ptaerehsahh
Topic Starter
This is about another laptop… Toshiba with Vista… *gag*…
Can not connect to internet wireless or Ethernet….
Services are turned off and will not allow me to enable or turn them on.
Windows Vista Home Basic
TOSHIBA
Satellite L355
Posting scans below….
OTL
OTL logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.
Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:UsersluciDesktopOTL.exe (OldTimer Tools)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)
========== Modules (No Company Name) ==========
MOD - C:Program FilesCommon Filesmicrosoft sharedOFFICE14CulturesOFFICE.ODF ()
MOD - C:Program FilesMicrosoft OfficeOffice141033GrooveIntlResource.dll ()
========== Services (SafeList) ==========
SRV - (Yontoo Desktop Updater) – C:Program FilesYontooY2Desktop.Updater.exe C:UsersluciAppDataRoamingYontooYontooDesktop.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:WindowsSystem32MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:Program FilesSkypeUpdaterUpdater.exe (Skype Technologies)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE (Microsoft Corporation)
SRV - (GamesAppService) – C:Program FilesWildTangent GamesAppGamesAppService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_4.EXE (Symantec Corporation)
SRV - (TMachInfo) – C:Program FilesToshibaTOSHIBA Service StationTMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:Program FilesToshibaTOSHIBA DVD PLAYERTNaviSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:Program FilesToshibaConfigFreeCFSvcs.exe (TOSHIBA CORPORATION)
SRV - (IAANTMON) – C:Program FilesIntelIntel Matrix Storage ManagerIAANTmon.exe (Intel Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe (Symantec Corporation)
SRV - (lxbk_device) – C:WindowsSystem32lxbkcoms.exe ( )
SRV - (TosCoSrv) – C:Program FilesToshibaPower SaverTosCoSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA SMART Log Service) – C:Program FilesToshibaSMARTLogServiceTosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:WindowsSystem32TODDSrv.exe (TOSHIBA Corporation)
SRV - (comHost) – C:Program FilesCommon FilesSymantec SharedVAScannercomHost.exe (Symantec Corporation)
SRV - (UleadBurningHelper) – C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe (Ulead Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32DRIVERSnwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32DRIVERSnwlnkflt.sys File not found
DRV - (NAVEX15) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVEX15.SYS File not found
DRV - (NAVENG) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVENG.SYS File not found
DRV - (IpInIp) – system32DRIVERSipinip.sys File not found
DRV - (IDSvix86) – C:ProgramDataSymantecDefinitionsSymcDataipsdefs20100804.001IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) – C:WindowsSystem32driversSYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:WindowsSystem32driversSymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:WindowsSystem32driverssymndisv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:WindowsSystem32driverssymtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:WindowsSystem32driverssymfw.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:WindowsSystem32driverssymredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:WindowsSystem32driverssymdns.sys (Symantec Corporation)
DRV - (COH_Mon) – C:WindowsSystem32driversCOH_Mon.sys (Symantec Corporation)
DRV - (tos_sps32) – C:WindowsSystem32driverstos_sps32.sys (TOSHIBA Corporation)
DRV - (JL2005C) – C:WindowsSystem32driversjl2005c.sys (Windows ® 2000 DDK provider)
DRV - (RTL8169) – C:WindowsSystem32driversRtlh86.sys (Realtek Corporation )
DRV - (mr97310c) – C:WindowsSystem32driversmr97310c.sys (Mars Semiconductor Corp.)
