roman623
Topic Starter
Hello all,
Need help removing odoyomo on moms PC. I think it's the reason her PC is running so crappy with a lot of pop up ads and redirecting to other websites.
I read the sticky's and here are the results of OTL and Hijackthis
OTL logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32
Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.VisualStudio.OLE.Interop\7.1.40304.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.OLE.Interop.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\de6ee26de5e4f343509de7e92ab48ba6\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\eee76321ef8c5639946ed9ccc488d360\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\dcc781ebbddf98a9cf6dd4f3b17f1063\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9e24b9ffd816c0c90efc4d3fc9fd745f\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\MACTrackBarLib.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll ()
MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()
========== Services (SafeList) ==========
SRV - (BrowserDefendert) – C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (DefaultTabUpdate) – C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (DefaultTabSearch) – C:\Program Files\DefaultTab\DefaultTabSearch.exe ()
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130808.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss…57&tsp=4963
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0BE8708C-DF24-41CD-B0A7-FA5017ADE058}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}: "URL" = http://search.conduit.com/ResultsExt.aspx?…421133&UM=2
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTer…57&tsp=4963
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…d&qsrc=2869
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/09 19:00:38 | 000,000,000 | —D | M]
[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SelectionLinks) - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll (SelectionLinks)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: qflix.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect] http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect2] http in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:37 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/08/02 22:41:29 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/08/02 22:41:23 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
[2013/08/02 22:40:47 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:40:27 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/08/02 22:40:20 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\TopArcadeHits
[2013/08/02 22:39:34 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/08/02 22:39:33 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:04:55 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Conduit
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:03:05 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:56 | 000,000,000 | —D | C] – C:\Program Files\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:32:35 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Smartbar
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla
========== Files - Modified Within 30 Days ==========
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/09 19:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:01:02 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/09 19:00:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 07:01:38 | 000,000,272 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:04 | 300,800,352 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
========== Files Created - No Company Name ==========
[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/02 22:40:20 | 000,000,272 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/23 08:01:54 | 000,000,009 | —- | C] () – C:\END
[2013/07/18 10:10:04 | 300,800,352 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/11 10:12:34 | 000,185,682 | —- | C] () – C:\Users\Loretta\Documents\beadsample.pdf
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/30 18:15:40 | 001,167,152 | —- | C] () – C:\Windows\System32\dmwu.exe
[2013/06/30 18:15:40 | 000,027,136 | —- | C] () – C:\Windows\System32\ImHttpComm.dll
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/06/12 17:28:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\AVG2013
[2013/08/02 22:40:48 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:39:33 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/06/16 08:08:46 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\ControlCenter4
[2013/06/17 07:16:03 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\DefaultTab
[2013/08/02 22:41:54 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/06/21 08:36:07 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Nuance
[2013/06/22 11:10:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Simple Star
[2013/06/16 08:25:00 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Template
[2013/06/12 17:27:59 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\TuneUp Software
[2013/07/23 16:36:40 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Webfoot
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/08 10:24:19 | 000,158,654 | —- | M] () MD5=9050FDD6250BCC84B9477F30576235D0 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: IEXPLORE.EXE >
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_b3cf7f6d9f39f5d6\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_ba672fa865e3902d\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_b1da3f12e114fd0b\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_b35e817286096d08\iexplore.exe
[2013/06/12 18:02:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_b0ef5115c8405b93\iexplore.exe
< MD5 for: IEXPLORE.EXE.19544.DMP >
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.19544.dmp
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.19544.dmp
