46 | 000,000,049 | —- | C] () – C:\Windows\NeroDigital.ini
[2011/10/11 18:46:56 | 000,000,000 | —- | C] () – C:\Windows\ToDisc.INI
[2010/10/26 18:56:33 | 000,000,120 | —- | C] () – C:\Users\Simpson\AppData\Local\Yzikahurozececi.dat
[2010/10/26 18:56:33 | 000,000,000 | —- | C] () – C:\Users\Simpson\AppData\Local\Ofumakuladole.bin
[2010/07/20 19:59:13 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/18 18:08:54 | 000,001,923 | —- | C] () – C:\Users\Simpson\AppData\Local\UserProducts.xml
[2010/06/30 18:24:05 | 000,001,356 | —- | C] () – C:\Users\Simpson\AppData\Local\d3d9caps.dat
[2009/07/25 21:51:17 | 000,024,358 | —- | C] () – C:\Users\Simpson\AppData\Roaming\UserTile.png
[2008/05/25 15:32:09 | 000,003,029 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2008/04/17 15:36:50 | 000,034,816 | —- | C] () – C:\Users\Simpson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 08:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/10/10 16:06:12 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\BitTorrent
[2011/08/13 16:56:13 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Dropbox
[2009/08/14 14:23:16 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\GARMIN
[2011/02/08 17:48:21 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\ICAClient
[2010/09/21 19:51:05 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Maternal-Newborn Nursing
[2009/09/02 18:12:12 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\nutritrac
[2012/07/21 12:47:40 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Opera
[2009/07/25 21:51:16 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\PeerNetworking
[2008/11/12 17:13:59 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\SecondLife
[2008/06/20 20:35:13 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\TOSHIBA
[2008/04/19 17:59:57 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Ulead Systems
[2011/06/18 17:18:49 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\W Photo Studio
[2011/06/18 17:16:20 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\W Photo Studio Viewer
[2011/06/18 17:17:57 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Walgreens
[2008/04/17 15:30:35 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\WildTangent
[2008/04/17 17:01:18 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\erdnt\cache\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 22:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SERVICES.EXE >
[2008/01/20 22:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\erdnt\cache\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SVCHOST.EXE >
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\erdnt\cache\svchost.exe
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\svchost.exe
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\erdnt\cache\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\erdnt\cache\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type:
Media Type: Fixed hard disk media
Model:
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 1.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 185.00GB
Starting Offset: 1573912576
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >
OTL Extras logfile created on: 5/8/2013 5:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simpson\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.79% Memory free
6.18 Gb Paging File | 4.47 Gb Available in Paging File | 72.36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 184.84 Gb Total Space | 107.27 Gb Free Space | 58.03% Space Free | Partition Type: NTFS