DRV - (SRTSPL) – C:WindowsSystem32driverssrtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:WindowsSystem32driverssrtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:WindowsSystem32driverssrtspx.sys (Symantec Corporation)
DRV - (RTL8187B) – C:WindowsSystem32driversrtl8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:WindowsSystem32driverstdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:WindowsSystem32driversTVALZ_O.SYS (TOSHIBA Corporation)
DRV - (CO_Mon) – C:WindowsSystem32driversCO_Mon.sys (Symantec Corporation)
DRV - (RtlProt) – C:WindowsSystem32driversRtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (FwLnk) – C:WindowsSystem32driversFwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:WindowsSystem32driversKR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:WindowsSystem32driversKR10N.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) – C:WindowsSystem32driversAGRSM.sys (Agere Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLM..SearchScopes,DefaultScope = {7F483B27-FA32-4A99-8F1C-E6E2282EAE18}
IE - HKLM..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSHB
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,StartPageCache = 1
IE - HKCU..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU..SearchScopes{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s;=jbR1Zar…q={searchTerms}
IE - HKCU..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSHB_enUS383
IE - HKCU..SearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={273E85…mp;d=2013-03-02 13:39:42&v;=14.2.0.1&pid;=safeguard&sg;=1&sap;=dsp&q;={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - [removed]/npPicasa3,version=3.0.0: C:Program FilesPicasa2npPicasa3.dll (Google, Inc.)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.1.20125.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~3Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~1MICROS~3Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WindowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/GamesAppPresenceDetector,Version=1.0: C:Program FilesWildTangent GamesAppBrowserIntegrationRegistered11NP_wtapp.dll ()
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:WindowsSystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesCommon FilesSymantec SharedIDSIPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll (Yontoo LLC)
O3 - HKLM..Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O3 - HKCU..ToolbarWebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: LogonHoursAction = 2
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:WindowsSystem32GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:Program FilesMicrosoft OfficeOffice14EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL) - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSystem32userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O24 - Desktop BackupWallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:autoexec.bat – [ NTFS ]
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}Shell - "" = AutoRun
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}ShellAutoRuncommand - "" = E:LaunchU3.exe -a
O33 - MountPoints2EShell - "" = AutoRun
O33 - MountPoints2EShellAutoRuncommand - "" = E:LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:WindowsSystem32ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2013/05/25 02:09:53 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingTemplate
[2013/05/25 02:06:09 | 000,891,248 | —- | C] (AVG Technologies) – C:UsersluciDesktopavg_free_stb_all_9_40_cnet.exe
[2013/05/25 01:43:35 | 000,602,112 | —- | C] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/23 19:20:07 | 000,467,464 | —- | C] (WinZip Computing) – C:UsersluciDesktopWinZipRegistryOptimizer.exe
[2013/05/23 19:02:04 | 000,000,000 | —D | C] – C:ProgramDataErrorEND
[2013/05/21 23:31:00 | 002,382,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2013/05/21 23:22:26 | 000,607,744 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2013/05/21 23:22:26 | 000,176,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2013/05/21 23:22:26 | 000,142,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2013/05/21 23:22:26 | 000,065,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2013/05/21 23:22:25 | 001,800,704 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jscript9.dll
[2013/05/21 23:22:25 | 000,231,936 | —- | C] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2013/05/21 23:22:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2013/05/21 10:48:55 | 000,000,000 | —D | C] – C:Windowspss
[2013/05/21 10:16:16 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingMicrosoftWindowsStart MenuProgramsPhoto2Album
[2013/05/20 22:54:48 | 000,037,376 | —- | C] (Microsoft Corporation) – C:WindowsSystem32cdd.dll
[2013/05/20 22:54:35 | 002,049,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32win32k.sys
[2013/05/20 22:15:21 | 000,000,000 | -HSD | C] – C:found.001
[2013/05/20 09:33:46 | 000,000,000 | -HSD | C] – C:found.000
[2013/05/05 18:28:24 | 000,000,000 | —D | C] – C:Program FilesCommon FilesSkype
[2011/06/11 21:40:29 | 038,147,376 | —- | C] (Apple Inc.) – C:UsersluciQuickTimeInstaller.exe
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/05/25 02:12:00 | 000,000,830 | —- | M] () – C:WindowstasksAdobe Flash Player Updater.job
[2013/05/25 02:09:54 | 000,000,036 | —- | M] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/25 02:08:10 | 000,000,886 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2013/05/25 02:01:02 | 000,607,656 | —- | M] () – C:WindowsSystem32perfh009.dat
[2013/05/25 02:01:02 | 000,105,264 | —- | M] () – C:WindowsSystem32perfc009.dat