< MD5 for: IEXPLORE.EXE.45228.DMP >
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\ProgramData\Norton\LocalDumps\iexplore.exe.45228.dmp
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.45228.dmp
< MD5 for: IEXPLORE.EXE.6788.DMP >
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6788.dmp
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6788.dmp
< MD5 for: IEXPLORE.EXE.6880.DMP >
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6880.dmp
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6880.dmp
< MD5 for: IEXPLORE.EXE.MUI >
[2013/06/12 18:02:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/08/09 19:39:50 | 000,327,084 | —- | M] () MD5=AFCC2AB2DFCF2770A44F8B7A6C9CCDDE – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf
< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 19:00:27 | 3178,119,168 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2013/06/13 21:32:23 | 000,001,718 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 7CE6-B0F3
Directory of C:\
07/14/2009 12:53 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:53 AM All Users [C:\ProgramData]
07/14/2009 12:53 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:53 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:53 AM My Music [C:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Loretta
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Roaming]
06/12/2013 11:42 AM Cookies [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Cookies]
06/12/2013 11:42 AM Local Settings [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM My Documents [C:\Users\Loretta\Documents]
06/12/2013 11:42 AM NetHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/12/2013 11:42 AM PrintHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/12/2013 11:42 AM Recent [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Recent]
06/12/2013 11:42 AM SendTo [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\SendTo]
06/12/2013 11:42 AM Start Menu [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu]
06/12/2013 11:42 AM Templates [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\AppData\Local
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM History [C:\Users\Loretta\AppData\Local\Microsoft\Windows\History]
06/12/2013 11:42 AM Temporary Internet Files [C:\Users\Loretta\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\Documents
06/12/2013 11:42 AM My Music [C:\Users\Loretta\Music]
06/12/2013 11:42 AM My Pictures [C:\Users\Loretta\Pictures]
06/12/2013 11:42 AM My Videos [C:\Users\Loretta\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:53 AM My Music [C:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 454,924,165,120 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/07/01 08:44:27 | 000,000,221 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/06/30 18:14:16 | 014,391,552 | —- | M] (PortableApps.com) – C:\Users\Loretta\Desktop\Java_Portable_6_Update_21_online.paf.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-30 12:16:00
< End of report >
OTL Extras logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32
Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1894FFB7-A6D5-4AC2-AAA8-42D418D764A4}" = rport=139 | protocol=6 | dir=out | app=system |
"{2C657A39-E52A-4A14-BAC9-3EEAA45F8A12}" = lport=138 | protocol=17 | dir=in | app=system |
"{41DFD525-7C64-41D4-BFD9-3660D2C85860}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{425796E2-1AAE-41E5-AB9A-EA75645CB509}" = rport=138 | protocol=17 | dir=out | app=system |
"{513D9BEA-AD10-4BAF-BAB8-77C7A8D465B8}" = rport=137 | protocol=17 | dir=out | app=system |
"{62D281E4-D831-4BF1-BE92-A99A65282637}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6CD42493-1EF6-43D7-B50D-1DF355E30D08}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{7A2F1CAF-DBA6-4791-A199-A730F8BEA4B0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{871A53E1-4D92-492F-9457-12224D5DE252}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8CE39DB7-A350-4612-8488-DE8EDAAF5250}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8ED38666-4850-479B-AEEA-AADF035EF766}" = lport=10243 | protocol=6 | dir=in | app=system |
"{987C655D-D66E-4D98-A2F4-8F7500045958}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A4018DBA-E080-49F0-B486-2BE8F32A5D82}" = lport=139 | protocol=6 | dir=in | app=system |
"{B394B97B-5AA4-4F13-A4A4-D7518A316167}" = lport=445 | protocol=6 | dir=in | app=system |
"{B60B8E3A-0396-44CD-95BF-573D27CCAE79}" = lport=137 | protocol=17 | dir=in | app=system |
"{B96D9383-03DD-4544-8869-F7F3BCDD4C30}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BF297E4C-DE8D-4537-A231-24B294119128}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3AA2E97-B80A-444C-98C9-C125D00885AA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C527D3C6-0702-469F-9152-0D357128C0D3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D0B352E6-2364-4505-8764-7F45632289AC}" = rport=445 | protocol=6 | dir=out | app=system |
"{DDEAA578-8AF7-47FE-B52C-DFA267E26E21}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F66AFD4C-F9B5-4360-98A6-BEEEAD6F8872}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F666FD2-289E-416E-B139-BD171AD9FB5D}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{127C3BC8-ED71-4655-A7F6-283A02558615}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1317069A-5991-40A0-9389-94970D7B7235}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\faxapplications.exe |
"{15435D13-6475-4157-A66D-5B24267362E5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{1E6C5FF1-ABD6-486F-8D7E-F65927F7CE52}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{229C45D9-8172-4491-B95E-4D5C1CFB040A}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{22C377B8-13C0-4496-9CF1-972E209E45EF}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{23277C90-1C73-424E-8AA4-C5998DDFEC06}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{2ACDB7D9-6500-471D-BDAA-944148C674C6}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2CE71CFE-2854-4228-998B-B369DFF2849B}" = protocol=58 | dir=in | app=system |