Computer Name: SIMPSON-PC | User Name: Simpson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] – Reg Error: Value error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00FA2B5C-2588-4AA1-AD18-D92EBD583986}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{035DF52E-B89E-4165-8A5E-6043DEF13F08}" = rport=139 | protocol=6 | dir=out | app=system |
"{058296CF-C6EF-433D-A7D4-4926E5FEBB71}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{05FF8F74-4238-4C96-B1DC-BE8893C6EB9D}" = lport=138 | protocol=17 | dir=in | app=system |
"{07FECAFE-89C2-4B93-B7CD-8EC1B4B48F92}" = lport=3390 | protocol=6 | dir=in | app=system |
"{090E2F46-1D3D-441B-859F-E4CC30ACB25F}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0A7025FA-44C9-4AB7-9846-BD7A726851C5}" = lport=445 | protocol=6 | dir=in | app=system |
"{0C67CF31-837F-4D66-A518-FB0B326B453A}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{0FEF4308-8851-49F5-BF59-295899B424BE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{12BCB1EB-6FB0-4D9E-A44B-6FED06E8E2FE}" = lport=445 | protocol=6 | dir=in | app=system |
"{1452DD0F-2311-40E4-B15C-6E92EC3C008B}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\netproj.exe |
"{16E66C4A-5E8F-4FA3-B31F-54E136F5557B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{1939CD50-7E67-4724-AC14-9391B9BA7A17}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{19BE6BFA-45B0-4644-B94C-6509B279E5D0}" = lport=rpc | protocol=6 | dir=in | svc=eventlog | app=c:\windows\system32\svchost.exe |
"{1AF422A4-5E4F-4D1B-AB09-F0712F32DA3E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{1B9C2C37-C608-49FE-A67E-86B0A2515DFA}" = rport=1723 | protocol=6 | dir=out | app=system |
"{1EFE8349-06C4-4A9E-BA8E-03C731B43C4C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{28255BED-842E-462C-A2E9-6A21E91B41DF}" = rport=2178 | protocol=6 | dir=out | app=system |
"{29C30141-E383-4FED-848F-74864760004F}" = rport=1701 | protocol=17 | dir=out | app=system |
"{2FF57B8C-2FC7-4089-94B2-C16FBEFC43DE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{3341CA83-BE63-4B26-83CA-55D5925FE62D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{370DA6B3-FC29-4806-A92F-F256DB8C4119}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{397D1F5C-C6A6-4ED3-B9CE-C990C02C382D}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{3C6A2B88-AA8C-42D7-9C1F-9E8CFC1C8BD8}" = rport=2869 | protocol=6 | dir=out | app=system |
"{3E9A629B-90F2-43A0-B591-B8495699AF9A}" = rport=5358 | protocol=6 | dir=out | app=system |
"{417C5A32-A89A-4F6A-BE20-CBA35E0093A3}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{41E7110A-FA9E-415D-941A-5B99711C7152}" = lport=80 | protocol=6 | dir=in | name=@wsmres.dll,-50 |
"{435195B3-1BD7-462F-8E07-1E6B64596957}" = rport=137 | protocol=17 | dir=out | app=system |
"{45E8353A-5EC7-405C-8AC5-774F19198610}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{46C45A69-6BE1-4938-AADE-40E3EA88B0DD}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe |
"{4794B7EB-5647-40EC-8154-5C56F80D1735}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{4ED0AD62-2424-4889-874C-344C20EAD027}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{532549D1-A69B-4DCC-A286-882AD3580D7E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{54D54CCA-852A-4AF0-A8AA-0CFE9D9DADAC}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5AE549F7-EFA8-4B74-A75C-BDBFFDB25C03}" = lport=rpc | protocol=6 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe |
"{60B111AE-C7EA-4C63-A7D5-111125DE25EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{613B07E9-B58C-4A77-9CFC-1F4DB78FB9E3}" = lport=5985 | protocol=6 | dir=in | app=system |
"{61BD653B-4842-4FA9-B85C-264DE5DEC1D7}" = lport=443 | protocol=6 | dir=in | app=system |
"{6730EC34-BF89-46FE-9386-8A5947051553}" = rport=445 | protocol=6 | dir=out | app=system |
"{67E29710-6084-4A5F-8D17-437CC1CF1F80}" = rport=138 | protocol=17 | dir=out | app=system |
"{6B39632C-401D-4099-BBCD-33836C79D5AE}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{6C3F98CA-73A4-4EC3-BF2A-EE3F4628EFD1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6D85EA38-EF35-4B77-B5E2-F169CC7B0490}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6EE3A2C2-6925-4D49-8EF5-4AFD8707E2D8}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{6F284E8D-F32F-4A93-AF39-B0E232EE152C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{700E0336-2F55-488D-8B13-1CAD83260D71}" = lport=162 | protocol=17 | dir=in | svc=snmptrap | app=c:\windows\system32\snmptrap.exe |
"{760A4BF0-408F-4932-A82A-470A11854901}" = lport=rpc | protocol=6 | dir=in | svc=ktmrm | app=c:\windows\system32\svchost.exe |
"{79D4FF55-B2F6-4869-87EF-5F5D90426849}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7A1B22C9-4563-465D-BE45-7849C4C6A286}" = lport=137 | protocol=17 | dir=in | app=system |
"{7F4A1F80-E8F6-43B0-BE43-F07AEC6FFB83}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{83F3CBAA-7BCF-4BFE-BC1B-A6DE193AC875}" = rport=10244 | protocol=6 | dir=out | app=system |
"{850C4931-8660-42C6-B992-4589EDBA70BC}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{85434120-F67D-4503-9DD7-71E0E2DCB7DF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{862761F2-9F7E-49D4-89CF-489044E3E19E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{87EF1A88-4F93-439F-BA6A-6F0190FAA5D6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{88F1E55D-D647-40FB-8223-FE4C24B75FC9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{89E46375-E60F-4CF0-B6F1-FFCC6CD0900D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{8AA772E5-ECB6-4F33-9DB8-F36F0321B75D}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\netproj.exe |