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:27:30 | 000,602,112 | —- | M] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/25 00:44:37 | 000,000,882 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2013/05/25 00:43:19 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2013/05/25 00:43:08 | 3080,744,960 | -HS- | M] () – C:hiberfil.sys
[2013/05/24 17:38:59 | 000,000,680 | —- | M] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/23 19:09:02 | 000,000,510 | —- | M] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 23:41:17 | 000,405,872 | —- | M] () – C:WindowsSystem32FNTCACHE.DAT
[2013/05/21 10:17:15 | 000,000,055 | —- | M] () – C:WindowsAPOapp.INI
[2013/05/21 10:16:16 | 000,001,787 | —- | M] () – C:UsersluciDesktopPhoto2Album.lnk
[2013/05/15 10:11:09 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerApp.exe
[2013/05/15 10:11:09 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerCPLApp.cpl
[2013/05/05 19:20:11 | 000,001,699 | —- | M] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2013/05/05 15:12:55 | 002,382,848 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/05/25 02:09:52 | 000,000,036 | —- | C] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/24 22:58:12 | 3080,744,960 | -HS- | C] () – C:hiberfil.sys
[2013/05/23 19:09:02 | 000,000,510 | —- | C] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 10:17:15 | 000,000,055 | —- | C] () – C:WindowsAPOapp.INI
[2013/05/21 10:10:22 | 000,000,680 | —- | C] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/05 19:20:11 | 000,001,699 | —- | C] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2012/11/24 13:20:10 | 000,053,248 | —- | C] () – C:WindowsSystem32CommonDL.dll
[2012/11/24 13:20:10 | 000,002,413 | —- | C] () – C:WindowsSystem32lgAxconfig.ini
[2012/05/28 19:20:06 | 000,015,164 | —- | C] () – C:Windowsmr310twc.ini
[2011/12/08 21:50:07 | 000,000,077 | —- | C] () – C:Windowsm2khd.ini
[2011/02/25 23:09:37 | 000,093,507 | —- | C] () – C:UsersluciCave Springs Church.jpg
[2010/07/28 21:46:20 | 000,013,824 | —- | C] () – C:UsersluciAppDataLocalDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/14 22:49:55 | 000,000,632 | RHS- | C] () – C:Userslucintuser.pol
========== ZeroAccess Check ==========
[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () – C:WindowsassemblyDesktop.ini
[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]
[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = %systemroot%system32wbemfastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = %systemroot%system32wbemwbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/05/25 02:09:53 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingTemplate
[2012/11/23 00:31:20 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingWildTangent
[2013/05/20 22:47:47 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingYontoo
========== Purity Check ==========
========== Custom Scans ==========
< ILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
< >
[2006/11/02 08:58:10 | 000,000,006 | -H– | C] () – C:WindowsTasksSA.DAT
[2006/11/02 08:58:10 | 000,032,644 | —- | C] () – C:WindowsTasksSCHEDLGU.TXT
[2010/06/13 19:14:43 | 000,000,882 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineCore.job
[2010/06/13 19:14:44 | 000,000,886 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineUA.job
[2012/07/22 08:39:03 | 000,000,830 | —- | C] () – C:WindowsTasksAdobe Flash Player Updater.job
< End of report >
OTL extras
OTL Extras logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.
Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{10392ACF-F158-4879-A242-6D25BAC2687C}" = lport=139 | protocol=6 | dir=in | app=system |
"{56E6B9F5-767D-4CCB-9880-C280DF657DB4}" = lport=138 | protocol=17 | dir=in | app=system |
"{72C38984-E1CB-44CE-A5FB-B2018521B1AC}" = rport=139 | protocol=6 | dir=out | app=system |
"{79FEE032-F010-4759-B909-F31D3582B42D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%system32spoolsv.exe |
"{9D33E8DC-C901-4666-9513-AD55F2F8F171}" = lport=6004 | protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14outlook.exe |
"{B66D41CB-6CE6-490A-9004-C53F784FA518}" = rport=138 | protocol=17 | dir=out | app=system |
"{C45C7C25-D6DC-49E4-B7BE-90672335E135}" = rport=137 | protocol=17 | dir=out | app=system |
"{CCA77738-F3B4-4CD1-B507-D897CEFA543E}" = rport=445 | protocol=6 | dir=out | app=system |
"{D345B308-F4F8-458E-BF0D-D8E61B08FCBD}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7B37365-82C8-41F9-8A43-877253BF95DE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FA13C5FE-4F76-42FD-B50A-1C62F1E24036}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{05F7C0F3-2A98-4E47-B391-58C2DE6DDF0F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{09743A40-150F-4C30-B830-6332543D6BE1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{13CA4BFA-2D7B-4338-AFF4-95519C19264B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{15DE6A25-120E-4BCC-A45C-8293894E77C8}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{2A2EC24C-8289-4E89-A83C-3F4E889E970D}" = protocol=17 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{3D7B1895-C945-4762-8D29-D3A89EE0A49C}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{5CAEB0D3-D875-4CA7-B710-9EC5BF86619D}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{6A0FDE05-7646-48CD-BE67-6FEC99965558}" = dir=in | app=c:program filesskypephoneskype.exe |
"{A38ECFC6-1DFB-4D13-9E6B-E59033258ABD}" = protocol=6 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{B8BBEA03-EE71-4648-9E98-B3BF06ED313D}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{F395AC62-872E-4F51-ABB3-E7B5015CE4C1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library
"{0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8}" = Norton 360 HTMLHelp
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{21829177-4DED-4209-AD08-490B3AC9C01A}" = Norton 360