"{3172D551-9D80-4182-AD6C-B8466E74033D}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{32135573-E09F-4B51-8D51-B62BEF688ABF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{346AA804-C9D6-4FCB-AB80-F3823B6C6C85}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{39194AE6-9A98-4859-99AB-AA04D4197BCB}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\devicesetup.exe |
"{3A5EA713-6DC1-4E74-8BB9-9519FE74E058}" = protocol=6 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{3DAEABA0-FCEB-4DC3-8434-1E55D8DA00A2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{4C2EB6A6-FBCA-449F-A78A-5D9C4AEC46AF}" = protocol=6 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{4FEA18AA-8354-4C5E-A971-2CCB423BE4C0}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{53A4A855-15C6-43A6-AE64-DBF37665085B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{55B1EA45-FEF7-4531-8750-37B9C472F7D9}" = protocol=6 | dir=out | app=system |
"{61396B30-F3D9-4EEB-AFF0-C552591370B4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{65F25203-1058-4299-9E34-E06178172D05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6B0D6EB4-1019-4A79-A115-BC3ADD396348}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{6B928B52-7491-41D1-B94F-6F3CE3BD1982}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7104BAD8-D279-428F-9C96-922BC997D180}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{7B8684A6-C679-4F5F-9C17-6E76A0760A88}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{854BB967-1694-4E92-A442-0638F60D1CC0}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicatorcom.exe |
"{86CCB421-4F7C-4CB9-B866-A3378D764442}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8E9B26A3-1AF1-4CCA-B0E6-396C4B4BAE60}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97CF8045-10F8-4AA5-95E8-B0D6ED81CB4C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{99E5F008-ED5C-4DF0-B056-808CEB68FC4B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CAAB97E-455F-46C9-93C0-DA0F677A0893}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{A0CB0F3C-64B3-46BD-B160-0AEF85365A98}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A4895B36-8D1B-4888-BB89-1EF7128EE014}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{ABC86008-28FD-499D-90CC-A4A07E6C8968}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{B09A9610-A1CD-4003-A84F-9E256876DD5C}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{BC580EF0-D16E-4978-8008-2FE2A7EF6806}" = protocol=17 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{BEDDDBC8-ADEA-430D-864A-44F5FBF2ABA5}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C0510044-2C49-47CD-B923-A179287B8BAA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C520FFC1-6EAB-4761-98AE-99EC13E4F427}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{C71223B2-937D-4873-B344-6AC3372FE2A4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C9E95C4B-4615-4294-B073-821206175F37}" = protocol=17 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"{CC758F91-2595-4C26-BDD0-67AE2BD6993C}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{CC82C465-8625-4310-A2B4-61EFCBDF2258}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{CD573553-FE1E-4D8F-99CC-4A91542141D7}" = protocol=17 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{CE2EB273-A950-48C3-9898-5652649F19F9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2793B46-EC1E-4025-ABD8-11ADD49E88B8}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\sendafax.exe |
"{DA89B402-CB9F-4092-9C02-0EFB48DD23D3}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\digitalwizards.exe |
"{DEE873D0-026D-4C96-87D6-5A6B364A4715}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicator.exe |
"{F860F1D1-7368-49B8-88F5-428E97406277}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{FB880303-7D70-467A-9547-888873C45F66}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FFF37DEE-814D-47C1-8548-EE29CDEE74A1}" = protocol=6 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"TCP Query User{5C226E5B-EA6B-4D77-AE93-721124A412C7}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"TCP Query User{AF439155-057D-4B03-8B48-FDFE42ACB722}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{57819D21-91B0-431C-B236-CCD129B2A175}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{9386D33D-7DC6-4D39-82BB-AA20C7529380}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01001202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard 2002
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{2B818257-E6C7-4841-8C29-C5C9A982BCE5}" = RICOH Media Driver ver.2.07.01.00
"{2FA81482-5570-4CF0-9A10-D61D2F164916}" = HP Officejet 6600 Help
"{329D7F73-3786-452C-88FA-A333DBFE160B}" = HP Officejet 6600 Product Improvement Study
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite MFC-7860DW
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{4333CA76-5C11-4D7C-AA07-C429D1C6B142}" = Snap.Do
"{43CD257A-4F32-4BDE-9B3D-14E6E10C8307}" = Roxio Creator 2010
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4D0AAB66-E604-4E82-A5AF-01AB97CB506D}" = Roxio Creator 2010 Content
"{539067D5-E3E8-4592-9169-358EFC40982B}" = The Ultimate 25 Game Pack
"{5491453D-8C3E-4785-AC5C-E9A4DABF378A}" = Roxio Venue
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5FF27D65-35E5-4855-B7ED-59BCFBC85776}" = AVG 2013
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{65A79175-3C4C-41F4-92AF-BA1DDDBA0626}" = Roxio Burn Manager CDB
"{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{733CDF24-0A93-426E-AA89-DF281EB54793}" = Roxio CinePlayer
"{74DC8A26-4E05-40B6-AD11-C9428A1AE150}" = Roxio Creator 2010
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}" = Roxio Video Capture USB
"{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}" = Roxio Creator 2010
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{906C01EE-B242-4197-AE85-6C506E1B869B}" = Roxio Burn Manager
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Roxio CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C4C4BECF-764C-406D-A1AD-F73611B0F668}" = HP Officejet 6600 Basic Device Software
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CBBB226E-2289-4D29-8E5C-1331E7D71ED9}" = AVG 2013
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AVG" = AVG 2013
"DefaultTab" = DefaultTab
"HP Photo Creations" = HP Photo Creations
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NIS" = Norton Internet Security
"Roxio PhotoShow" = Roxio PhotoShow
"Shockwave" = Shockwave
"sl-apl" = SelectionLinks
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{C1C3E833-420E-4D78-9BA7-86AEBB272384}" = TopArcadeHits
"Akamai" = Akamai NetSession Interface
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 8/7/2013 4:42:21 PM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 8/8/2013 12:30:14 AM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 8/8/2013 10:24:51 AM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/8/2013 2:04:39 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 462c Start
Time: 01ce9460acbd2233 Termination Time: 60 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 6:09:20 AM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 5ee4 Start
Time: 01ce94e8546f499c Termination Time: 15 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 6:27:00 PM | Computer Name = Loretta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Exception code: 0xc0000005 Fault offset: 0x00002c60 Faulting
process id: 0x204 Faulting application start time: 0x01ce954f858cb65b Faulting application
path: C:\Program Files\DefaultTab\DefaultTabSearch.exe Faulting module path: C:\Program
Files\DefaultTab\DefaultTabSearch.exe Report Id: ce937380-0142-11e3-bc69-0021708f4a89
Error - 8/9/2013 6:27:50 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/9/2013 7:01:19 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/9/2013 7:02:28 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1534 Start
Time: 01ce95546769a417 Termination Time: 8 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 7:46:28 PM | Computer Name = Loretta-PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2013/08/09 19:46:28.849]: [00004120]: SendSKeySettingToDevice::
Snmp Load Error[0] To[192.168.0.141]
[ Media Center Events ]
Error - 7/7/2013 6:25:29 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:29 PM - Error connecting to the internet. 6:25:29 PM - Unable
to contact server..
Error - 7/7/2013 6:25:44 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:35 PM - Error connecting to the internet. 6:25:35 PM - Unable
to contact server..
Error - 7/7/2013 7:25:48 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:48 PM - Error connecting to the internet. 7:25:48 PM - Unable
to contact server..
Error - 7/7/2013 7:25:54 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:53 PM - Error connecting to the internet. 7:25:53 PM - Unable
to contact server..
Error - 7/7/2013 8:30:07 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:07 PM - Error connecting to the internet. 8:30:07 PM - Unable
to contact server..
Error - 7/7/2013 8:30:14 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:12 PM - Error connecting to the internet. 8:30:12 PM - Unable
to contact server..
Error - 7/8/2013 10:18:38 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:38 AM - Error connecting to the internet. 10:18:38 AM - Unable
to contact server..
Error - 7/8/2013 10:18:48 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:43 AM - Error connecting to the internet. 10:18:43 AM - Unable
to contact server..
Error - 7/29/2013 10:18:54 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:54 AM - Error connecting to the internet. 10:18:54 AM - Unable
to contact server..
Error - 7/29/2013 7:14:32 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:19:17 AM - Error connecting to the internet. 10:19:17 AM - Unable
to contact server..
[ System Events ]
Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Roxio
Hard Drive Watcher 12 service to connect.
Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7023
Description = The Power service terminated with the following error: %%4203
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:11:15 PM, on 8/9/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Nuance\PaperPort\pptd40nt.exe
C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files\ControlCenter4\BrCtrlCntr.exe
C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe
C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\ControlCenter4\BrCcUxSys.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Loretta\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelloWorldBHO - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll
O2 - BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O3 - Toolbar: Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
O4 - HKLM\..\Run: [CPMonitor] "C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [HP Officejet 6600 (NET)] "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN32S6RHF705RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Monitor Ink Alerts - HP Officejet 6600 (Network).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.cinemanow.com
O15 - Trusted Zone: http://*.qflix.com
O15 - Trusted Zone: http://*.roxio.com
O15 - Trusted Zone: http://redirect.sonic.com
O15 - Trusted Zone: http://redirect2.sonic.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: RoxMediaDB12 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\STacSV.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 10595 bytes
Need help removing odoyomo on moms PC. I think it's the reason her PC is running so crappy with a lot of pop up ads and redirecting to other websites.
I read the sticky's and here are the results of OTL and Hijackthis
OTL logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32
Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.VisualStudio.OLE.Interop\7.1.40304.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.OLE.Interop.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\de6ee26de5e4f343509de7e92ab48ba6\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\eee76321ef8c5639946ed9ccc488d360\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\dcc781ebbddf98a9cf6dd4f3b17f1063\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9e24b9ffd816c0c90efc4d3fc9fd745f\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\MACTrackBarLib.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll ()
MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()
========== Services (SafeList) ==========
SRV - (BrowserDefendert) – C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (DefaultTabUpdate) – C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (DefaultTabSearch) – C:\Program Files\DefaultTab\DefaultTabSearch.exe ()
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130808.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss…57&tsp=4963
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0BE8708C-DF24-41CD-B0A7-FA5017ADE058}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}: "URL" = http://search.conduit.com/ResultsExt.aspx?…421133&UM=2
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTer…57&tsp=4963
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…d&qsrc=2869
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/09 19:00:38 | 000,000,000 | —D | M]
[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SelectionLinks) - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll (SelectionLinks)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: qflix.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect] http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect2] http in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:37 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/08/02 22:41:29 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/08/02 22:41:23 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
[2013/08/02 22:40:47 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:40:27 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/08/02 22:40:20 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\TopArcadeHits
[2013/08/02 22:39:34 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/08/02 22:39:33 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:04:55 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Conduit
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:03:05 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:56 | 000,000,000 | —D | C] – C:\Program Files\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:32:35 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Smartbar
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla
========== Files - Modified Within 30 Days ==========
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/09 19:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:01:02 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/09 19:00:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 07:01:38 | 000,000,272 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:04 | 300,800,352 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
========== Files Created - No Company Name ==========
[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/02 22:40:20 | 000,000,272 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/23 08:01:54 | 000,000,009 | —- | C] () – C:\END
[2013/07/18 10:10:04 | 300,800,352 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/11 10:12:34 | 000,185,682 | —- | C] () – C:\Users\Loretta\Documents\beadsample.pdf
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/30 18:15:40 | 001,167,152 | —- | C] () – C:\Windows\System32\dmwu.exe
[2013/06/30 18:15:40 | 000,027,136 | —- | C] () – C:\Windows\System32\ImHttpComm.dll
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/06/12 17:28:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\AVG2013
[2013/08/02 22:40:48 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:39:33 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/06/16 08:08:46 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\ControlCenter4
[2013/06/17 07:16:03 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\DefaultTab
[2013/08/02 22:41:54 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/06/21 08:36:07 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Nuance
[2013/06/22 11:10:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Simple Star
[2013/06/16 08:25:00 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Template
[2013/06/12 17:27:59 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\TuneUp Software
[2013/07/23 16:36:40 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Webfoot
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/08 10:24:19 | 000,158,654 | —- | M] () MD5=9050FDD6250BCC84B9477F30576235D0 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: IEXPLORE.EXE >
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_b3cf7f6d9f39f5d6\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_ba672fa865e3902d\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_b1da3f12e114fd0b\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_b35e817286096d08\iexplore.exe
[2013/06/12 18:02:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_b0ef5115c8405b93\iexplore.exe
< MD5 for: IEXPLORE.EXE.19544.DMP >
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.19544.dmp
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.19544.dmp
< MD5 for: IEXPLORE.EXE.45228.DMP >
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\ProgramData\Norton\LocalDumps\iexplore.exe.45228.dmp
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.45228.dmp
< MD5 for: IEXPLORE.EXE.6788.DMP >
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6788.dmp
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6788.dmp
< MD5 for: IEXPLORE.EXE.6880.DMP >
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6880.dmp
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6880.dmp
< MD5 for: IEXPLORE.EXE.MUI >
[2013/06/12 18:02:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/08/09 19:39:50 | 000,327,084 | —- | M] () MD5=AFCC2AB2DFCF2770A44F8B7A6C9CCDDE – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf
< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 19:00:27 | 3178,119,168 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2013/06/13 21:32:23 | 000,001,718 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 7CE6-B0F3
Directory of C:\
07/14/2009 12:53 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:53 AM All Users [C:\ProgramData]
07/14/2009 12:53 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:53 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:53 AM My Music [C:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Loretta
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Roaming]
06/12/2013 11:42 AM Cookies [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Cookies]
06/12/2013 11:42 AM Local Settings [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM My Documents [C:\Users\Loretta\Documents]
06/12/2013 11:42 AM NetHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/12/2013 11:42 AM PrintHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/12/2013 11:42 AM Recent [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Recent]
06/12/2013 11:42 AM SendTo [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\SendTo]
06/12/2013 11:42 AM Start Menu [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu]
06/12/2013 11:42 AM Templates [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\AppData\Local
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM History [C:\Users\Loretta\AppData\Local\Microsoft\Windows\History]
06/12/2013 11:42 AM Temporary Internet Files [C:\Users\Loretta\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\Documents
06/12/2013 11:42 AM My Music [C:\Users\Loretta\Music]
06/12/2013 11:42 AM My Pictures [C:\Users\Loretta\Pictures]
06/12/2013 11:42 AM My Videos [C:\Users\Loretta\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:53 AM My Music [C:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 454,924,165,120 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/07/01 08:44:27 | 000,000,221 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/06/30 18:14:16 | 014,391,552 | —- | M] (PortableApps.com) – C:\Users\Loretta\Desktop\Java_Portable_6_Update_21_online.paf.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-30 12:16:00
< End of report >
OTL Extras logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32
Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1894FFB7-A6D5-4AC2-AAA8-42D418D764A4}" = rport=139 | protocol=6 | dir=out | app=system |
"{2C657A39-E52A-4A14-BAC9-3EEAA45F8A12}" = lport=138 | protocol=17 | dir=in | app=system |
"{41DFD525-7C64-41D4-BFD9-3660D2C85860}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{425796E2-1AAE-41E5-AB9A-EA75645CB509}" = rport=138 | protocol=17 | dir=out | app=system |
"{513D9BEA-AD10-4BAF-BAB8-77C7A8D465B8}" = rport=137 | protocol=17 | dir=out | app=system |
"{62D281E4-D831-4BF1-BE92-A99A65282637}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6CD42493-1EF6-43D7-B50D-1DF355E30D08}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{7A2F1CAF-DBA6-4791-A199-A730F8BEA4B0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{871A53E1-4D92-492F-9457-12224D5DE252}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8CE39DB7-A350-4612-8488-DE8EDAAF5250}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8ED38666-4850-479B-AEEA-AADF035EF766}" = lport=10243 | protocol=6 | dir=in | app=system |
"{987C655D-D66E-4D98-A2F4-8F7500045958}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A4018DBA-E080-49F0-B486-2BE8F32A5D82}" = lport=139 | protocol=6 | dir=in | app=system |
"{B394B97B-5AA4-4F13-A4A4-D7518A316167}" = lport=445 | protocol=6 | dir=in | app=system |
"{B60B8E3A-0396-44CD-95BF-573D27CCAE79}" = lport=137 | protocol=17 | dir=in | app=system |
"{B96D9383-03DD-4544-8869-F7F3BCDD4C30}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BF297E4C-DE8D-4537-A231-24B294119128}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3AA2E97-B80A-444C-98C9-C125D00885AA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C527D3C6-0702-469F-9152-0D357128C0D3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D0B352E6-2364-4505-8764-7F45632289AC}" = rport=445 | protocol=6 | dir=out | app=system |
"{DDEAA578-8AF7-47FE-B52C-DFA267E26E21}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F66AFD4C-F9B5-4360-98A6-BEEEAD6F8872}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F666FD2-289E-416E-B139-BD171AD9FB5D}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{127C3BC8-ED71-4655-A7F6-283A02558615}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1317069A-5991-40A0-9389-94970D7B7235}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\faxapplications.exe |
"{15435D13-6475-4157-A66D-5B24267362E5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{1E6C5FF1-ABD6-486F-8D7E-F65927F7CE52}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{229C45D9-8172-4491-B95E-4D5C1CFB040A}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{22C377B8-13C0-4496-9CF1-972E209E45EF}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{23277C90-1C73-424E-8AA4-C5998DDFEC06}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{2ACDB7D9-6500-471D-BDAA-944148C674C6}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2CE71CFE-2854-4228-998B-B369DFF2849B}" = protocol=58 | dir=in | app=system |
"{3172D551-9D80-4182-AD6C-B8466E74033D}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{32135573-E09F-4B51-8D51-B62BEF688ABF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{346AA804-C9D6-4FCB-AB80-F3823B6C6C85}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{39194AE6-9A98-4859-99AB-AA04D4197BCB}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\devicesetup.exe |
"{3A5EA713-6DC1-4E74-8BB9-9519FE74E058}" = protocol=6 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{3DAEABA0-FCEB-4DC3-8434-1E55D8DA00A2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{4C2EB6A6-FBCA-449F-A78A-5D9C4AEC46AF}" = protocol=6 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{4FEA18AA-8354-4C5E-A971-2CCB423BE4C0}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{53A4A855-15C6-43A6-AE64-DBF37665085B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{55B1EA45-FEF7-4531-8750-37B9C472F7D9}" = protocol=6 | dir=out | app=system |
"{61396B30-F3D9-4EEB-AFF0-C552591370B4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{65F25203-1058-4299-9E34-E06178172D05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6B0D6EB4-1019-4A79-A115-BC3ADD396348}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{6B928B52-7491-41D1-B94F-6F3CE3BD1982}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7104BAD8-D279-428F-9C96-922BC997D180}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{7B8684A6-C679-4F5F-9C17-6E76A0760A88}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{854BB967-1694-4E92-A442-0638F60D1CC0}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicatorcom.exe |
"{86CCB421-4F7C-4CB9-B866-A3378D764442}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8E9B26A3-1AF1-4CCA-B0E6-396C4B4BAE60}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97CF8045-10F8-4AA5-95E8-B0D6ED81CB4C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{99E5F008-ED5C-4DF0-B056-808CEB68FC4B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CAAB97E-455F-46C9-93C0-DA0F677A0893}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{A0CB0F3C-64B3-46BD-B160-0AEF85365A98}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A4895B36-8D1B-4888-BB89-1EF7128EE014}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{ABC86008-28FD-499D-90CC-A4A07E6C8968}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{B09A9610-A1CD-4003-A84F-9E256876DD5C}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{BC580EF0-D16E-4978-8008-2FE2A7EF6806}" = protocol=17 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{BEDDDBC8-ADEA-430D-864A-44F5FBF2ABA5}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C0510044-2C49-47CD-B923-A179287B8BAA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C520FFC1-6EAB-4761-98AE-99EC13E4F427}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{C71223B2-937D-4873-B344-6AC3372FE2A4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C9E95C4B-4615-4294-B073-821206175F37}" = protocol=17 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"{CC758F91-2595-4C26-BDD0-67AE2BD6993C}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{CC82C465-8625-4310-A2B4-61EFCBDF2258}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{CD573553-FE1E-4D8F-99CC-4A91542141D7}" = protocol=17 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{CE2EB273-A950-48C3-9898-5652649F19F9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2793B46-EC1E-4025-ABD8-11ADD49E88B8}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\sendafax.exe |
"{DA89B402-CB9F-4092-9C02-0EFB48DD23D3}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\digitalwizards.exe |
"{DEE873D0-026D-4C96-87D6-5A6B364A4715}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicator.exe |
"{F860F1D1-7368-49B8-88F5-428E97406277}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{FB880303-7D70-467A-9547-888873C45F66}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FFF37DEE-814D-47C1-8548-EE29CDEE74A1}" = protocol=6 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"TCP Query User{5C226E5B-EA6B-4D77-AE93-721124A412C7}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"TCP Query User{AF439155-057D-4B03-8B48-FDFE42ACB722}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{57819D21-91B0-431C-B236-CCD129B2A175}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{9386D33D-7DC6-4D39-82BB-AA20C7529380}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01001202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard 2002
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{2B818257-E6C7-4841-8C29-C5C9A982BCE5}" = RICOH Media Driver ver.2.07.01.00
"{2FA81482-5570-4CF0-9A10-D61D2F164916}" = HP Officejet 6600 Help
"{329D7F73-3786-452C-88FA-A333DBFE160B}" = HP Officejet 6600 Product Improvement Study
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite MFC-7860DW
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{4333CA76-5C11-4D7C-AA07-C429D1C6B142}" = Snap.Do
"{43CD257A-4F32-4BDE-9B3D-14E6E10C8307}" = Roxio Creator 2010
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4D0AAB66-E604-4E82-A5AF-01AB97CB506D}" = Roxio Creator 2010 Content
"{539067D5-E3E8-4592-9169-358EFC40982B}" = The Ultimate 25 Game Pack
"{5491453D-8C3E-4785-AC5C-E9A4DABF378A}" = Roxio Venue
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5FF27D65-35E5-4855-B7ED-59BCFBC85776}" = AVG 2013
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{65A79175-3C4C-41F4-92AF-BA1DDDBA0626}" = Roxio Burn Manager CDB
"{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{733CDF24-0A93-426E-AA89-DF281EB54793}" = Roxio CinePlayer
"{74DC8A26-4E05-40B6-AD11-C9428A1AE150}" = Roxio Creator 2010
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}" = Roxio Video Capture USB