"{8D384677-0846-4BDB-8C8B-1D29D50E3828}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{8ED8B655-62C7-44B0-BFE6-39844730D981}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{90A6EF79-80C1-4339-94BE-28A5749AFA42}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe |
"{90AB25E2-C16B-40FC-AF34-43F5CF3CC59A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{935B3CD0-E119-4192-8EF9-6407EE62BD7F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{9683ED1E-D3B6-4967-8F59-993310EC64C1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{975DB7F4-7FB7-4E79-87CA-8F56F102C000}" = lport=445 | protocol=6 | dir=in | app=system |
"{9B555A8D-56C4-4523-A1B3-84B044174FB8}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{9B926DD5-263C-41DE-AED7-C228A38A1F7C}" = lport=139 | protocol=6 | dir=in | app=system |
"{9C6F22CC-360F-4ACA-A1E5-8FD6B7F3FBED}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{9D18FCBF-1BAF-4500-A330-0A2D42A36A55}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{9E208C2A-426E-402D-A70E-483FFE28FEF8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{A1A3970D-C80C-4BC1-B400-19A312684A87}" = lport=rpc | protocol=6 | dir=in | svc=schedule | app=c:\windows\system32\svchost.exe |
"{A22C5042-FB8E-4B4F-959D-BF80BC450227}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A751D35D-7A73-4E2A-B3F4-568676761ED1}" = lport=10244 | protocol=6 | dir=in | app=system |
"{ABE5C3EE-DF8D-4B59-8758-489E3617E6C3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{AC968984-D862-4D0E-A2DE-BD2D0E371A85}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{ACEA692D-E866-484B-A023-88C8088B15CA}" = lport=2178 | protocol=6 | dir=in | app=system |
"{AD00CF7F-745E-422B-B70B-92DE9DC4D4D2}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{AD988696-7B6C-404C-89CA-1565FED27756}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{ADCED61D-94FC-42D9-B00C-85493296EF6E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{B35E9B1B-35D3-4473-8ECE-70027E6AAC72}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |
"{B4D2B6AC-CBD1-4F63-B8DD-EAFE36E5C53A}" = rport=5357 | protocol=6 | dir=out | app=system |
"{B72D724D-0191-455A-B1D0-6DA9E0D5BE19}" = rport=3702 | protocol=17 | dir=out | svc=bits | app=c:\windows\system32\svchost.exe |
"{B95FC332-0EAE-4B3D-A3AD-BC62067CFAF0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{BBB3343A-81DC-4097-9594-E53DD9A47371}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe |
"{BC7967EF-4098-4C89-AC64-C8071662400F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BD3227AE-34AF-44B6-A4D1-0C3845658AA6}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{BF265446-5EFE-4B99-AFD9-D08E8A4725FE}" = lport=5358 | protocol=6 | dir=in | app=system |
"{C2398D6E-A2EF-4517-B81E-49F4E5D9B559}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{C2B8E5E2-2B1B-4259-9966-7AE23B39D825}" = lport=5357 | protocol=6 | dir=in | app=system |
"{C3EA2452-25BB-49C6-AE96-1F03480A4662}" = lport=1701 | protocol=17 | dir=in | app=system |
"{C6323F54-D59D-4EF1-9773-61DF70D79826}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C6763ADD-DE9C-4256-9E6D-7043F8E2E984}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{CC8B17AE-C4D0-48FE-AECB-DE815C060440}" = lport=3702 | protocol=17 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe |
"{CCBF634E-96FC-49A9-BBFA-4B9C919CA0D7}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |
"{D5E6F756-FFCE-490B-A100-2CF8E2714F33}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{D7E56974-56E9-4C0C-9467-CEEB57DFE52E}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe |
"{DA72968F-8795-4377-AC26-BC84AD611FE4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DB095ABF-BD54-45E0-A8E0-AC882E4EC305}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe |
"{DBAF26EF-9355-4E14-86FD-FFFA69AA7A93}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{DBFA7D7C-0838-4AF7-8960-000946CA6719}" = lport=445 | protocol=6 | dir=in | app=system |
"{E28A51BC-FD29-4B79-959D-49489C1555ED}" = lport=1723 | protocol=6 | dir=in | app=system |
"{E3F1F38B-860E-4CD0-B129-E96EFECBDF08}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{EC6F0465-A23A-48AD-B98F-A7391264D5BF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F17E757B-1EBA-4020-A5A4-B4D1AE17E68C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{F4A96262-DC51-4092-BCD1-7450562C616F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{F9386AAD-C8D1-4D27-8445-5026B87F18CA}" = lport=445 | protocol=6 | dir=in | app=system |
"{FC09540C-CBA9-4091-9410-79D251595AD1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{FC4BBF2A-A33A-447B-97B9-C441E649D235}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{FE4D4960-86E0-49C5-80B7-9BEB695ABA21}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02255BD5-9942-4170-9C79-F6BB3D53CDA9}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe |
"{02994B3E-7346-477A-A48F-1EC061D68991}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{04DABBF6-AA49-46CF-938B-70DA584ED18A}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{04E80306-8170-4C8F-A5BD-C6104EF97D02}" = protocol=6 | dir=in | app=c:\windows\system32\netproj.exe |
