SweetTech,
Thank you for your prompt reply.
The materials that you requested are as follows:
OTL Logfile:
OTL logfile created on: 2010/05/24 11:30:49 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Ryan N Kelley\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000411 | Country: 米国 | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 48.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.95 Gb Total Space | 86.78 Gb Free Space | 39.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Q: | 9.77 Gb Total Space | 5.05 Gb Free Space | 51.66% Space Free | Partition Type: NTFS
Computer Name: RYANNKELLEY
Current User Name: Ryan N Kelley
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Users\Ryan N Kelley\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Ryan N Kelley\Downloads\4dhjsehq.exe ()
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lenovo\Access Connections\AcSvc.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe (Lenovo)
PRC - C:\Program Files\Anki\Anki.exe (Damien Elmes)
PRC - C:\Windows\System32\TpShocks.exe (Lenovo.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Windows\System32\ibmpmsvc.exe (Lenovo.)
PRC - C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\cammute.exe (Lenovo Group Limited)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - c:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
PRC - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Program Files\Rainlendar2\Rainlendar2.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Anki\mecab\bin\mecab.exe ()
PRC - C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Windows\System32\atibtmon.exe (Advanced Micro Devices, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Users\Ryan N Kelley\Documents\KIC Ver. 2.2.2\KanjiInContext.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Anki\kakasi\bin\kakasi.exe ()
PRC - C:\Program Files\Wakan\wakan.exe ()
========== Modules (SafeList) ========== MOD - C:\Users\Ryan N Kelley\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Power Manager DBC Service) -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE (Lenovo)
SRV - (AcSvc) -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe (Lenovo)
SRV - (AcPrfMgrSvc) -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (IBMPMSVC) -- C:\Windows\System32\ibmpmsvc.exe (Lenovo.)
SRV - (LENOVO.MICMUTE) -- C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (TPHKSVC) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.CAMMUTE) -- C:\Program Files\Lenovo\HOTKEY\cammute.exe (Lenovo Group Limited)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TPHDEXLGSVC) -- C:\Windows\System32\TPHDEXLG.exe (Lenovo.)
SRV - (btwdins) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (SUService) -- c:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (TVT Backup Service) -- C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe (Lenovo Group Limited)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
========== Driver Services (SafeList) ========== DRV - (PCDSRVC{3037D694-FD904ACA-06020000}_0) -- c:\Program Files\PC-Doctor\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (AvgRkx86) -- C:\Windows\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) -- C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TPPWRIF) -- C:\Windows\System32\drivers\TPPWR32V.SYS (Lenovo Group Limited)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (psadd) -- C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (IBMPMDRV) -- C:\Windows\System32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (SCDEmu) -- C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (rtl8192se) -- C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (usbsmi) -- C:\Windows\System32\drivers\SMIksdrv.sys (SMI)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (Shockprf) -- C:\Windows\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\Windows\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (RTL8167) -- C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (btwaudio) -- C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (RSUSBSTOR) -- C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (btwavdt) -- C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwrchid) -- C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) -- C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (SrvHsfV92) -- C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfWinac) -- C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfHDA) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (netw5v32) Intel® -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (usbfilter) -- C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices)
DRV - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (btwl2cap) -- C:\Windows\System32\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV - (lenovo.smi) -- C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo.msn.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/jp/ja [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/jp/ja [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.msn.comIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/19 12:54:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/19 12:54:01 | 000,000,000 | ---D | M]
[2010/05/19 12:54:20 | 000,000,000 | ---D | M] -- C:\Users\Ryan N Kelley\AppData\Roaming\mozilla\Extensions
[2010/05/19 12:54:20 | 000,000,000 | ---D | M] -- C:\Users\Ryan N Kelley\AppData\Roaming\mozilla\Firefox\Profiles\6f2ywr9q.default\extensions
[2010/05/19 12:54:02 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/02 02:17:08 | 000,001,842 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-jp.xml
[2010/04/02 02:17:08 | 000,002,630 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google-jp.xml
[2010/04/02 02:17:08 | 000,001,269 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\oshiete-goo.xml
[2010/04/02 02:17:08 | 000,000,814 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\rakuten.xml
[2010/04/02 02:17:08 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-ja.xml
[2010/04/02 02:17:08 | 000,000,889 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-jp-auctions.xml
[2010/04/02 02:17:08 | 000,000,696 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-jp.xml
O1 HOSTS File: ([2009/06/11 06:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [Launch Backup Service Once] C:\Program Files\Lenovo\Rescue and Recovery\rrstrigger.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TpShocks] C:\Windows\System32\TpShocks.exe (Lenovo.)