"{224821ED-CADA-4A8A-AC8D-3734CC0F0931}" = Amazon Links
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24DF7221-644B-4C3A-A478-459502D40522}" = Backup
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45690715-80A6-4445-B61D-ADEC5888E8CD}" = Symantec Technical Support Controls
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 2.04
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}" = QuickBooks Financial Center
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1B3874F-3057-11D6-B2EA-0050BA18806B}" = Camera Driver
"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E1E56B8A-1AAF-422A-91DB-625059FB9863}" = TOSHIBA Desktop Links
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4FB5DCD-0681-4B6C-AF2E-121A2DA746EE}" = SymNet
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Digital Binoculars_is1" = Uninstall Digital Binoculars Driver
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"Home Improvement 1-2-3" = Home Improvement 1-2-3
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360 (Symantec Corporation)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WildTangent toshiba Master Uninstall" = WildTangent Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/10/2011 10:17:30 AM | Computer Name = luci-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:58:43 PM, on 5/25/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:UsersluciDesktopHiJackThis.exe
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:PROGRA~1COMMON~1SYMANT~1IDSIPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~3Office14GROOVEEX.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~1MICROS~3Office14URLREDIR.DLL
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDTOSCDSPD.exe
O4 - HKCU..Run: [swg] "C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:Windowssystem32GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~3Office14EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:PROGRA~1MICROS~3Office14ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL
O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:Windowssystem32browseui.dll
–
End of file - 4318 bytes
Can not connect to internet wireless or Ethernet….
Services are turned off and will not allow me to enable or turn them on.
Windows Vista Home Basic
TOSHIBA
Satellite L355
Posting scans below….
OTL
OTL logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.
Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:UsersluciDesktopOTL.exe (OldTimer Tools)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)
========== Modules (No Company Name) ==========
MOD - C:Program FilesCommon Filesmicrosoft sharedOFFICE14CulturesOFFICE.ODF ()
MOD - C:Program FilesMicrosoft OfficeOffice141033GrooveIntlResource.dll ()
========== Services (SafeList) ==========
SRV - (Yontoo Desktop Updater) – C:Program FilesYontooY2Desktop.Updater.exe C:UsersluciAppDataRoamingYontooYontooDesktop.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:WindowsSystem32MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:Program FilesSkypeUpdaterUpdater.exe (Skype Technologies)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE (Microsoft Corporation)
SRV - (GamesAppService) – C:Program FilesWildTangent GamesAppGamesAppService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_4.EXE (Symantec Corporation)
SRV - (TMachInfo) – C:Program FilesToshibaTOSHIBA Service StationTMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:Program FilesToshibaTOSHIBA DVD PLAYERTNaviSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:Program FilesToshibaConfigFreeCFSvcs.exe (TOSHIBA CORPORATION)
SRV - (IAANTMON) – C:Program FilesIntelIntel Matrix Storage ManagerIAANTmon.exe (Intel Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe (Symantec Corporation)
SRV - (lxbk_device) – C:WindowsSystem32lxbkcoms.exe ( )
SRV - (TosCoSrv) – C:Program FilesToshibaPower SaverTosCoSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA SMART Log Service) – C:Program FilesToshibaSMARTLogServiceTosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:WindowsSystem32TODDSrv.exe (TOSHIBA Corporation)
SRV - (comHost) – C:Program FilesCommon FilesSymantec SharedVAScannercomHost.exe (Symantec Corporation)
SRV - (UleadBurningHelper) – C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe (Ulead Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32DRIVERSnwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32DRIVERSnwlnkflt.sys File not found
DRV - (NAVEX15) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVEX15.SYS File not found
DRV - (NAVENG) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVENG.SYS File not found
DRV - (IpInIp) – system32DRIVERSipinip.sys File not found
DRV - (IDSvix86) – C:ProgramDataSymantecDefinitionsSymcDataipsdefs20100804.001IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) – C:WindowsSystem32driversSYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:WindowsSystem32driversSymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:WindowsSystem32driverssymndisv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:WindowsSystem32driverssymtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:WindowsSystem32driverssymfw.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:WindowsSystem32driverssymredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:WindowsSystem32driverssymdns.sys (Symantec Corporation)
DRV - (COH_Mon) – C:WindowsSystem32driversCOH_Mon.sys (Symantec Corporation)
DRV - (tos_sps32) – C:WindowsSystem32driverstos_sps32.sys (TOSHIBA Corporation)
DRV - (JL2005C) – C:WindowsSystem32driversjl2005c.sys (Windows ® 2000 DDK provider)
DRV - (RTL8169) – C:WindowsSystem32driversRtlh86.sys (Realtek Corporation )
DRV - (mr97310c) – C:WindowsSystem32driversmr97310c.sys (Mars Semiconductor Corp.)
DRV - (SRTSPL) – C:WindowsSystem32driverssrtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:WindowsSystem32driverssrtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:WindowsSystem32driverssrtspx.sys (Symantec Corporation)
DRV - (RTL8187B) – C:WindowsSystem32driversrtl8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:WindowsSystem32driverstdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:WindowsSystem32driversTVALZ_O.SYS (TOSHIBA Corporation)
DRV - (CO_Mon) – C:WindowsSystem32driversCO_Mon.sys (Symantec Corporation)
DRV - (RtlProt) – C:WindowsSystem32driversRtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (FwLnk) – C:WindowsSystem32driversFwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:WindowsSystem32driversKR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:WindowsSystem32driversKR10N.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) – C:WindowsSystem32driversAGRSM.sys (Agere Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLM..SearchScopes,DefaultScope = {7F483B27-FA32-4A99-8F1C-E6E2282EAE18}
IE - HKLM..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSHB
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,StartPageCache = 1
IE - HKCU..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU..SearchScopes{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s;=jbR1Zar…q={searchTerms}
IE - HKCU..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSHB_enUS383
IE - HKCU..SearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={273E85…mp;d=2013-03-02 13:39:42&v;=14.2.0.1&pid;=safeguard&sg;=1&sap;=dsp&q;={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - [removed]/npPicasa3,version=3.0.0: C:Program FilesPicasa2npPicasa3.dll (Google, Inc.)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.1.20125.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~3Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~1MICROS~3Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WindowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/GamesAppPresenceDetector,Version=1.0: C:Program FilesWildTangent GamesAppBrowserIntegrationRegistered11NP_wtapp.dll ()
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:WindowsSystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesCommon FilesSymantec SharedIDSIPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll (Yontoo LLC)
O3 - HKLM..Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O3 - HKCU..ToolbarWebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: LogonHoursAction = 2
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:WindowsSystem32GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:Program FilesMicrosoft OfficeOffice14EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL) - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSystem32userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O24 - Desktop BackupWallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:autoexec.bat – [ NTFS ]
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}Shell - "" = AutoRun
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}ShellAutoRuncommand - "" = E:LaunchU3.exe -a
O33 - MountPoints2EShell - "" = AutoRun
O33 - MountPoints2EShellAutoRuncommand - "" = E:LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:WindowsSystem32ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2013/05/25 02:09:53 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingTemplate
[2013/05/25 02:06:09 | 000,891,248 | —- | C] (AVG Technologies) – C:UsersluciDesktopavg_free_stb_all_9_40_cnet.exe
[2013/05/25 01:43:35 | 000,602,112 | —- | C] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/23 19:20:07 | 000,467,464 | —- | C] (WinZip Computing) – C:UsersluciDesktopWinZipRegistryOptimizer.exe
[2013/05/23 19:02:04 | 000,000,000 | —D | C] – C:ProgramDataErrorEND
[2013/05/21 23:31:00 | 002,382,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2013/05/21 23:22:26 | 000,607,744 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2013/05/21 23:22:26 | 000,176,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2013/05/21 23:22:26 | 000,142,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2013/05/21 23:22:26 | 000,065,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2013/05/21 23:22:25 | 001,800,704 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jscript9.dll
[2013/05/21 23:22:25 | 000,231,936 | —- | C] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2013/05/21 23:22:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2013/05/21 10:48:55 | 000,000,000 | —D | C] – C:Windowspss