"{06196B0F-3743-4CAD-8133-2B10685AC6A8}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{095AEA42-9493-4B8E-BF01-8F35903871A9}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{0E1AB54F-546A-418F-92A9-EE1881BDBD8E}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{0F2F3B36-E39A-4912-A5FE-62FE047337C0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{150DCFD4-8798-46A7-9CB7-2DECA06DB455}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe |
"{21E47655-149D-41A3-91BC-F5F2FF04DABA}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{25DCEBD1-4760-4EDD-B3E4-C85FC664963A}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{2A86289F-9BE4-496E-8CE9-BB55F5E7DB1D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{2AD9D237-BFD6-436A-831C-86BA5632EAE7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{32CB9BD4-9BFD-4FB3-9337-062CAD4820E4}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{3406D870-9848-424B-93E4-0788EED072B8}" = protocol=6 | dir=out | app=c:\windows\system32\msdtc.exe |
"{3BD09067-37FD-48FE-A4C2-047CC5AD76C6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{3EC84A4E-BCD4-43EC-BCD8-17CC071012D3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{440B5A9E-EE5C-4346-9F84-B90C6D891D73}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{451D255B-A920-4C97-BA94-9970625B7FE2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{45E70193-7F9F-482A-B7CB-7191907BAF5A}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{4BC04189-C388-4362-9155-A04FA57740FE}" = protocol=6 | dir=out | app=c:\windows\system32\netproj.exe |
"{56E19BEE-022F-437C-AE8F-E3BA6037B148}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{5C16D427-6D77-47D1-8024-BB277B8DE248}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{6108FC2E-712D-4F8B-9246-615B7262CD76}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{6511F271-874A-4CB1-9B5C-D93BDF8915F2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{66A20537-70BE-416E-A0E7-CD0936675C01}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{674D0DF9-2725-4EAD-8DEA-B4DC8F2C65B8}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{76647AFD-64F0-4C29-848C-3FFE0C7CBC1E}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{78FB6C01-CA57-4F0E-B3E8-93526B47C439}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{798851A1-1453-431A-BE2B-3E0B77F9CA76}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{83DD539C-FB3C-4035-BE83-875AF07655E6}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{868FF85A-CFE4-4B0B-9BA1-416BE5CC4791}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{8724373C-1F3B-45EC-89D6-90C3DBB67C38}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{88A04857-557D-4BBB-9400-42DE7D6FB47F}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{900E8664-5F71-4184-B566-52FA6D71FAE1}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{92B04918-5925-4240-9ECF-58E24AAD3936}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9620397A-B31D-4AD1-A04E-6947C83BCD3A}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{97F5D5B8-21CD-40E0-95C1-36111FAFCDAC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9A692F01-4FDE-426E-B858-85220C7941ED}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9D50BF2F-7292-44A3-8481-CFAA8E58EF5F}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{9ED74689-D914-497E-9220-C2C076EFA741}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe |
"{A01532D5-18EB-4229-B136-DFA000A9B6B8}" = protocol=6 | dir=out | app=c:\windows\system32\msra.exe |
"{A13929EE-B96E-4ECD-B14B-F54424E65DB4}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe |
"{A8058B03-2959-4F98-A9CF-51DAAA0B2A8B}" = protocol=6 | dir=out | app=system |
"{A874B50E-F3A0-4B4A-BDF2-4682BAA97D23}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AA66EC36-604C-4F38-B9ED-0784D490D366}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{AAC53FEF-BC21-409E-A837-200C1C642714}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{ABFC6A3D-F1D5-4EC0-A634-2E2DF38637CB}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B9DC1BDD-7A9C-4731-91C9-0440A471A4C8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{BB593BB3-D766-4573-A2EF-5CE3FA70E23C}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{BB59D709-5415-4981-8CAA-BF83018DFFFC}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{C30C36C2-BB70-43DD-8AAC-7FB507E6790B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C5611767-0FB0-4B26-BDC6-1CA8E4B92A77}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{C59AC8E3-17F3-4BCC-BF6A-BF039E0420AA}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{C610EA06-7961-4174-A8C0-60D9C2FF77C8}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{C7DBBFF7-4EB4-4BC5-B0DD-DC4E580D6BBC}" = protocol=6 | dir=in | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{CABBA6E2-6B52-4604-8A6F-C0EFEE3FCE6F}" = protocol=6 | dir=out | svc=msiscsi | app=c:\windows\system32\svchost.exe |
"{CD7ACDB2-EB65-408A-8756-EB339813755E}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe |
"{D156A3FA-648B-4BEB-BA4E-F4B7C9A7F2F1}" = protocol=6 | dir=in | app=c:\windows\system32\msdtc.exe |
"{D8753FDC-3390-4768-8C67-8B6E765B7997}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{D9F85F4A-73F1-4D3C-BD51-E134587729B1}" = protocol=6 | dir=out | app=system |
"{DAD4158D-120B-453F-94D2-61B730D39935}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe |
"{E89AD7C9-27F3-470B-B39B-0E1A8ACEF7A4}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{E8EF9468-D9C6-484E-8A64-8E0F100BB310}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{F4B89461-AFC0-4981-9BB6-CC8B1BC94D20}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe |
"{F9266E1F-A626-4078-BF2D-951808588EF0}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{FA85B737-AB2A-44D1-8ED7-87E05F627121}" = protocol=6 | dir=in | app=c:\windows\system32\msra.exe |
"{FD9DB6AA-04AC-4ABF-A44C-3CA128444837}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{FEEFE12E-929D-4932-945D-094D2E882779}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FFD2167E-0E28-4AFB-A179-5D31D93C7385}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{FFF59660-7C85-4289-B87B-C4459542E6AB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"TCP Query User{15C323CF-1F86-4124-A0C6-88F1E0C2C9CB}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{2B43BCD6-6F02-418B-8E0A-0DE1BA7C371F}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{2D145BEB-B240-4D85-9298-B40E72F2A7EC}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{4796D38C-BE8C-4531-B7EA-546B07932A8F}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{AE584E2F-0102-4C8E-806D-B24E54FB4C04}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{C5D84F67-DDEC-4FA2-9D7D-E2539098EB0C}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{E905BAC0-E3EF-4F2F-8D83-9FC408C181DD}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |
"TCP Query User{F273A5AA-F2FD-480F-BEF7-29438EF2D2CA}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{150815D4-A004-4058-A0EC-41CF15AC5E8F}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{4A33145D-20A8-468E-8CDA-18E9ACCEB307}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |
"UDP Query User{91C98862-236D-46E9-96BE-B2C7616EAA57}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{AC00D4BC-11E4-4992-888A-5F516D9BCBDC}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{B420C266-0B3E-4A8D-BB7C-D55E5150A1FD}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{BC72AA0A-6E37-4233-A360-DD3F6796878F}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{DF631C06-6BB8-4EAE-AF6E-802A99E40971}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{F539C7C8-A06C-4E67-9F80-7DE368675BA0}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{03895495-B383-4F15-A7F8-0AE976759665}_is1" = updater-[removed]
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix online plug-in (Web)
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CA3A991-B03D-4C92-9922-315E5434E87B}" = PS_AIO_05_C4600_Software_Min
"{1E1746EF-F5BF-4677-8F30-04FE399130DA}" = HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2CDB2DCD-1153-4ED4-9D0A-606231CEFE9A}" = LightScribe Template Designs - Art Pack 1
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{48B82226-75E3-4E90-92CC-D30F79EA6380}" = Norton Security Scan
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{513148E7-B7A1-48B2-B518-668701E546F5}" = LightScribe System Software [removed]
"{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix online plug-in (USB)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7E052F74-10A7-42E7-84EB-01C172F5AB5D}" = SlimDrivers
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix online plug-in (HDX)
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{85548764-32DC-43ED-BAA5-5386FDB2500A}" = LightScribe Template Designs - Urban Pack 1
"{8686D4FE-62EF-46FB-B9FD-00679EB381FF}_is1" = Trojan Killer 2.1
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E0E1E3B-229C-4CF9-8A39-4455477327E4}" = C4600
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A945BD16-4774-4A1F-96A7-118BEC004881}" = mCorev32.ism_new
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.1
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C2D129C0-7508-11DF-9F1B-005056806466}" = Google Earth
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CA0F8FE3-644D-4370-B137-1F7F7A6CAD47}_is1" = lightshot-ie-2.6.0.0
"{CBF3C503-946E-45EA-B347-EACC41781989}" = W Photo Studio
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition
"{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix online plug-in (DV)
"{D08B1161-16E6-4CA4-97EA-606E43BC8441}" = Easy Phone Tunes
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE72186D-A4A5-4504-839C-B14FC3432DA1}" = LightScribe Template Designs - Fantasy Pack 1
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E35A1183-F6D8-4DCA-A111-296AFFA00A5C}" = LightScribe Template Designs - Tattoo Pack 1
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F32ED8B1-2442-4B0E-8DEC-3F3BFC1C2B7F}" = mCPlug
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FDB5E0F3-86EA-4379-8A2F-1BC2436543E9}" = iCloud
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"22A03655B083CBA48D06AC6168E58505D985A435" = Windows Driver Package - Intel (NETwNv32) net (07/14/2010 13.3.0.24)
"6CF78C20C2A7F2CFD53A10716FFCBBCE4DA156A8" = Windows Driver Package - Intel (NETwLv32) net (08/15/2010 13.3.0.137)
"AC3Filter" = AC3Filter (remove only)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"EADM" = EA Download Manager
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photo Creations" = HP Photo Creations
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel® PROSet/Wireless Software
"Shop for HP Supplies" = Shop for HP Supplies
"StyleEase for APA Style" = StyleEase for APA Style
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"WildTangent toshiba Master Uninstall" = TOSHIBA Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/8/2013 3:00:42 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 17286892