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: イメージを Bluetooth デバイスに送信(&B)... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: ページを Bluetooth デバイスに送信(&B)... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: このコンテンツを引用 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Live Writer でこのコンテンツに関する記事を書く(&B) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 06:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/06/11 01:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{1640d487-2094-11df-9f7d-00269ed98ce7}\Shell - "" = AutoRun
O33 - MountPoints2\{1640d487-2094-11df-9f7d-00269ed98ce7}\Shell\AutoRun\command - "" = E:\launcher.exe -- File not found
O33 - MountPoints2\{b2af0d46-050b-11df-b388-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b2af0d46-050b-11df-b388-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/11 06:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/14 11:37:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ========== [2010/05/23 23:36:57 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Roaming\Malwarebytes
[2010/05/23 23:35:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/23 23:35:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/05/23 23:35:43 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/05/23 23:35:43 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/20 13:32:11 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/05/19 17:29:25 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows
[2010/05/19 17:18:55 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Roaming\Update
[2010/05/19 12:54:15 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Roaming\Mozilla
[2010/05/19 12:54:15 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Local\Mozilla
[2010/05/19 12:53:59 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/05/19 08:38:26 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010/05/19 02:48:56 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/05/18 15:34:23 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\Tracing
[2010/05/18 14:13:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2010/05/15 20:24:18 | 000,000,000 | ---D | C] -- C:\Games
[2010/05/04 00:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/04 00:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/02 13:11:20 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2010/05/02 13:11:19 | 000,052,872 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/02 13:11:14 | 000,242,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/05/02 13:11:05 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2010/05/02 13:10:55 | 000,029,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/02 13:10:55 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg
[2010/05/02 13:10:38 | 000,000,000 | ---D | C] -- C:\ProgramData\avg9
[2010/04/28 14:40:15 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/04/28 14:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\River Software
[2010/04/26 21:32:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Roaming\cYo
[2010/04/26 21:32:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\AppData\Local\cYo
[2010/04/26 21:30:43 | 000,000,000 | ---D | C] -- C:\Program Files\ComicRack
[2010/04/26 10:37:29 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\Documents\Theories of War and Peace copy
[2010/04/25 09:51:37 | 000,000,000 | ---D | C] -- C:\Users\Ryan N Kelley\Documents\GP Tabs
[2010/04/25 09:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Guitar Pro 5
[2010/04/25 08:51:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
========== Files - Modified Within 30 Days ========== [2010/05/24 11:33:57 | 002,359,296 | -HS- | M] () -- C:\Users\Ryan N Kelley\ntuser.dat
[2010/05/24 10:49:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/05/24 09:43:40 | 060,315,615 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010/05/24 09:02:36 | 000,003,249 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Kaspersky Report.html
[2010/05/24 06:27:52 | 000,019,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/24 06:27:52 | 000,019,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/24 06:18:50 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/05/24 06:18:16 | 1408,045,056 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/24 06:16:38 | 001,801,192 | -H-- | M] () -- C:\Users\Ryan N Kelley\AppData\Local\IconCache.db
[2010/05/20 21:19:44 | 001,572,085 | ---- | M] () -- C:\Users\Ryan N Kelley\Desktop\1274357740129.jpg
[2010/05/20 21:09:28 | 000,993,399 | ---- | M] () -- C:\Users\Ryan N Kelley\Desktop\020.JPG
[2010/05/20 13:32:22 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2010/05/20 13:32:22 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2010/05/20 13:31:48 | 180,732,072 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/05/19 15:10:10 | 172,785,396 | ---- | M] () -- C:\Users\Ryan N Kelley\Desktop\t_reddeadr_vr_mvf4_gt_hd.wmv
[2010/05/19 14:28:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/05/19 14:28:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/05/19 14:25:51 | 000,008,487 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\VirtuaNES.ini
[2010/05/19 11:42:22 | 000,524,288 | -HS- | M] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TMContainer00000000000000000002.regtrans-ms
[2010/05/19 11:42:22 | 000,524,288 | -HS- | M] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TMContainer00000000000000000001.regtrans-ms
[2010/05/19 11:42:22 | 000,065,536 | -HS- | M] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TM.blf
[2010/05/14 06:18:37 | 001,199,652 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/05/14 06:18:37 | 000,609,756 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/05/14 06:18:37 | 000,386,112 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2010/05/14 06:18:37 | 000,103,702 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2010/05/14 06:18:37 | 000,103,702 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/13 14:01:02 | 000,011,621 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Square Numbers.docx
