XoXo_LuLu_XoXo
Topic Starter
My computer has been acting very strange lately, I'm not sure if it is a virus, spyware, malware, or if someone is hacking into my computer. When I go to network and sharing center I started to noticed that my firewall would be turned off so I would turn it back on change settings for it to work properly and I would exit screen then go back to to the network and sharing center and it would be off again. I then noticed that at times my computer runs very slow and then at other times it runs fine. I've scanned for viruses and everything comes back fine but I think something or someone is connecting to my computer. I just notice different settings changed, like network discovery will be on when I know it was off, or different things showing about remote access that normally are not activated or haven't been there before. I was on internet earlier and had no sign of internet connection lost then network connection screen popped up saying connect to samsung galaxy and then try connecting to router, or something along those lines. I was looking at the event viewer after network popup and it had logs about firewall not being able to tell user it blocked 2 connections, a user logged off. It says malware was detected when i've never had a scan come back with issues.Also was saying special prililvages were made for user, be was attempted using explicit credentials just Sorry I'm not a little more rate, but I do know things are different and not right. At first I was set on that boyfrind was hacking into my computer but he swearOTL Extras logfile created on: 7/18/2013 9:13:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS
Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3876892959-2368528674-3984381725-1000]
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{98CDF18C-2176-4380-BD0E-0B2EA867428C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{30B48E87-F382-4643-8E06-E968B471682B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{348AB39A-6B1F-471D-BA3F-32E07B82D633}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{82741CEB-B33D-4180-BEEC-483A61187EC6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{D80A6FBE-E723-4B03-8850-BCA96B8DBF70}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"TCP Query User{CE4F62E2-203A-4184-A8A4-33E82A7E7863}C:\program files\microsoft office\office14\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"UDP Query User{422E0F52-E9AC-4B39-BBE2-D927BB7C6434}C:\program files\microsoft office\office14\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series" = Canon MG3100 series MP Drivers
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A6D9B5E-9BAB-4141-85BA-2C6552FA7913}" = Dell Backup and Recovery Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E6C7A4F4-D098-4412-BA79-6806C2675395}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D8CD8BBE-81F6-49CB-84D2-A1E616875792}" = AVG 2012
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Internet Security
"Baidu PC Faster 3.6.0.33146" = Baidu PC Faster
"Canon MG3100 series On-screen Manual" = Canon MG3100 series On-screen Manual
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist Corporate
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"WinLiveSuite" = Windows Live Essentials
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/16/2013 11:04:26 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 11:08:56 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 11:30:43 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 7:29:02 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 5:38:57 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 2:43:45 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 7:36:41 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 9:51:45 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3024
Description =
Error - 7/17/2013 10:18:46 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3013
Description =
Error - 7/18/2013 12:28:12 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 7/17/2013 7:36:42 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/17/2013 8:05:43 PM | Computer Name = LULU | Source = DCOM | ID = 10005
Description =
Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7009
Description =
Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/17/2013 9:47:55 PM | Computer Name = LULU | Source = Microsoft-Windows-Diagnostics-Networking | ID = 5300
Description =
Error - 7/18/2013 12:26:22 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 7/18/2013 12:26:30 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 7/18/2013 12:26:40 AM | Computer Name = LULU | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =
Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
< End of report >
s it is not him.
OTL logfile created on: 7/18/2013 9:13:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS
Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rose\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
========== Services (SafeList) ==========
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe File not found
SRV - (vToolbarUpdater15.3.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (PCFasterSvc_{PCFaster_3.6.0.33146}) – C:\Program Files\Baidu Security\PC Faster\3.6.0.33146\PCFasterSvc.exe (Baidu Inc.)