"{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}" = Roxio Creator 2010
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{906C01EE-B242-4197-AE85-6C506E1B869B}" = Roxio Burn Manager
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Roxio CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C4C4BECF-764C-406D-A1AD-F73611B0F668}" = HP Officejet 6600 Basic Device Software
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CBBB226E-2289-4D29-8E5C-1331E7D71ED9}" = AVG 2013
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AVG" = AVG 2013
"DefaultTab" = DefaultTab
"HP Photo Creations" = HP Photo Creations
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NIS" = Norton Internet Security
"Roxio PhotoShow" = Roxio PhotoShow
"Shockwave" = Shockwave
"sl-apl" = SelectionLinks
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{C1C3E833-420E-4D78-9BA7-86AEBB272384}" = TopArcadeHits
"Akamai" = Akamai NetSession Interface
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 8/7/2013 4:42:21 PM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 8/8/2013 12:30:14 AM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 8/8/2013 10:24:51 AM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/8/2013 2:04:39 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 462c Start
Time: 01ce9460acbd2233 Termination Time: 60 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 6:09:20 AM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 5ee4 Start
Time: 01ce94e8546f499c Termination Time: 15 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 6:27:00 PM | Computer Name = Loretta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Exception code: 0xc0000005 Fault offset: 0x00002c60 Faulting
process id: 0x204 Faulting application start time: 0x01ce954f858cb65b Faulting application
path: C:\Program Files\DefaultTab\DefaultTabSearch.exe Faulting module path: C:\Program
Files\DefaultTab\DefaultTabSearch.exe Report Id: ce937380-0142-11e3-bc69-0021708f4a89
Error - 8/9/2013 6:27:50 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/9/2013 7:01:19 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =
Error - 8/9/2013 7:02:28 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1534 Start
Time: 01ce95546769a417 Termination Time: 8 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:
Error - 8/9/2013 7:46:28 PM | Computer Name = Loretta-PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2013/08/09 19:46:28.849]: [00004120]: SendSKeySettingToDevice::
Snmp Load Error[0] To[192.168.0.141]
[ Media Center Events ]
Error - 7/7/2013 6:25:29 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:29 PM - Error connecting to the internet. 6:25:29 PM - Unable
to contact server..
Error - 7/7/2013 6:25:44 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:35 PM - Error connecting to the internet. 6:25:35 PM - Unable
to contact server..
Error - 7/7/2013 7:25:48 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:48 PM - Error connecting to the internet. 7:25:48 PM - Unable
to contact server..
Error - 7/7/2013 7:25:54 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:53 PM - Error connecting to the internet. 7:25:53 PM - Unable
to contact server..
Error - 7/7/2013 8:30:07 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:07 PM - Error connecting to the internet. 8:30:07 PM - Unable
to contact server..
Error - 7/7/2013 8:30:14 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:12 PM - Error connecting to the internet. 8:30:12 PM - Unable
to contact server..
Error - 7/8/2013 10:18:38 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:38 AM - Error connecting to the internet. 10:18:38 AM - Unable
to contact server..
Error - 7/8/2013 10:18:48 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:43 AM - Error connecting to the internet. 10:18:43 AM - Unable
to contact server..
Error - 7/29/2013 10:18:54 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:54 AM - Error connecting to the internet. 10:18:54 AM - Unable
to contact server..
Error - 7/29/2013 7:14:32 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:19:17 AM - Error connecting to the internet. 10:19:17 AM - Unable
to contact server..
[ System Events ]
Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Roxio
Hard Drive Watcher 12 service to connect.
Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7023
Description = The Power service terminated with the following error: %%4203
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:11:15 PM, on 8/9/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Nuance\PaperPort\pptd40nt.exe
C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files\ControlCenter4\BrCtrlCntr.exe
C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe
C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\ControlCenter4\BrCcUxSys.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Loretta\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelloWorldBHO - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll
O2 - BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O3 - Toolbar: Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
O4 - HKLM\..\Run: [CPMonitor] "C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [HP Officejet 6600 (NET)] "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN32S6RHF705RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Monitor Ink Alerts - HP Officejet 6600 (Network).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.cinemanow.com
O15 - Trusted Zone: http://*.qflix.com
O15 - Trusted Zone: http://*.roxio.com
O15 - Trusted Zone: http://redirect.sonic.com
O15 - Trusted Zone: http://redirect2.sonic.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: RoxMediaDB12 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\STacSV.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 10595 bytes