[2010/05/13 13:04:11 | 000,011,536 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\square explanation.docx
[2010/05/13 12:43:01 | 000,013,212 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\glint.ini
[2010/05/13 12:40:36 | 000,012,596 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Lawless Questions.docx
[2010/05/13 00:58:09 | 000,155,221 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Square-enix Financial Analysis.pptx
[2010/05/11 17:23:23 | 000,010,646 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\MBA Management.docx
[2010/05/08 10:11:33 | 000,012,160 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Outline.docx
[2010/05/07 14:27:42 | 000,014,894 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\I promised myself that I would write every day.docx
[2010/05/07 13:52:29 | 000,014,103 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\SquareEnix Report.docx
[2010/05/07 13:22:30 | 000,015,236 | ---- | M] () -- C:\Users\Ryan N Kelley\Documents\Ryan Nathaniel Kelley Resume 10.5.6.docx
[2010/05/02 13:11:20 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2010/05/02 13:11:19 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/02 13:11:14 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/05/02 13:11:05 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2010/05/02 13:10:55 | 000,113,461 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/02 13:10:55 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/26 06:01:01 | 000,434,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/04/25 09:48:23 | 000,114,616 | ---- | M] () -- C:\Users\Ryan N Kelley\AppData\Local\GDIPFONTCACHEV1.DAT
========== Files Created - No Company Name ========== [2010/05/24 09:02:36 | 000,003,249 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Kaspersky Report.html
[2010/05/20 21:19:44 | 001,572,085 | ---- | C] () -- C:\Users\Ryan N Kelley\Desktop\1274357740129.jpg
[2010/05/20 21:09:25 | 000,993,399 | ---- | C] () -- C:\Users\Ryan N Kelley\Desktop\020.JPG
[2010/05/20 13:31:48 | 180,732,072 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/05/19 17:30:29 | 000,000,528 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2010/05/19 17:30:14 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2010/05/19 15:06:25 | 172,785,396 | ---- | C] () -- C:\Users\Ryan N Kelley\Desktop\t_reddeadr_vr_mvf4_gt_hd.wmv
[2010/05/19 14:28:27 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010/05/19 14:28:27 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010/05/19 11:34:04 | 000,524,288 | -HS- | C] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TMContainer00000000000000000002.regtrans-ms
[2010/05/19 11:34:03 | 000,524,288 | -HS- | C] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TMContainer00000000000000000001.regtrans-ms
[2010/05/19 11:34:02 | 000,065,536 | -HS- | C] () -- C:\Users\Ryan N Kelley\ntuser.dat{0f210e93-62ed-11df-9faf-00269ed98ce7}.TM.blf
[2010/05/13 13:04:10 | 000,011,536 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\square explanation.docx
[2010/05/13 00:58:33 | 000,011,621 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Square Numbers.docx
[2010/05/13 00:35:28 | 000,155,221 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Square-enix Financial Analysis.pptx
[2010/05/12 22:48:48 | 000,012,596 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Lawless Questions.docx
[2010/05/11 17:23:22 | 000,010,646 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\MBA Management.docx
[2010/05/08 10:11:32 | 000,012,160 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Outline.docx
[2010/05/07 13:52:28 | 000,014,103 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\SquareEnix Report.docx
[2010/05/07 13:22:29 | 000,015,236 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\Ryan Nathaniel Kelley Resume 10.5.6.docx
[2010/05/02 13:10:55 | 060,315,615 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010/05/02 13:10:55 | 000,113,461 | ---- | C] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/04/27 22:40:01 | 000,014,894 | ---- | C] () -- C:\Users\Ryan N Kelley\Documents\I promised myself that I would write every day.docx
[2010/01/20 00:16:22 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010/01/20 00:11:58 | 000,163,840 | ---- | C] () -- C:\Windows\System32\SM37XCoInst.dll
[2009/07/14 08:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 08:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2009/06/11 06:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/07/14 10:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/07/21 15:20:38 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2009/06/11 06:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/05/24 06:18:16 | 1408,045,056 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/19 14:28:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/05/19 14:28:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/05/24 06:18:18 | 1877,393,408 | -HS- | M] () -- C:\pagefile.sys
[2010/03/27 17:30:47 | 000,000,006 | ---- | M] () -- C:\SISHashTodo
[2010/03/27 17:30:47 | 000,000,610 | ---- | M] () -- C:\SISTodo
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\drivers\*.sys /180 >[2009/12/02 02:50:03 | 000,274,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\acpi.sys
[2010/05/02 13:11:05 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2010/05/02 13:10:55 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2010/05/02 13:11:19 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys
[2010/05/02 13:11:14 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/02/19 12:07:42 | 000,516,152 | ---- | M] (Conexant Systems Inc.) -- C:\Windows\System32\drivers\CHDRT32.sys
[2009/12/11 16:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ksecpkg.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/27 16:32:05 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/27 16:32:26 | 000,221,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/27 16:32:12 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys
[2010/01/20 00:32:32 | 000,033,088 | ---- | M] (Lenovo (United States) Inc.) -- C:\Windows\System32\drivers\psadd.sys
[2009/12/08 17:05:40 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv.sys
[2009/12/08 17:05:09 | 000,113,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srvnet.sys
[2009/11/25 16:37:18 | 000,230,576 | ---- | M] (Synaptics Incorporated) -- C:\Windows\System32\drivers\SynTP.sys
[2010/03/03 03:20:00 | 000,011,552 | ---- | M] (Lenovo Group Limited) -- C:\Windows\System32\drivers\TPPWR32V.SYS
[2009/12/04 15:51:10 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbehci.sys
[2009/12/04 15:51:54 | 000,258,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbhub.sys
========== Files - Unicode (All) ==========[2010/05/13 07:56:19 | 002,011,240 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\?????.pptx) -- C:\Users\Ryan N Kelley\Documents\普天間発表.pptx
[2010/05/11 16:29:26 | 000,011,212 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\???????????????????.docx) -- C:\Users\Ryan N Kelley\Documents\見せかけの同盟はもう維持出来ない副文献.docx
[2010/05/11 16:29:24 | 000,011,212 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\???????????????????.docx) -- C:\Users\Ryan N Kelley\Documents\見せかけの同盟はもう維持出来ない副文献.docx
[2010/05/11 16:10:12 | 000,013,104 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????????????????·?????·????·???.docx) -- C:\Users\Ryan N Kelley\Documents\見せかけの同盟はもう維持できない・単語シート・ライアン・ケリー.docx
[2010/05/11 16:10:10 | 000,013,104 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????????????????·?????·????·???.docx) -- C:\Users\Ryan N Kelley\Documents\見せかけの同盟はもう維持できない・単語シート・ライアン・ケリー.docx
[2010/05/10 10:34:07 | 002,011,240 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\?????.pptx) -- C:\Users\Ryan N Kelley\Documents\普天間発表.pptx
[2010/05/08 10:11:39 | 000,025,305 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\???????????????2????.docx) -- C:\Users\Ryan N Kelley\Documents\米軍は日本から引き揚げると見る2つの根拠.docx
[2010/05/07 17:01:16 | 000,025,305 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\???????????????2????.docx) -- C:\Users\Ryan N Kelley\Documents\米軍は日本から引き揚げると見る2つの根拠.docx
[2010/04/28 09:43:14 | 000,012,131 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\?????????.docx) -- C:\Users\Ryan N Kelley\Documents\原発バブルと民主党.docx
[2010/04/27 12:46:09 | 000,012,131 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\?????????.docx) -- C:\Users\Ryan N Kelley\Documents\原発バブルと民主党.docx
[2010/04/26 21:26:41 | 000,032,731 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\?????????????.docx) -- C:\Users\Ryan N Kelley\Documents\『財務諸表の読み方』の概要.docx
[2010/04/19 14:34:03 | 000,013,374 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\??????·????????.docx) -- C:\Users\Ryan N Kelley\Documents\パナソニック・損益計算書の分析.docx
[2010/04/19 12:57:49 | 000,119,924 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????????????.pptx) -- C:\Users\Ryan N Kelley\Documents\パナソニック株式会社分析.pptx
[2010/04/19 10:40:53 | 000,119,924 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????????????.pptx) -- C:\Users\Ryan N Kelley\Documents\パナソニック株式会社分析.pptx
[2010/04/19 10:33:19 | 000,011,112 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\??????·???????.docx) -- C:\Users\Ryan N Kelley\Documents\パナソニック・損益計算書比較.docx
[2010/04/19 10:33:18 | 000,011,112 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\??????·???????.docx) -- C:\Users\Ryan N Kelley\Documents\パナソニック・損益計算書比較.docx
[2010/04/19 07:20:17 | 000,013,374 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\??????·????????.docx) -- C:\Users\Ryan N Kelley\Documents\パナソニック・損益計算書の分析.docx
[2010/04/19 06:38:40 | 000,187,412 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\??????.pdf) -- C:\Users\Ryan N Kelley\Documents\パナソニック.pdf
[2010/04/19 06:38:40 | 000,187,412 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\??????.pdf) -- C:\Users\Ryan N Kelley\Documents\パナソニック.pdf
[2010/04/15 10:02:17 | 000,011,413 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\??????????·????.docx) -- C:\Users\Ryan N Kelley\Documents\「学生の声」ライアン・ケリー編.docx
[2010/04/15 10:02:16 | 000,011,413 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\??????????·????.docx) -- C:\Users\Ryan N Kelley\Documents\「学生の声」ライアン・ケリー編.docx
[2010/04/09 07:58:00 | 000,011,973 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·???·???????.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー・研究目的の提示.docx
[2010/04/09 07:57:58 | 000,011,973 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·???·???????.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー・研究目的の提示.docx
[2010/04/06 08:53:38 | 000,000,162 | -H-- | M] ()(C:\Users\Ryan N Kelley\Documents\~$????.docx) -- C:\Users\Ryan N Kelley\Documents\~$中根知恵.docx
[2010/04/06 08:53:38 | 000,000,162 | -H-- | C] ()(C:\Users\Ryan N Kelley\Documents\~$????.docx) -- C:\Users\Ryan N Kelley\Documents\~$中根知恵.docx
[2010/04/06 08:53:37 | 000,012,013 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????.docx) -- C:\Users\Ryan N Kelley\Documents\中根知恵.docx
[2010/04/06 08:53:33 | 000,012,013 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????.docx) -- C:\Users\Ryan N Kelley\Documents\中根知恵.docx
[2010/04/05 13:13:18 | 000,032,731 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\?????????????.docx) -- C:\Users\Ryan N Kelley\Documents\『財務諸表の読み方』の概要.docx
[2010/04/02 16:08:09 | 000,011,199 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????.docx) -- C:\Users\Ryan N Kelley\Documents\財務諸表.docx
[2010/04/02 16:08:09 | 000,000,162 | -H-- | M] ()(C:\Users\Ryan N Kelley\Documents\~$????.docx) -- C:\Users\Ryan N Kelley\Documents\~$財務諸表.docx
[2010/04/02 16:08:09 | 000,000,162 | -H-- | C] ()(C:\Users\Ryan N Kelley\Documents\~$????.docx) -- C:\Users\Ryan N Kelley\Documents\~$財務諸表.docx
[2010/04/02 16:08:08 | 000,011,199 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????.docx) -- C:\Users\Ryan N Kelley\Documents\財務諸表.docx
[2010/04/02 11:31:53 | 000,011,398 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????????????????????????.docx) -- C:\Users\Ryan N Kelley\Documents\証券発行を希望している会社はまず投資機関に相談し.docx
[2010/04/02 11:31:51 | 000,011,398 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????????????????????????.docx) -- C:\Users\Ryan N Kelley\Documents\証券発行を希望している会社はまず投資機関に相談し.docx
[2010/04/02 10:06:18 | 000,011,826 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·??1.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリ1.docx
[2010/04/02 10:06:16 | 000,011,826 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·??1.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリ1.docx
[2010/04/02 09:54:21 | 000,012,066 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·???????????.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー「お勧めの場所」.docx
[2010/04/02 09:54:17 | 000,012,066 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·???????????.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー「お勧めの場所」.docx
[2010/04/02 09:51:34 | 000,012,066 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·???.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー.docx
[2010/04/02 08:19:23 | 000,012,066 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·???.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー.docx
[2010/03/31 09:47:21 | 000,012,929 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·???????·????152???.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー待遇表現・応用練習152ページ.docx
[2010/03/31 09:47:19 | 000,012,929 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·???????·????152???.docx) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー待遇表現・応用練習152ページ.docx
[2010/03/31 09:47:08 | 000,012,929 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·????152???.docx) -- C:\Users\Ryan N Kelley\Documents\待遇表現・応用練習152ページ.docx
[2010/03/31 08:00:45 | 000,012,929 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·????152???.docx) -- C:\Users\Ryan N Kelley\Documents\待遇表現・応用練習152ページ.docx
[2010/03/29 16:43:21 | 000,084,750 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????·??????10?3?.pdf) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー履歴書10年3月.pdf
[2010/03/29 16:43:21 | 000,084,750 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????·??????10?3?.pdf) -- C:\Users\Ryan N Kelley\Documents\ライアン・ケリー履歴書10年3月.pdf
[2010/03/29 16:23:45 | 000,084,693 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\???????.pdf) -- C:\Users\Ryan N Kelley\Documents\履歴書一般模範.pdf
[2010/03/29 16:23:45 | 000,084,693 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\???????.pdf) -- C:\Users\Ryan N Kelley\Documents\履歴書一般模範.pdf
[2010/03/29 15:56:55 | 000,011,199 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\??????.docx) -- C:\Users\Ryan N Kelley\Documents\会計学の授業.docx
[2010/03/29 15:56:53 | 000,011,199 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\??????.docx) -- C:\Users\Ryan N Kelley\Documents\会計学の授業.docx
[2010/03/09 10:50:54 | 000,000,000 | ---D | M](C:\Users\Ryan N Kelley\Documents\??) -- C:\Users\Ryan N Kelley\Documents\写真
[2010/03/09 10:39:55 | 000,000,000 | ---D | C](C:\Users\Ryan N Kelley\Documents\??) -- C:\Users\Ryan N Kelley\Documents\写真
[2010/03/09 10:15:15 | 000,000,000 | ---D | M](C:\Users\Ryan N Kelley\Documents\????·??3??) -- C:\Users\Ryan N Kelley\Documents\政治経済・教材3学期
[2010/03/09 10:08:11 | 000,000,000 | ---D | C](C:\Users\Ryan N Kelley\Documents\????·??3??) -- C:\Users\Ryan N Kelley\Documents\政治経済・教材3学期
[2010/03/08 14:22:58 | 000,027,169 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\????????????·?????.odt) -- C:\Users\Ryan N Kelley\Documents\デフレ地獄脱出への処方箋・予習シート.odt
[2010/03/04 10:12:44 | 000,027,169 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\????????????·?????.odt) -- C:\Users\Ryan N Kelley\Documents\デフレ地獄脱出への処方箋・予習シート.odt
[2010/03/02 12:39:25 | 126,318,468 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\???????.wmv) -- C:\Users\Ryan N Kelley\Documents\マネーゲーム②.wmv
[2010/02/26 12:58:42 | 076,170,946 | ---- | C] ()(C:\Users\Ryan N Kelley\Documents\???????.wmv) -- C:\Users\Ryan N Kelley\Documents\マネーゲーム①.wmv
[2010/02/23 23:29:41 | 000,000,000 | -HSD | M](C:\Users\Ryan N Kelley\???? ????) -- C:\Users\Ryan N Kelley\スタート メニュー
[2010/02/23 23:27:39 | 000,000,000 | -HSD | M](C:\ProgramData\??????) -- C:\ProgramData\デスクトップ
[2010/02/23 23:27:39 | 000,000,000 | -HSD | M](C:\ProgramData\???? ????) -- C:\ProgramData\スタート メニュー
[2010/01/20 00:50:10 | 000,000,020 | ---- | M] ()(C:\Windows\??) -- C:\Windows\ィ
[2010/01/20 00:50:10 | 000,000,020 | ---- | C] ()(C:\Windows\??) -- C:\Windows\ィ
[2007/12/17 15:47:42 | 126,318,468 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\???????.wmv) -- C:\Users\Ryan N Kelley\Documents\マネーゲーム②.wmv
[2007/12/17 14:55:03 | 076,170,946 | ---- | M] ()(C:\Users\Ryan N Kelley\Documents\???????.wmv) -- C:\Users\Ryan N Kelley\Documents\マネーゲーム①.wmv
(C:\Users\Ryan N Kelley\???? ????) -- C:\Users\Ryan N Kelley\スタート メニュー
(C:\ProgramData\??????) -- C:\ProgramData\デスクトップ
(C:\ProgramData\???? ????) -- C:\ProgramData\スタート メニュー
< End of report >
OTL Extras:
OTL Extras logfile created on: 2010/05/24 11:30:49 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Ryan N Kelley\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000411 | Country: 米国 | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 48.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.95 Gb Total Space | 86.78 Gb Free Space | 39.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Q: | 9.77 Gb Total Space | 5.05 Gb Free Space | 51.66% Space Free | Partition Type: NTFS
Computer Name: RYANNKELLEY
Current User Name: Ryan N Kelley
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{}" = ThinkPad Wireless LAN Adapter Software
"{03307ADB-5DCC-44B2-4A6E-DEF5FBDEBF8F}" = Catalyst Control Center Graphics Full New
"{09D12A04-7868-7E7A-FBEE-2D8B84A0CEC1}" = ccc-core-static
"{13EDE453-1B5D-C894-399C-6F97B8F5AABD}" = CCC Help English
"{174E7E6E-EE32-E978-1775-7354B4BB708E}" = CCC Help Portuguese
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav ???????
"{18554B3F-46EA-40A9-B4EA-7EEE83C0559D}" = Client Security - Password Manager
"{1E0BAB0C-62D6-050E-0F03-300D49C4367A}" = Catalyst Control Center Localization All
"{1F8DA253-3C27-4B01-A63A-BA3533120833}" = Microsoft Research AutoCollage Touch 2009
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live アップロード ツール
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 20
"{283276C7-67EF-4EE4-8663-E46013148330}" = Windows Live サインイン アシスタント
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2B3FC7F2-B03D-5317-BC39-28E424D560DE}" = CCC Help Italian
"{35EF2C07-76FE-4CD6-9648-07001437ED3D}" = iTuner
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{449F6C53-3BDE-7CFA-442B-86FEEC99BE40}" = Catalyst Control Center Graphics Full Existing
"{457C231F-853D-4FB6-8E8D-72B73A113637}" = Windows Live Messenger
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage ハードディスク・アクティブプロテクション・システム
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F5B18A3-E921-4FFE-BEF4-ACBB98964FC2}" = AMD USB Filter Driver
"{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}" = Create Recovery Media
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{57FA0525-01F9-4051-8DE9-CBF43CAC68D9}" = Catalyst Control Center - Branding
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6672CCD8-3F97-C941-316D-2ADD845C2806}" = CCC Help German
"{67CC1309-4B7B-8E02-05F4-24893D7E2695}" = Catalyst Control Center Graphics Light
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6AD782EA-43B4-0FE7-0D66-BED8FA74B4D7}" = CCC Help Russian
"{76CAAA8A-8DFB-608B-ADB5-0BF970F51816}" = CCC Help Chinese Standard
"{78FD9D18-8EF1-5B9D-04D4-4B3AA0EF91EF}" = CCC Help Thai
"{7A6DF1F2-CD27-7B7D-5D38-3EF996C4BA09}" = CCC Help Norwegian
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8644F312-3393-423A-89CB-250C0FE58C09}" = Windows Live メール
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{89E3D86B-F03E-4956-20BB-FC63C57EE600}" = Catalyst Control Center Core Implementation
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8C050D9C-3C82-EB28-3E42-DB750646ED58}" = CCC Help Swedish
"{8CDAA241-56BA-2753-159E-D94A331C857B}" = CCC Help Polish
"{8E537894-A559-4D60-B3CB-F4485E3D24E3}" = ThinkVantage Access Connections
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90FD3224-976C-42AE-AFD1-69F91D4915DF}" = Windows Live ムービー メーカー
"{9202762E-4B4C-48C9-A6CC-C27F9F85190A}" = Mobile Broadband Connect
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96514462-396E-58AB-E7D8-40E68DF0540E}" = CCC Help Danish
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{974321BB-4C1B-E2DD-8681-9299A0612220}" = CCC Help Turkish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{A0288703-7C15-BB9C-67F4-87BD77254B5B}" = CCC Help Hungarian
"{AA4BB734-4ECD-ED8E-CDF6-9B46A7EA4723}" = CCC Help Dutch
"{AA771B73-87FD-176A-080D-CB7B565B9D02}" = CCC Help Japanese
"{AC76BA86-7AD7-1041-7B44-A93000000001}" = Adobe Reader 9.3.2 - Japanese
"{AEDA8B17-9571-4839-9240-F93E41198E19}" = Windows Live Sync
"{B383F243-0ABC-4E56-AA30-923B8D85076E}" = Rescue and Recovery
"{B8ED7934-A409-485D-8A9B-B6E13FD70649}" = Windows Live おすすめパック
"{B9CF1C2E-6B3C-409C-A12B-836DAFC18059}" = Windows Live フォト ギャラリー
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C4C6D61E-812A-7D27-1253-8DC94BC2949C}" = ATI Catalyst Install Manager
"{C64A877E-DF8D-4017-AA82-000A77C6D809}" = Verizon Wireless Mobile Broadband Self Activation
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{CF45FA39-F1DF-68F3-8D58-376FAA730B82}" = Catalyst Control Center InstallProxy
"{D0CFEF60-D6C3-6B73-3942-39F1996C2590}" = CCC Help French
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D54B026D-BBEC-F673-F6AF-01E70DCA8AC7}" = CCC Help Czech
"{D81486A1-2371-4059-AC70-1AB894AC96E6}" = AT&T Service Activation
"{DA30454E-6F71-352B-E9D8-587D27A29167}" = CCC Help Chinese Traditional
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad È“d—̓}ƒl[ƒWƒƒ[
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EC40CFB8-D427-2369-035B-3C687136189D}" = CCC Help Finnish
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EE0693CF-56A7-F290-C26C-908CA6CB1852}" = CCC Help Greek
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2091915-62C0-8B8C-CDAE-E25DCC2671CF}" = ccc-utility
"{F7237FF7-DEF7-E05A-9695-404D02D48739}" = Catalyst Control Center Graphics Previews Vista
"{F744737E-97E7-4C9E-AC96-C986B189E410}" = Windows Live Toolbar
"{F964875D-648A-E867-9158-C2EFA46DCF67}" = CCC Help Korean
"{FC05D86B-2D16-477D-A3D2-7D12970583D0}" = Windows Live Writer
"{FD0F6896-7BAF-7D9C-A6A9-A50B8854F8E4}" = CCC Help Spanish
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}" = Lenovo Warranty Information
"{FE7AD27A-62B1-44F6-B69C-25D1ECA94F5D}" = Integrated Camera
"{FF7DB6B3-1288-4A82-A42A-14F76420DC42}" = Windows Live Call
"114EB224AD576F278686036AA9E1EFB7847E3935" = Windows ドライバ パッケージ - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4)
"755087041320E005CB1E8A67C5C55A260EB81B90" = Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407)
"A6A8668C0A13640CA28FE2A7D9654BE4AE478B13" = Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Anki" = Anki
"ATI Uninstaller" = ATI Uninstaller
"AVG9Uninstall" = AVG 9.0
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"Chipamp" = Chipamp
"CNXT_AUDIO_HDA" = Conexant CX20582 SmartAudio HD
"ComicRack" = ComicRack v0.9.119
"EnablePS" = Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FLAC" = FLAC 1.2.1b (remove only)
"GOM Player" = GOM PLAYER
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HUAWEI DataCard Driver" = HUAWEI DataCard Driver 3.05
"InFlac" = InFlac 1.1.1
"JDownloader" = JDownloader
"Lenovo Welcome_is1" = Lenovo Welcome
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"OnScreenDisplay" = オン スクリーン表示
"PC-Doctor for Windows" = Lenovo ThinkVantage Toolbox
"Power Management Driver" = ThinkPad Power Management Driver
"PowerISO" = PowerISO
"Rainlendar2" = Rainlendar2 (remove only)
"Rainmeter" = Rainmeter (remove only)
"Revo Uninstaller" = Revo Uninstaller 1.88
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"W7DevOR" = Registry Patch to arrange icons in Device and Printers folder of Windows 7
"Wakan" = Wakan 1.67
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live おすすめパック
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 2010/05/17 19:27:16 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11996
Error - 2010/05/17 19:27:16 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11996
Error - 2010/05/17 19:27:18 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2010/05/17 19:27:18 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 13151
Error - 2010/05/17 19:27:18 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13151
Error - 2010/05/17 19:27:19 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2010/05/17 19:27:19 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 14367
Error - 2010/05/17 19:27:19 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 14367
Error - 2010/05/17 19:27:20 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2010/05/17 19:27:20 | Computer Name = RyanNKelley | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 15740
[ OSession Events ]
Error - 2010/04/05 19:54:34 | Computer Name = RyanNKelley | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 70926
seconds with 5940 seconds of active time. This session ended with a crash.
Error - 2010/05/12 10:21:16 | Computer Name = RyanNKelley | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 42991
seconds with 2340 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2010/05/15 7:03:31 | Computer Name = RyanNKelley | Source = Service Control Manager | ID = 7026
Description = ?????????????????????????????????????: cdrom
Error - 2010/05/18 0:16:02 | Computer Name = RyanNKelley | Source = Service Control Manager | ID = 7011
Description = Wlansvc ???????????????????????????? (30000 ???) ???????
Error - 2010/05/18 20:11:08 | Computer Name = RyanNKelley | Source = Service Control Manager | ID = 7026
Description = ?????????????????????????????????????: cdrom
Error - 2010/05/18 21:11:49 | Computer Name = RyanNKelley | Source = ACPI | ID = 327693
Description = : ??????????? (EC) ??????????????????????????EC ???????????????????????????BIOS
? EC ???????????????????????????????? BIOS ????????????????????????????????????????????????????????????????????
Error - 2010/05/18 21:11:50 | Computer Name = RyanNKelley | Source = Service Control Manager | ID = 7026
Description = ?????????????????????????????????????: cdrom
Error - 2010/05/18 21:12:23 | Computer Name = RyanNKelley | Source = WMPNetworkSvc | ID = 866300
Description =
Error - 2010/05/18 21:16:35 | Computer Name = RyanNKelley | Source = DCOM | ID = 10016
Description =
Error - 2010/05/18 21:16:37 | Computer Name = RyanNKelley | Source = DCOM | ID = 10016
Description =
Error - 2010/05/18 21:16:40 | Computer Name = RyanNKelley | Source = DCOM | ID = 10016
Description =
Error - 2010/05/18 21:16:40 | Computer Name = RyanNKelley | Source = DCOM | ID = 10016
Description =
< End of report >
GMER Log:
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-05-24 11:59:33
Windows 6.1.7600
Running: 4dhjsehq.exe; Driver: C:\Users\RYANNK~1\AppData\Local\Temp\pflyiaow.sys
---- System - GMER 1.0.15 ----
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342DAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342D104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342D3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83415634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83415898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342D1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342D958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342D6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342DF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8342E1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8348D599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 834B1F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\vrisqqb.sys ???????????????? !
.rsrc C:\Windows\System32\drivers\discache.sys entry point in ".rsrc" section [0x8E3CD014]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8FA2E000, 0x2CC244, 0xE8000020]
.text peauth.sys 99A96C9D 28 Bytes [55, BA, 55, B4, 28, 52, 4A, ...]
.text peauth.sys 99A96CC1 28 Bytes [55, BA, 55, B4, 28, 52, 4A, ...]
.text autochk.exe 00691204 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text autochk.exe 0069120C 1 Byte [00]
.text autochk.exe 00691210 1 Byte [00]
.text autochk.exe 00691214 2 Bytes [00, 00] {ADD [EAX], AL}
.text autochk.exe 00691218 2 Bytes [00, 00] {ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1392] ntdll.dll!NtProtectVirtualMemory 77655360 5 Bytes JMP 0025000A
.text C:\Windows\system32\svchost.exe[1392] ntdll.dll!NtWriteVirtualMemory 77655EE0 5 Bytes JMP 0026000A
.text C:\Windows\system32\svchost.exe[1392] ntdll.dll!KiUserExceptionDispatcher 77656448 5 Bytes JMP 0024000A
.text C:\Windows\system32\svchost.exe[1392] ole32.dll!CoCreateInstance 75F257FC 5 Bytes JMP 0066000A
.text C:\Windows\system32\svchost.exe[1392] USER32.dll!GetCursorPos 7776C198 5 Bytes JMP 005D000A
.text C:\Windows\Explorer.EXE[2636] ntdll.dll!NtProtectVirtualMemory 77655360 5 Bytes JMP 0052000A
.text C:\Windows\Explorer.EXE[2636] ntdll.dll!NtWriteVirtualMemory 77655EE0 5 Bytes JMP 0053000A
.text C:\Windows\Explorer.EXE[2636] ntdll.dll!KiUserExceptionDispatcher 77656448 5 Bytes JMP 0051000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5960] ntdll.dll!NtProtectVirtualMemory 77655360 5 Bytes JMP 0063000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5960] ntdll.dll!NtWriteVirtualMemory 77655EE0 5 Bytes JMP 006C000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[5960] ntdll.dll!KiUserExceptionDispatcher 77656448 5 Bytes JMP 0060000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3552] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[3612] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
IAT c:\Program Files\Lenovo\System Update\SUService.exe[3984] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [756C5E25] C:\Windows\system32\apphelp.dll (?????????????????? ?????/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (???? ??? ????? ??????? ?????/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (???? ??? ????? ??????? ?????/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004b halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device -> \Driver\atapi \Device\Harddisk0\DR0 8668DCEC
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Bluetooth \x30c7\x30d0\x30a4\x30b9 (RFCOMM \x30d7\x30ed\x30c8\x30b3\x30eb TDI) 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Bluetooth \x30c7\x30d0\x30a4\x30b9 (\x30d1\x30fc\x30bd\x30ca\x30eb \x30a8\x30ea\x30a2 \x30cd\x30c3\x30c8\x30ef\x30fc\x30af) 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f3ad3f68b
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\506313c47442
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Bluetooth \x30c7\x30d0\x30a4\x30b9 (RFCOMM \x30d7\x30ed\x30c8\x30b3\x30eb TDI) 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Bluetooth \x30c7\x30d0\x30a4\x30b9 (\x30d1\x30fc\x30bd\x30ca\x30eb \x30a8\x30ea\x30a2 \x30cd\x30c3\x30c8\x30ef\x30fc\x30af) 1?
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f3ad3f68b (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\506313c47442 (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\Ryan N Kelley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (\x30bb\x30fc\x30d5\x30e2\x30fc\x30c9).lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (\x30bb\x30fc\x30d5\x30e2\x30fc\x30c9).lnk 1
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
---- Files - GMER 1.0.15 ----
File C:\Windows\System32\drivers\discache.sys suspicious modification
File C:\Windows\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----
Thank you for your help.