Error - 5/8/2013 3:00:58 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/8/2013 3:00:58 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 17302492

Error - 5/8/2013 3:00:58 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 17302492

Error - 5/8/2013 3:01:13 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/8/2013 3:01:13 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 17318092

Error - 5/8/2013 3:01:13 AM | Computer Name = Simpson-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 17318092

Error - 5/8/2013 4:33:46 PM | Computer Name = Simpson-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/8/2013 5:08:02 PM | Computer Name = Simpson-PC | Source = SPP | ID = 16387
Description =

Error - 5/8/2013 5:08:02 PM | Computer Name = Simpson-PC | Source = System Restore | ID = 8193
Description =

[ OSession Events ]
Error - 11/22/2010 7:03:49 PM | Computer Name = Simpson-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 14
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 5/7/2013 7:22:43 PM | Computer Name = Simpson-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 5/7/2013 7:23:03 PM | Computer Name = Simpson-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

Error - 5/7/2013 7:32:55 PM | Computer Name = Simpson-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:30:02 PM on 5/7/2013 was unexpected.

Error - 5/7/2013 7:33:23 PM | Computer Name = Simpson-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 5/7/2013 9:33:12 PM | Computer Name = Simpson-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 5/7/2013 10:12:30 PM | Computer Name = Simpson-PC | Source = DCOM | ID = 10010
Description =

Error - 5/8/2013 3:00:15 AM | Computer Name = Simpson-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

Error - 5/8/2013 3:00:17 AM | Computer Name = Simpson-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