[2013/05/21 10:16:16 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingMicrosoftWindowsStart MenuProgramsPhoto2Album
[2013/05/20 22:54:48 | 000,037,376 | —- | C] (Microsoft Corporation) – C:WindowsSystem32cdd.dll
[2013/05/20 22:54:35 | 002,049,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32win32k.sys
[2013/05/20 22:15:21 | 000,000,000 | -HSD | C] – C:found.001
[2013/05/20 09:33:46 | 000,000,000 | -HSD | C] – C:found.000
[2013/05/05 18:28:24 | 000,000,000 | —D | C] – C:Program FilesCommon FilesSkype
[2011/06/11 21:40:29 | 038,147,376 | —- | C] (Apple Inc.) – C:UsersluciQuickTimeInstaller.exe
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/05/25 02:12:00 | 000,000,830 | —- | M] () – C:WindowstasksAdobe Flash Player Updater.job
[2013/05/25 02:09:54 | 000,000,036 | —- | M] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/25 02:08:10 | 000,000,886 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2013/05/25 02:01:02 | 000,607,656 | —- | M] () – C:WindowsSystem32perfh009.dat
[2013/05/25 02:01:02 | 000,105,264 | —- | M] () – C:WindowsSystem32perfc009.dat
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:27:30 | 000,602,112 | —- | M] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/25 00:44:37 | 000,000,882 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2013/05/25 00:43:19 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2013/05/25 00:43:08 | 3080,744,960 | -HS- | M] () – C:hiberfil.sys
[2013/05/24 17:38:59 | 000,000,680 | —- | M] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/23 19:09:02 | 000,000,510 | —- | M] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 23:41:17 | 000,405,872 | —- | M] () – C:WindowsSystem32FNTCACHE.DAT
[2013/05/21 10:17:15 | 000,000,055 | —- | M] () – C:WindowsAPOapp.INI
[2013/05/21 10:16:16 | 000,001,787 | —- | M] () – C:UsersluciDesktopPhoto2Album.lnk
[2013/05/15 10:11:09 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerApp.exe
[2013/05/15 10:11:09 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerCPLApp.cpl
[2013/05/05 19:20:11 | 000,001,699 | —- | M] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2013/05/05 15:12:55 | 002,382,848 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/05/25 02:09:52 | 000,000,036 | —- | C] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/24 22:58:12 | 3080,744,960 | -HS- | C] () – C:hiberfil.sys
[2013/05/23 19:09:02 | 000,000,510 | —- | C] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 10:17:15 | 000,000,055 | —- | C] () – C:WindowsAPOapp.INI
[2013/05/21 10:10:22 | 000,000,680 | —- | C] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/05 19:20:11 | 000,001,699 | —- | C] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2012/11/24 13:20:10 | 000,053,248 | —- | C] () – C:WindowsSystem32CommonDL.dll
[2012/11/24 13:20:10 | 000,002,413 | —- | C] () – C:WindowsSystem32lgAxconfig.ini
[2012/05/28 19:20:06 | 000,015,164 | —- | C] () – C:Windowsmr310twc.ini
[2011/12/08 21:50:07 | 000,000,077 | —- | C] () – C:Windowsm2khd.ini
[2011/02/25 23:09:37 | 000,093,507 | —- | C] () – C:UsersluciCave Springs Church.jpg
[2010/07/28 21:46:20 | 000,013,824 | —- | C] () – C:UsersluciAppDataLocalDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/14 22:49:55 | 000,000,632 | RHS- | C] () – C:Userslucintuser.pol
========== ZeroAccess Check ==========
[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () – C:WindowsassemblyDesktop.ini
[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]
[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = %systemroot%system32wbemfastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = %systemroot%system32wbemwbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/05/25 02:09:53 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingTemplate
[2012/11/23 00:31:20 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingWildTangent
[2013/05/20 22:47:47 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingYontoo
========== Purity Check ==========
========== Custom Scans ==========
< ILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
< >
[2006/11/02 08:58:10 | 000,000,006 | -H– | C] () – C:WindowsTasksSA.DAT
[2006/11/02 08:58:10 | 000,032,644 | —- | C] () – C:WindowsTasksSCHEDLGU.TXT
[2010/06/13 19:14:43 | 000,000,882 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineCore.job
[2010/06/13 19:14:44 | 000,000,886 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineUA.job
[2012/07/22 08:39:03 | 000,000,830 | —- | C] () – C:WindowsTasksAdobe Flash Player Updater.job
< End of report >
OTL extras
OTL Extras logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.
Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{10392ACF-F158-4879-A242-6D25BAC2687C}" = lport=139 | protocol=6 | dir=in | app=system |
"{56E6B9F5-767D-4CCB-9880-C280DF657DB4}" = lport=138 | protocol=17 | dir=in | app=system |
"{72C38984-E1CB-44CE-A5FB-B2018521B1AC}" = rport=139 | protocol=6 | dir=out | app=system |
"{79FEE032-F010-4759-B909-F31D3582B42D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%system32spoolsv.exe |
"{9D33E8DC-C901-4666-9513-AD55F2F8F171}" = lport=6004 | protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14outlook.exe |
"{B66D41CB-6CE6-490A-9004-C53F784FA518}" = rport=138 | protocol=17 | dir=out | app=system |
"{C45C7C25-D6DC-49E4-B7BE-90672335E135}" = rport=137 | protocol=17 | dir=out | app=system |
"{CCA77738-F3B4-4CD1-B507-D897CEFA543E}" = rport=445 | protocol=6 | dir=out | app=system |
"{D345B308-F4F8-458E-BF0D-D8E61B08FCBD}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7B37365-82C8-41F9-8A43-877253BF95DE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FA13C5FE-4F76-42FD-B50A-1C62F1E24036}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{05F7C0F3-2A98-4E47-B391-58C2DE6DDF0F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{09743A40-150F-4C30-B830-6332543D6BE1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{13CA4BFA-2D7B-4338-AFF4-95519C19264B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{15DE6A25-120E-4BCC-A45C-8293894E77C8}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{2A2EC24C-8289-4E89-A83C-3F4E889E970D}" = protocol=17 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{3D7B1895-C945-4762-8D29-D3A89EE0A49C}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{5CAEB0D3-D875-4CA7-B710-9EC5BF86619D}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{6A0FDE05-7646-48CD-BE67-6FEC99965558}" = dir=in | app=c:program filesskypephoneskype.exe |
"{A38ECFC6-1DFB-4D13-9E6B-E59033258ABD}" = protocol=6 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{B8BBEA03-EE71-4648-9E98-B3BF06ED313D}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{F395AC62-872E-4F51-ABB3-E7B5015CE4C1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library
"{0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8}" = Norton 360 HTMLHelp
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{21829177-4DED-4209-AD08-490B3AC9C01A}" = Norton 360
"{224821ED-CADA-4A8A-AC8D-3734CC0F0931}" = Amazon Links
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24DF7221-644B-4C3A-A478-459502D40522}" = Backup
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45690715-80A6-4445-B61D-ADEC5888E8CD}" = Symantec Technical Support Controls
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 2.04
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}" = QuickBooks Financial Center
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1B3874F-3057-11D6-B2EA-0050BA18806B}" = Camera Driver
"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E1E56B8A-1AAF-422A-91DB-625059FB9863}" = TOSHIBA Desktop Links
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4FB5DCD-0681-4B6C-AF2E-121A2DA746EE}" = SymNet
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Digital Binoculars_is1" = Uninstall Digital Binoculars Driver
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"Home Improvement 1-2-3" = Home Improvement 1-2-3
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360 (Symantec Corporation)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WildTangent toshiba Master Uninstall" = WildTangent Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/10/2011 10:17:30 AM | Computer Name = luci-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:58:43 PM, on 5/25/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:UsersluciDesktopHiJackThis.exe
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:PROGRA~1COMMON~1SYMANT~1IDSIPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~3Office14GROOVEEX.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~1MICROS~3Office14URLREDIR.DLL
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDTOSCDSPD.exe
O4 - HKCU..Run: [swg] "C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:Windowssystem32GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~3Office14EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:PROGRA~1MICROS~3Office14ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL
O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:Windowssystem32browseui.dll
–
End of file - 4318 bytes