SRV - (BAVSvc) – C:\Program Files\Baidu Security\Cloud Security\BAVSvc.exe (Baidu, Inc.)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV - (ezSharedSvc) – C:\Windows\System32\ezSharedSvcHost.exe (EasyBits Software AS)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (wanatw) – File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (easytether) – system32\DRIVERS\easytthr.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswNdis2) – C:\Windows\System32\drivers\aswNdis2.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (aswFW) – C:\Windows\System32\drivers\aswFW.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswNdis) – C:\Windows\System32\drivers\aswNdis.sys (ALWIL Software)
DRV - (FlyUsb) – C:\Windows\System32\drivers\FlyUsb.sys (LeapFrog)
DRV - (ssadmdm) – C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) – C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (androidusb) – C:\Windows\System32\drivers\ssadadb.sys (Google Inc)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (PID_PEPI) – C:\Windows\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (toshidpt) – C:\Windows\System32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (DLADResM) – C:\Windows\System32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {4C1EF763-FF77-4D7C-8E5D-189249B83B78}
IE - HKCU\..\SearchScopes\{4C1EF763-FF77-4D7C-8E5D-189249B83B78}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}: C:\Program Files\Updater By Smilebox\Firefox
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: blank:new
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
CHR - plugin: Native Client (Disabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Disabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: AVG SiteSafety plugin (Disabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Disabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Disabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Glitter Text Maker = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bcgebmidacnhidoinadkojhhcpjomhck\3.777_0\
CHR - Extension: Gismeteo = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bfegaehidkkcfaikpaijcdahnpikhobf\2.3.3_0\
CHR - Extension: YouTube = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Ebates Cash Back = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\chhjbpecpncaggjpdakmflnfcopglcmi\3.0.1.16_0\
CHR - Extension: Google Search = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Pump Knuckles Theme = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\dgcllodjkonpmdledaaoihjfckkjmhig\1_0\
CHR - Extension: Mahjongg = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\eegpopcingfghbompjfejakfeaolmbop\1.0.0.2_0\
CHR - Extension: Hospital Hustle = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ehakeingkmjibabcmjdncekhodablbon\0.1_0\
CHR - Extension: Pandora = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: PicMonkey = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fgdgokchhicmaiacmgegjnppjkgogdhm\1.5_0\
CHR - Extension: A Girl in the City = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fklbnfemodbmkehogchaclhggkjmldda\0.1_0\
CHR - Extension: My Scrap Nook = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\gnaghjfblmncnfgjddgelpkbhfdflicf\4.96.1.48221_0\
CHR - Extension: Dropbox = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.6_0\
CHR - Extension: GCH Calendar = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lhammhngpacbengeachfclhcjbjfkfmf\0.0.4_0\
CHR - Extension: Webfetti = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lmpchpgemlpnbapjajinolkefniihpod\4.96.1.48191_0\
CHR - Extension: Love and Death - Bitten = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\mihacdejifldbkobglccfmnfhinealma\0.2_0\
CHR - Extension: Incredible StartPage - Productive Start Page for Chrome! = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ncdfeghkpohnalmpblddmnppfooljekh\1.6.2_0\
CHR - Extension: Blood Ties = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\paldnkgokaahkjfgadfkhbpghcgonbhl\0.2_0\
CHR - Extension: deviantART\u2122 = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pbppfiakkcakldnnhcfncfmclhkhhdcp\2.0.3_0\
CHR - Extension: Gmail = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Dr Wise - Medical Mysteries = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\podjepkbfogcclejdjapofifhfjebeik\0.1_0\
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD67D9B2-CA97-45C7-82AF-F82320ED645F}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E343DDE5-E345-4655-97A9-44B48425462F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E35E3665-1BD0-4F66-8D61-782107C97B01}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\viprotocol - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell\AutoRun\command - "" = F:\PcOptions.exe
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell\AutoRun\command - "" = F:\iStudio.exe
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/07/18 08:49:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/14 05:07:02 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{A133B38B-07CA-450B-8A62-9E3C541EDB24}
[2013/07/14 04:44:00 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{78095194-C4CB-4E11-A49A-BBBABEC0FBE6}
[2013/07/14 04:09:51 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\AquaSoft
[2013/07/14 04:08:16 | 000,000,000 | —D | C] – C:\Program Files\AquaSoft
[2013/07/13 12:15:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{48DAF17A-1F57-4F0D-AE17-5D3E964E4228}
[2013/07/13 03:41:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Magentic
[2013/07/13 00:00:21 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Stardock_Corporation
[2013/07/12 23:59:09 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\PackageAware
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Baidu Security
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:29:17 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Templates\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:28:25 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu
[2013/07/12 19:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Baidu
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Program Files\Baidu Security
[2013/07/12 01:38:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/12 01:38:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/12 01:38:52 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/12 01:38:52 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/12 01:38:52 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/12 01:38:48 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/12 01:38:48 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/12 01:38:43 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/12 00:42:33 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/07/12 00:41:56 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/12 00:41:55 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/12 00:41:55 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/12 00:41:54 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/12 00:41:53 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/12 00:41:52 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/12 00:41:52 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/12 00:41:52 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/12 00:41:47 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/07/12 00:41:43 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/07/09 19:15:44 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\WinRAR
[2013/07/09 18:57:39 | 000,000,000 | —D | C] – C:\Users\Rose\Documents\Graboid
[2013/07/09 18:53:17 | 000,000,000 | —D | C] – C:\ProgramData\Graboid Inc
[2013/07/09 18:53:07 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Geckofx
[2013/07/09 18:53:03 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Mozilla
[2013/07/09 18:47:29 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2013/07/09 18:47:13 | 000,000,000 | —D | C] – C:\Program Files\Graboid
[2013/06/30 02:53:59 | 000,204,784 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswNdis2.sys
[2013/06/30 02:53:58 | 000,104,752 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFW.sys
[2013/06/30 02:53:56 | 000,021,576 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswKbd.sys
[2013/06/30 02:52:48 | 000,012,112 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis.sys
[2013/06/30 02:47:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2013/06/30 01:30:07 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/06/30 01:30:06 | 000,369,584 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:02 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/06/30 01:30:01 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/06/30 01:30:00 | 000,770,344 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:29:52 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/06/30 01:29:50 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/06/30 01:28:16 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/06/30 01:27:13 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/30 01:25:29 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/06/29 18:36:34 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Avg2013
[2013/06/29 18:22:49 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Windows Live Writer
[2013/06/29 12:03:54 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/06/29 07:35:11 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{EB461E1B-B31A-41B8-AF8F-DE14C2EBBB71}
[2013/06/29 01:24:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/06/29 01:21:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2013/06/29 01:21:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2013/06/29 01:18:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2013/06/29 01:17:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2013/06/29 01:17:33 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2013/06/29 01:16:15 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Microsoft Help
[2013/06/29 01:15:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/06/29 01:14:35 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/06/22 23:36:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/22 14:19:36 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\DownLite
[2013/06/21 17:33:11 | 000,000,000 | —D | C] – C:\Users\Rose\Desktop\–SCHOOL–
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/07/18 08:50:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/18 08:49:57 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 06:58:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/18 03:37:41 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/17 21:13:34 | 000,000,000 | —- | M] () – C:\END
[2013/07/17 18:48:57 | 000,000,040 | —- | M] () – C:\user_defpage_list
[2013/07/13 03:15:24 | 000,002,064 | —- | M] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | M] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | M] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | M] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | M] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 02:23:50 | 000,383,440 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/07/12 02:09:29 | 000,640,658 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/12 02:09:29 | 000,118,878 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/12 00:27:43 | 000,003,584 | —- | M] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/09 01:44:55 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/07/09 00:14:07 | 000,006,702 | —- | M] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/07/08 19:02:06 | 000,713,217 | —- | M] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 02:03:58 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/06/30 02:03:58 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/06/30 01:30:15 | 000,770,344 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:30:15 | 000,369,584 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:15 | 000,175,176 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 00:12:46 | 000,000,512 | —- | M] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 16:27:59 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/23 14:27:36 | 000,001,957 | —- | M] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/19 00:44:23 | 000,000,680 | —- | M] () – C:\Users\Rose\AppData\Local\d3d9caps.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/07/13 03:15:24 | 000,002,064 | —- | C] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | C] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | C] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | C] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | C] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 19:29:32 | 000,000,040 | —- | C] () – C:\user_defpage_list
[2013/07/12 00:27:42 | 000,003,584 | —- | C] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/08 19:02:05 | 000,713,217 | —- | C] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 01:29:59 | 000,175,176 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:29:57 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/06/30 00:12:46 | 000,000,512 | —- | C] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 19:44:14 | 000,006,702 | —- | C] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/06/22 23:36:07 | 000,001,957 | —- | C] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/22 23:35:20 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/22 23:35:18 |
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS
Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3876892959-2368528674-3984381725-1000]
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{98CDF18C-2176-4380-BD0E-0B2EA867428C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{30B48E87-F382-4643-8E06-E968B471682B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{348AB39A-6B1F-471D-BA3F-32E07B82D633}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{82741CEB-B33D-4180-BEEC-483A61187EC6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{D80A6FBE-E723-4B03-8850-BCA96B8DBF70}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"TCP Query User{CE4F62E2-203A-4184-A8A4-33E82A7E7863}C:\program files\microsoft office\office14\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"UDP Query User{422E0F52-E9AC-4B39-BBE2-D927BB7C6434}C:\program files\microsoft office\office14\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series" = Canon MG3100 series MP Drivers
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A6D9B5E-9BAB-4141-85BA-2C6552FA7913}" = Dell Backup and Recovery Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E6C7A4F4-D098-4412-BA79-6806C2675395}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D8CD8BBE-81F6-49CB-84D2-A1E616875792}" = AVG 2012
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Internet Security
"Baidu PC Faster 3.6.0.33146" = Baidu PC Faster
"Canon MG3100 series On-screen Manual" = Canon MG3100 series On-screen Manual
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist Corporate
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"WinLiveSuite" = Windows Live Essentials
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/16/2013 11:04:26 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 11:08:56 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 11:30:43 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/16/2013 7:29:02 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 5:38:57 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 2:43:45 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 7:36:41 PM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
Error - 7/17/2013 9:51:45 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3024
Description =
Error - 7/17/2013 10:18:46 PM | Computer Name = LULU | Source = Windows Search Service | ID = 3013
Description =
Error - 7/18/2013 12:28:12 AM | Computer Name = LULU | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 7/17/2013 7:36:42 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/17/2013 8:05:43 PM | Computer Name = LULU | Source = DCOM | ID = 10005
Description =
Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7009
Description =
Error - 7/17/2013 8:05:44 PM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/17/2013 9:47:55 PM | Computer Name = LULU | Source = Microsoft-Windows-Diagnostics-Networking | ID = 5300
Description =
Error - 7/18/2013 12:26:22 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 7/18/2013 12:26:30 AM | Computer Name = LULU | Source = volmgr | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 7/18/2013 12:26:40 AM | Computer Name = LULU | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =
Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
Error - 7/18/2013 12:28:13 AM | Computer Name = LULU | Source = Service Control Manager | ID = 7000
Description =
< End of report >
s it is not him.
OTL logfile created on: 7/18/2013 9:13:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rose\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.10% Memory free
3.43 Gb Paging File | 2.38 Gb Available in Paging File | 69.50% Paging File free
Paging file location(s): c:\pagefile.sys 1530 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 83.67 Gb Free Space | 62.27% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 7.45 Gb Free Space | 50.86% Space Free | Partition Type: NTFS
Computer Name: LULU | User Name: Rose | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rose\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
========== Services (SafeList) ==========
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe File not found
SRV - (vToolbarUpdater15.3.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (PCFasterSvc_{PCFaster_3.6.0.33146}) – C:\Program Files\Baidu Security\PC Faster\3.6.0.33146\PCFasterSvc.exe (Baidu Inc.)
SRV - (BAVSvc) – C:\Program Files\Baidu Security\Cloud Security\BAVSvc.exe (Baidu, Inc.)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV - (ezSharedSvc) – C:\Windows\System32\ezSharedSvcHost.exe (EasyBits Software AS)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (wanatw) – File not found
DRV - (USBAAPL) – System32\Drivers\usbaapl.sys File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (easytether) – system32\DRIVERS\easytthr.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswNdis2) – C:\Windows\System32\drivers\aswNdis2.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (aswFW) – C:\Windows\System32\drivers\aswFW.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswNdis) – C:\Windows\System32\drivers\aswNdis.sys (ALWIL Software)
DRV - (FlyUsb) – C:\Windows\System32\drivers\FlyUsb.sys (LeapFrog)
DRV - (ssadmdm) – C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) – C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (androidusb) – C:\Windows\System32\drivers\ssadadb.sys (Google Inc)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (PID_PEPI) – C:\Windows\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (toshidpt) – C:\Windows\System32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (DLADResM) – C:\Windows\System32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {4C1EF763-FF77-4D7C-8E5D-189249B83B78}
IE - HKCU\..\SearchScopes\{4C1EF763-FF77-4D7C-8E5D-189249B83B78}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{C4AF7745-34C4-4921-8F7A-81A3C9D8B0EB}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}: C:\Program Files\Updater By Smilebox\Firefox
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: blank:new
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
CHR - plugin: Native Client (Disabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Disabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: AVG SiteSafety plugin (Disabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Disabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Disabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Glitter Text Maker = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bcgebmidacnhidoinadkojhhcpjomhck\3.777_0\
CHR - Extension: Gismeteo = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\bfegaehidkkcfaikpaijcdahnpikhobf\2.3.3_0\
CHR - Extension: YouTube = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Ebates Cash Back = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\chhjbpecpncaggjpdakmflnfcopglcmi\3.0.1.16_0\
CHR - Extension: Google Search = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Pump Knuckles Theme = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\dgcllodjkonpmdledaaoihjfckkjmhig\1_0\
CHR - Extension: Mahjongg = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\eegpopcingfghbompjfejakfeaolmbop\1.0.0.2_0\
CHR - Extension: Hospital Hustle = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ehakeingkmjibabcmjdncekhodablbon\0.1_0\
CHR - Extension: Pandora = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: PicMonkey = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fgdgokchhicmaiacmgegjnppjkgogdhm\1.5_0\
CHR - Extension: A Girl in the City = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\fklbnfemodbmkehogchaclhggkjmldda\0.1_0\
CHR - Extension: My Scrap Nook = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\gnaghjfblmncnfgjddgelpkbhfdflicf\4.96.1.48221_0\
CHR - Extension: Dropbox = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.6_0\
CHR - Extension: GCH Calendar = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lhammhngpacbengeachfclhcjbjfkfmf\0.0.4_0\
CHR - Extension: Webfetti = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\lmpchpgemlpnbapjajinolkefniihpod\4.96.1.48191_0\
CHR - Extension: Love and Death - Bitten = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\mihacdejifldbkobglccfmnfhinealma\0.2_0\
CHR - Extension: Incredible StartPage - Productive Start Page for Chrome! = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\ncdfeghkpohnalmpblddmnppfooljekh\1.6.2_0\
CHR - Extension: Blood Ties = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\paldnkgokaahkjfgadfkhbpghcgonbhl\0.2_0\
CHR - Extension: deviantART\u2122 = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pbppfiakkcakldnnhcfncfmclhkhhdcp\2.0.3_0\
CHR - Extension: Gmail = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Dr Wise - Medical Mysteries = C:\Users\Rose\AppData\Local\Google\Chrome\User Data\default\extensions\podjepkbfogcclejdjapofifhfjebeik\0.1_0\
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 189
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD67D9B2-CA97-45C7-82AF-F82320ED645F}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E343DDE5-E345-4655-97A9-44B48425462F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E35E3665-1BD0-4F66-8D61-782107C97B01}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\viprotocol - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rose\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{818b3ab6-fc1a-11de-b43a-00038a000015}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{8977c4d5-2a75-11df-85c1-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{9629c68d-d696-11e1-afb2-00038a000015}\Shell\AutoRun\command - "" = F:\PcOptions.exe
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{a6e2d327-0076-11df-b1ed-00038a000015}\Shell\AutoRun\command - "" = F:\iStudio.exe
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{b36b8768-f360-11de-b5db-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{d91af080-0d53-11df-85c3-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/07/18 08:49:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/14 05:07:02 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{A133B38B-07CA-450B-8A62-9E3C541EDB24}
[2013/07/14 04:44:00 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{78095194-C4CB-4E11-A49A-BBBABEC0FBE6}
[2013/07/14 04:09:51 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\AquaSoft
[2013/07/14 04:08:16 | 000,000,000 | —D | C] – C:\Program Files\AquaSoft
[2013/07/13 12:15:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{48DAF17A-1F57-4F0D-AE17-5D3E964E4228}
[2013/07/13 03:41:38 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Magentic
[2013/07/13 00:00:21 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Stardock_Corporation
[2013/07/12 23:59:09 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\PackageAware
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Baidu Security
[2013/07/12 19:29:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:29:17 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Microsoft\Windows\Templates\Start Menu\Programs\Baidu PC Faster
[2013/07/12 19:28:25 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu
[2013/07/12 19:28:23 | 000,000,000 | —D | C] – C:\ProgramData\Baidu
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Baidu Security
[2013/07/12 19:21:48 | 000,000,000 | —D | C] – C:\Program Files\Baidu Security
[2013/07/12 01:38:56 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/12 01:38:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/12 01:38:52 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/12 01:38:52 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/12 01:38:52 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/12 01:38:48 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/12 01:38:48 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/12 01:38:43 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/12 00:42:33 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/07/12 00:41:56 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/12 00:41:55 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/12 00:41:55 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/12 00:41:54 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/12 00:41:53 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/12 00:41:52 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/12 00:41:52 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/12 00:41:52 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/12 00:41:47 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/07/12 00:41:43 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/07/09 19:15:44 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\WinRAR
[2013/07/09 18:57:39 | 000,000,000 | —D | C] – C:\Users\Rose\Documents\Graboid
[2013/07/09 18:53:17 | 000,000,000 | —D | C] – C:\ProgramData\Graboid Inc
[2013/07/09 18:53:07 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Geckofx
[2013/07/09 18:53:03 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Mozilla
[2013/07/09 18:47:29 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2013/07/09 18:47:13 | 000,000,000 | —D | C] – C:\Program Files\Graboid
[2013/06/30 02:53:59 | 000,204,784 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswNdis2.sys
[2013/06/30 02:53:58 | 000,104,752 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFW.sys
[2013/06/30 02:53:56 | 000,021,576 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswKbd.sys
[2013/06/30 02:52:48 | 000,012,112 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis.sys
[2013/06/30 02:47:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2013/06/30 01:30:07 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/06/30 01:30:06 | 000,369,584 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:02 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/06/30 01:30:01 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/06/30 01:30:00 | 000,770,344 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:29:52 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/06/30 01:29:50 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/06/30 01:28:16 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/06/30 01:27:13 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/06/30 01:25:29 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/06/29 18:36:34 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Avg2013
[2013/06/29 18:22:49 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\Windows Live Writer
[2013/06/29 12:03:54 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/06/29 07:35:11 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\{EB461E1B-B31A-41B8-AF8F-DE14C2EBBB71}
[2013/06/29 01:24:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/06/29 01:21:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2013/06/29 01:21:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/06/29 01:20:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2013/06/29 01:18:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2013/06/29 01:17:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2013/06/29 01:17:33 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2013/06/29 01:16:15 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Local\Microsoft Help
[2013/06/29 01:15:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/06/29 01:14:35 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/06/22 23:36:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/22 14:19:36 | 000,000,000 | —D | C] – C:\Users\Rose\AppData\Roaming\DownLite
[2013/06/21 17:33:11 | 000,000,000 | —D | C] – C:\Users\Rose\Desktop\–SCHOOL–
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/07/18 08:50:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/18 08:49:57 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Rose\Desktop\OTL.exe
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 07:29:30 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/18 06:58:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/18 03:37:41 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/17 21:13:34 | 000,000,000 | —- | M] () – C:\END
[2013/07/17 18:48:57 | 000,000,040 | —- | M] () – C:\user_defpage_list
[2013/07/13 03:15:24 | 000,002,064 | —- | M] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | M] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | M] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | M] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | M] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 02:23:50 | 000,383,440 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/07/12 02:09:29 | 000,640,658 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/12 02:09:29 | 000,118,878 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/12 00:27:43 | 000,003,584 | —- | M] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/09 01:44:55 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/07/09 00:14:07 | 000,006,702 | —- | M] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/07/08 19:02:06 | 000,713,217 | —- | M] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 02:03:58 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/06/30 02:03:58 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/06/30 01:30:15 | 000,770,344 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/06/30 01:30:15 | 000,369,584 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/06/30 01:30:15 | 000,175,176 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | M] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 00:12:46 | 000,000,512 | —- | M] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 16:27:59 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/06/23 14:27:36 | 000,001,957 | —- | M] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/19 00:44:23 | 000,000,680 | —- | M] () – C:\Users\Rose\AppData\Local\d3d9caps.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/07/13 03:15:24 | 000,002,064 | —- | C] () – C:\Users\Rose\Desktop\Baidu PC Faster.lnk
[2013/07/13 03:15:24 | 000,001,921 | —- | C] () – C:\Users\Rose\Desktop\Google Chrome.lnk
[2013/07/13 03:15:24 | 000,001,841 | —- | C] () – C:\Users\Rose\Desktop\avast! Internet Security.lnk
[2013/07/13 03:15:24 | 000,001,749 | —- | C] () – C:\Users\Rose\Desktop\Internet Explorer.lnk
[2013/07/13 03:15:24 | 000,000,448 | —- | C] () – C:\Users\Rose\Desktop\Downloads - Shortcut.lnk
[2013/07/12 19:29:32 | 000,000,040 | —- | C] () – C:\user_defpage_list
[2013/07/12 00:27:42 | 000,003,584 | —- | C] () – C:\Users\Rose\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/08 19:02:05 | 000,713,217 | —- | C] () – C:\Users\Rose\Desktop\Creek Nation School Clothes Assistance Application.pdf
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/30 01:30:15 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/30 01:29:59 | 000,175,176 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/06/30 01:29:57 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/06/30 00:12:46 | 000,000,512 | —- | C] () – C:\Windows\System32\F39D4DE6-98B8-4E05-91BD-549E8A8248BD
[2013/06/28 19:44:14 | 000,006,702 | —- | C] () – C:\Users\Rose\AppData\Roaming\wklnhst.dat
[2013/06/22 23:36:07 | 000,001,957 | —- | C] () – C:\Users\Rose\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/22 23:35:20 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/22 23:35:18 |