Error - 5/8/2013 4:33:47 PM | Computer Name = Simpson-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-05-08 17:22:20 —————————– 17:22:20.369 OS Version: Windows 6.0.6002 Service Pack 2 17:22:20.369 Number of processors: 2 586 0xF0D 17:22:20.369 ComputerName: SIMPSON-PC UserName: Simpson 17:22:23.084 Initialize success 17:22:33.166 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 17:22:33.166 Disk 0 Vendor: Hitachi_ BBDO Size: 190782MB BusType: 3 17:22:33.260 Disk 0 MBR read successfully 17:22:33.260 Disk 0 MBR scan 17:22:33.260 Disk 0 Windows VISTA default MBR code 17:22:33.276 Disk 0 MBR hidden 17:22:33.276 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 17:22:33.291 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 189280 MB offset 3074048 17:22:33.307 Disk 0 scanning sectors +390719920 17:22:33.338 Disk 0 scanning C:\Windows\system32\drivers 17:22:41.840 Service scanning 17:23:05.147 Modules scanning 17:23:11.778 Disk 0 trace - called modules: 17:23:11.794 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x878054b1]<< 17:23:12.293 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8687a5f8] 17:23:12.293 3 CLASSPNP.SYS[8ab198b3] -> nt!IofCallDriver -> [0x8771c6a0] 17:23:12.293 \Driver\iaStor[0x877389a0] -> IRP_MJ_CREATE -> 0x878054b1 17:23:12.309 Scan finished successfully 17:23:25.210 Disk 0 MBR has been saved successfully to "C:\Users\Simpson\Desktop\MBR.dat" 17:23:25.226 The log file has been saved successfully to "C:\Users\Simpson\Desktop\aswMBR.txt"

Attachments:

Hi ericaps ;)


P2P Programs:

P2P programs are a major source of Malware infections.
From your log I see you have BitTorrent We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
If you wish to keep the program(s), please do not use them until your computer is cleaned.

Information regarding the risk of using these programs can be found from here and here

Next




Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :otl
    DRV - (catchme) – C:\Users\Simpson\AppData\Local\Temp\catchme.sys File not found
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\y, = http://yandex.ru/yandsearch?win=29&cli…511&text=%s
    IE - HKCU\..\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}: "URL" = http://yandex.ru/yandsearch?win=29&cli…t={searchTerms}
    IE - HKCU\..\SearchScopes\{E5F5D888-2587-E012-A817-7038F5690F26}: "URL" = http://www.brotherstart.com/s/?q={searchTe…g=2-199-0-1tmBC
    FF - prefs.js..keyword.URL: "http://yandex.ru/yandsearch?win=29&clid=1855511&text="
    FF - user.js - File not found
    FF - prefs.js..browser.search.defaultenginename: "Яндекс"
    FF - prefs.js..browser.search.selectedEngine: "Яндекс"
    [2012/07/21 12:47:40 | 000,007,859 | —- | M] () – C:\Users\Simpson\AppData\Roaming\mozilla\firefox\profiles\nahd6ha2.default\searchplugins\yandex.ru-124740.xml
    O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
    [2010/10/26 18:56:33 | 000,000,120 | —- | C] () – C:\Users\Simpson\AppData\Local\Yzikahurozececi.dat
    [2010/10/26 18:56:33 | 000,000,000 | —- | C] () – C:\Users\Simpson\AppData\Local\Ofumakuladole.bin
    [2011/10/10 16:06:12 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\BitTorrent
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [EMPTYFLASH]
    [REBOOT]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.
========== OTL ==========
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\Users\Simpson\AppData\Local\Temp\catchme.sys File not found not found.
HKCU\Software\Microsoft\Internet Explorer\SearchURL\y\\| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E5F5D888-2587-E012-A817-7038F5690F26}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E5F5D888-2587-E012-A817-7038F5690F26}\ not found.
Prefs.js: "http://yandex.ru/yandsearch?win=29&clid=1855511&text=" removed from keyword.URL
Prefs.js: "Яндекс" removed from browser.search.defaultenginename
Prefs.js: "Яндекс" removed from browser.search.selectedEngine
C:\Users\Simpson\AppData\Roaming\mozilla\firefox\profiles\nahd6ha2.default\searchplugins\yandex.ru-124740.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NDSTray.exe deleted successfully.
C:\Users\Simpson\AppData\Local\Yzikahurozececi.dat moved successfully.
C:\Users\Simpson\AppData\Local\Ofumakuladole.bin moved successfully.
C:\Users\Simpson\AppData\Roaming\BitTorrent\dlimagecache folder moved successfully.
C:\Users\Simpson\AppData\Roaming\BitTorrent\apps folder moved successfully.
C:\Users\Simpson\AppData\Roaming\BitTorrent folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Simpson\Desktop\cmd.bat deleted successfully.
C:\Users\Simpson\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Simpson
->Flash cache emptied: 3124688 bytes

Total Flash Files Cleaned = 3.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
System Restore Service not available.

OTL by OldTimer - Version 3.2.69.0 log created on 05092013_201311

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI