My wife's computer went bonkers today. She opened an email 'from' fedex about a package that failed to be delivered and proceeded to infect her computer. A window titled 'System Check' opened and claims to want to 'Scan PC for errors' but you cant close it and cant open task manager. Along with this, there is a pop-up titled 'Windows detected a hard disk problem' with a message stating 'A potential disk failure may cause loss of files... its highly recommended to scan and solve the HDD problems before continue using this PC' two buttons are available 'scan and fix', 'cancel and reboot'. In addition there are about 20 pop-ups that keep coming back after closing them.. they all state 'failed to save all the components for the file \\system32\000006e6a. The file is corrupted or unreadable. This error may be caused by a PC hardware problem.' (the hex code is different in all the pop-ups but the rest of the message is the same). Lastly theres a 'Files Indexation Process Failed' pop-up.. which also comes back pretty much as soon as its closed.
I've unplugged the network cable on her PC, thinking that whatever has infected her PC wont be able to transfer anything else off or copy anything else on. I downloaded OTL, ran the quick scan and have posted the log below.
Any help that can be provided would be greatly appreciated!
OTL logfile created on: 2/1/2012 10:51:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Arlie Norwood\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.51% Memory free
3.85 Gb Paging File | 3.28 Gb Available in Paging File | 85.29% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.85 Gb Total Space | 5.77 Gb Free Space | 3.95% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 197.68 Gb Free Space | 21.22% Space Free | Partition Type: NTFS
Drive G: | 3.77 Gb Total Space | 3.19 Gb Free Space | 84.47% Space Free | Partition Type: FAT32
Drive H: | 2048.00 Gb Total Space | 1434.65 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
Drive N: | 465.76 Gb Total Space | 14.10 Gb Free Space | 3.03% Space Free | Partition Type: NTFS
Drive O: | 2048.00 Gb Total Space | 2030.59 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive P: | 232.88 Gb Total Space | 0.27 Gb Free Space | 0.12% Space Free | Partition Type: NTFS
Computer Name: DC0XMBC1 | User Name: Arlie Norwood | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/01 22:48:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Arlie Norwood\Desktop\OTL.exe
PRC - [2012/02/01 18:18:58 | 000,361,472 | -H-- | M] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\ji0oVjv2ohKbsg.exe
PRC - [2012/02/01 11:25:26 | 000,451,584 | -H-- | M] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\cYmlANnOemt.exe
PRC - [2011/11/11 14:36:56 | 000,045,056 | -H-- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2011/05/30 20:16:12 | 000,032,849 | -H-- | M] (MyWebSearch.com) -- C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
PRC - [2010/09/07 09:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 09:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/09/07 09:11:44 | 000,119,200 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\afwServ.exe
PRC - [2010/08/04 16:25:00 | 000,057,344 | -H-- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\ASTSRV.EXE
PRC - [2010/07/13 12:43:50 | 000,720,896 | -H-- | M] (Data Robotics, Inc.) -- C:\Program Files\Drobo\Drobo Dashboard\Support\DDService.exe
PRC - [2008/07/17 16:12:24 | 000,161,064 | -H-- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2008/07/17 16:12:04 | 000,177,448 | -H-- | M] (Seagate LLC) -- C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
PRC - [2008/06/24 15:06:06 | 001,840,424 | -H-- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008/04/26 14:34:00 | 000,185,896 | -H-- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/02/22 03:25:21 | 000,144,784 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
PRC - [2007/12/04 02:07:00 | 000,061,440 | RH-- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe
PRC - [2007/09/05 13:06:56 | 000,057,344 | -H-- | M] (Creative Technology Ltd) -- C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
PRC - [2007/08/27 10:36:34 | 000,111,912 | -H-- | M] (SingleClick Systems) -- C:\Program Files\Dell Network Assistant\hnm_svc.exe
PRC - [2007/06/13 04:23:07 | 001,033,216 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/28 21:57:12 | 000,395,776 | -H-- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/07/06 07:15:00 | 000,151,552 | -H-- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2006/07/06 07:14:30 | 000,090,112 | -H-- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2006/03/03 21:03:10 | 000,069,632 | -H-- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2006/02/28 06:00:00 | 000,015,872 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2005/10/05 03:12:00 | 000,094,208 | -H-- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2005/09/08 05:20:00 | 000,122,940 | -H-- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2004/07/13 15:51:29 | 000,679,936 | -H-- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\Tablet.exe
PRC - [2003/12/05 15:21:48 | 000,073,728 | -H-- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
PRC - [2003/11/12 01:05:00 | 000,094,208 | -H-- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2002/07/01 02:05:00 | 000,074,752 | -H-- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\W32X86\3\E_S10IC2.EXE
========== Modules (No Company Name) ==========
MOD - [2012/02/01 16:57:50 | 001,697,280 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020101\algo.dll
MOD - [2011/07/15 00:09:29 | 000,212,992 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\a9e71dda6389403be4db7b567592e3b8\System.ServiceProcess.ni.dll
MOD - [2011/07/15 00:09:27 | 007,867,392 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
MOD - [2011/07/15 00:09:21 | 011,485,184 | -H-- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
MOD - [2010/09/07 09:13:40 | 000,142,872 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\aswDld.dll
MOD - [2009/02/26 00:39:00 | 000,065,536 | RH-- | M] () -- C:\WINDOWS\system32\P17.dll
MOD - [2007/04/15 20:56:10 | 000,389,120 | -H-- | M] () -- C:\Program Files\Adobe\Reader 8.0\Reader\AdobeXMP.dll
MOD - [2005/10/05 03:12:00 | 000,094,208 | -H-- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
MOD - [2004/08/24 11:50:32 | 000,217,157 | -H-- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBMSDev.dll
MOD - [2003/12/05 15:28:52 | 000,118,784 | -H-- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBRsvc.dll
MOD - [2003/12/05 15:28:24 | 000,274,432 | -H-- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBNWDev.dll
MOD - [2003/12/05 15:21:48 | 000,073,728 | -H-- | M] () -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
MOD - [2001/10/28 15:42:30 | 000,116,224 | -H-- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/11/11 14:36:56 | 000,045,056 | -H-- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2011/05/30 20:16:13 | 000,028,762 | -H-- | M] (MyWebSearch.com) [Auto | Stopped] -- C:\Program Files\MyWebSearch\bar\3.bin\MWSSVC.EXE -- (MyWebSearchService)
SRV - [2010/09/07 09:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 09:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 09:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/09/07 09:11:44 | 000,119,200 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\afwServ.exe -- (avast! Firewall)
SRV - [2010/08/04 16:25:00 | 000,057,344 | -H-- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\ASTSRV.EXE -- (astcc)
SRV - [2010/07/13 12:43:50 | 000,720,896 | -H-- | M] (Data Robotics, Inc.) [Auto | Running] -- C:\Program Files\Drobo\Drobo Dashboard\Support\DDService.exe -- (DDService)
SRV - [2009/07/23 20:10:38 | 000,061,440 | -H-- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2009/05/28 09:19:36 | 000,655,624 | -H-- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/07/17 16:12:24 | 000,161,064 | -H-- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2007/08/27 10:36:34 | 000,111,912 | -H-- | M] (SingleClick Systems) [Auto | Running] -- C:\Program Files\Dell Network Assistant\hnm_svc.exe -- (hnmsvc)
SRV - [2007/07/06 05:00:46 | 002,988,888 | -H-- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90)
SRV - [2006/07/06 07:14:30 | 000,090,112 | -H-- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2006/03/03 21:03:10 | 000,069,632 | -H-- | M] (HP) [Unknown | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2006/02/28 06:00:00 | 000,015,872 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2006/02/28 06:00:00 | 000,015,872 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (SMTPSVC) Simple Mail Transfer Protocol (SMTP)
SRV - [2006/02/28 06:00:00 | 000,015,872 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2005/09/23 07:01:16 | 002,799,808 | -H-- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80)
SRV - [2004/07/13 15:51:29 | 000,679,936 | -H-- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\WINDOWS\system32\Tablet.exe -- (TabletService)
SRV - [2003/12/05 15:21:48 | 000,073,728 | -H-- | M] () [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
SRV - [2003/11/12 01:05:00 | 000,094,208 | -H-- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)
========== Driver Services (SafeList) ==========
DRV - [2010/09/07 08:54:16 | 000,099,792 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2010/09/07 08:53:58 | 000,340,048 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2010/09/07 08:53:35 | 000,190,416 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2010/09/07 08:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 08:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 08:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 08:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 08:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 08:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010/06/28 14:10:45 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aswNdis.sys -- (aswNdis)
DRV - [2009/08/25 14:10:52 | 000,049,904 | RH-- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2009/02/26 00:29:58 | 001,142,272 | RH-- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\P17.sys -- (P17)
DRV - [2008/02/14 17:50:04 | 000,038,656 | -H-- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Capt9051.sys -- (SQTECH9051)
DRV - [2006/12/18 18:01:20 | 000,012,672 | -H-- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\packet.sys -- (Packet)
DRV - [2006/07/24 10:20:00 | 001,156,648 | -H-- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/05/11 16:14:40 | 000,014,416 | -H-- | M] (Portrait Displays, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\pdihwctl.sys -- (PDIHWCTL)
DRV - [2006/01/10 11:07:58 | 000,004,864 | -H-- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/27 18:25:00 | 000,031,896 | -H-- | M] (DemoForge, LLC) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dfmirage.sys -- (dfmirage)
DRV - [2005/09/23 02:42:00 | 000,054,464 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys -- (VSPerfDrv)
DRV - [2005/09/08 05:20:00 | 000,094,332 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/08 05:20:00 | 000,087,036 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/08 05:20:00 | 000,086,524 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/08 05:20:00 | 000,025,628 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/08 05:20:00 | 000,014,684 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/08 05:20:00 | 000,006,364 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/08 05:20:00 | 000,002,496 | -H-- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/08/25 12:16:52 | 000,005,628 | -H-- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 12:16:16 | 000,022,684 | -H-- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/01/10 04:15:30 | 000,106,496 | RH-- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2005/01/10 04:15:24 | 000,138,752 | RH-- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2004/10/15 07:54:56 | 000,044,344 | -H-- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i1display.sys -- (i1display)
DRV - [2004/05/07 12:02:08 | 000,044,344 | -H-- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EyeOneDp.sys -- (eyeonedp)
DRV - [2004/03/08 12:55:50 | 000,013,567 | -H-- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2002/04/02 15:30:16 | 000,033,024 | -H-- | M] (Colorvision Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cvspydr2.sys -- (cvspydr2)
DRV - [2001/12/19 10:45:00 | 000,008,576 | -H-- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\VCdRom.sys -- (vcdrom)
DRV - [2001/04/09 14:45:00 | 000,008,138 | -H-- | M] (Wacom Technology Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PenClass.sys -- (PenClass)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070104
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070104
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070104
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...client&ie=UTF-8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.co...-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "My Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co...us&ibd=6070104"
FF - prefs.js..extensions.mywebsearch.prevKwdURL: "data:text/plain,keyword.URL=http://www.google.com/search?ie=UTF-8&oe=UTF-8&gfns=1&sourceid=navclient&rls=com.google:en-US:official&q="
FF - prefs.js..keyword.URL: "http://search.mywebs...732&searchfor="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Maija Norwood\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\3.bin\NPMyWebS.dll (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.1: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\3.bin [2011/10/28 11:48:21 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/11/03 19:55:34 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/11/03 19:55:42 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/10 12:48:36 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/10 12:48:36 | 000,000,000 | -H-D | M]
[2009/03/09 17:50:38 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Extensions
[2011/10/28 11:48:22 | 000,000,000 | -H-D | M] (No name found) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\extensions
[2009/03/31 19:10:53 | 000,000,000 | -H-D | M] (FireFTP) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2008/04/19 09:29:15 | 000,000,000 | -H-D | M] (Dimdim Web Meeting Publisher) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\extensions\[email protected]
[2011/10/28 11:48:22 | 000,000,000 | -H-D | M] (My Web Search) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\extensions\[email protected]
[2009/03/31 19:10:55 | 000,000,000 | -H-D | M] (RedShift V3) -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\extensions\[email protected]
[2010/09/07 20:50:57 | 000,010,017 | -H-- | M] () -- C:\Documents and Settings\Arlie Norwood\Application Data\Mozilla\Firefox\Profiles\qv5xj8no.default\searchplugins\mywebsearch.xml
[2012/01/29 19:22:02 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2007/04/24 17:51:22 | 000,000,000 | -H-D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/11/14 19:34:14 | 000,090,112 | -H-- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2007/03/05 12:59:06 | 000,645,504 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
[2006/01/18 12:50:00 | 000,319,488 | -H-- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\3.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [cYmlANnOemt.exe] C:\Documents and Settings\All Users\Application Data\cYmlANnOemt.exe (Microsoft Corp)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [My Web Search Bar] C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [unYHREDALK.exe] C:\Documents and Settings\All Users\Application Data\unYHREDALK.exe ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O4 - Startup: C:\Documents and Settings\Arlie Norwood\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O8 - Extra context menu item: &Search - http://edits.mywebse...1w&n=2010040114 File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish...fishActivia.cab (Snapfish Activia)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds...ransferCtrl.cab (DLC Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2005\HelpAsyncPluggableProtocol.dll (TODO: <Company name>)
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Arlie Norwood\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Arlie Norwood\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/09/28 19:55:13 | 000,000,062 | -H-- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{0cda8aa2-92cb-11dc-8d92-0019d1033d05}\Shell\AutoRun\command - "" = "I:\Install FreeAgent Tools.exe" /run
O33 - MountPoints2\{9a4ea692-5c6f-11df-8e35-0019d1033d05}\Shell\AutoRun\command - "" = E:\InstallSeagateManager.exe
O33 - MountPoints2\Z\Shell - "" = AutoRun
O33 - MountPoints2\Z\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\Z\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL splash.hta
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (aswBoot.exe /A:"*" /L:"1033" /heur:80 /pup /archives /IA:0 /KBD:2 /dir:"C:\Program Files\Alwil Software\Avast5")
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/01 23:20:03 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Arlie Norwood\Recent
[2012/02/01 22:50:54 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Arlie Norwood\Desktop\OTL.exe
[2012/02/01 18:19:12 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Arlie Norwood\Start Menu\Programs\System Check
[2012/02/01 18:18:58 | 000,361,472 | -H-- | C] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\ji0oVjv2ohKbsg.exe
[2012/02/01 11:28:32 | 000,451,584 | -H-- | C] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\cYmlANnOemt.exe
[2012/01/20 13:58:56 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011
[2012/01/06 10:06:41 | 000,000,000 | -H-D | C] -- C:\Program Files\Eye-One Match 3
[2011/06/01 20:00:32 | 000,065,536 | RH-- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2008/03/25 11:53:15 | 000,115,712 | -H-- | C] (Macrovision) -- C:\Program Files\eZsuite.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/01 22:48:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Arlie Norwood\Desktop\OTL.exe
[2012/02/01 22:45:23 | 000,000,886 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/01 20:55:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\At3.job
[2012/02/01 20:40:07 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\At2.job
[2012/02/01 18:19:26 | 000,000,416 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\ji0oVjv2ohKbsg
[2012/02/01 18:19:13 | 000,000,853 | -H-- | M] () -- C:\Documents and Settings\Arlie Norwood\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/02/01 18:19:13 | 000,000,835 | -H-- | M] () -- C:\Documents and Settings\Arlie Norwood\Desktop\System Check.lnk
[2012/02/01 18:15:01 | 000,039,472 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/02/01 18:14:34 | 000,013,668 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/01 18:14:32 | 000,000,882 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/01 16:56:30 | 000,000,527 | -H-- | M] () -- C:\WINDOWS\System32\tablet.dat
[2012/02/01 16:54:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/01 16:54:50 | 2145,304,576 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/01 14:00:04 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\At4.job
[2012/02/01 13:12:18 | 000,000,456 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\zoNkJHJwME917F
[2012/02/01 13:10:06 | 000,340,104 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\zoNkJHJwME917F.exe
[2012/02/01 12:47:43 | 000,431,240 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\unYHREDALK.exe
[2012/02/01 10:10:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\At1.job
[2012/01/28 21:34:15 | 000,000,069 | -H-- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/19 22:23:22 | 000,000,090 | -H-- | M] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2012/01/06 10:05:35 | 000,000,034 | -H-- | M] () -- C:\WINDOWS\AutoRun.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/01 18:19:13 | 000,000,853 | -H-- | C] () -- C:\Documents and Settings\Arlie Norwood\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/02/01 18:19:13 | 000,000,835 | -H-- | C] () -- C:\Documents and Settings\Arlie Norwood\Desktop\System Check.lnk
[2012/02/01 18:19:09 | 000,000,416 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ji0oVjv2ohKbsg
[2012/02/01 13:10:30 | 000,000,456 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\zoNkJHJwME917F
[2012/02/01 13:10:06 | 000,340,104 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\zoNkJHJwME917F.exe
[2012/02/01 12:47:46 | 000,431,240 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\unYHREDALK.exe
[2011/12/22 14:44:33 | 000,294,256 | -H-- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/07/15 00:51:14 | 000,000,090 | -H-- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/06/15 20:24:49 | 000,000,069 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/06/14 12:09:55 | 000,000,664 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/06/01 20:00:32 | 000,053,248 | RH-- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2011/06/01 20:00:31 | 000,065,536 | RH-- | C] () -- C:\WINDOWS\System32\P17.dll
[2011/05/31 18:03:05 | 000,000,527 | -H-- | C] () -- C:\WINDOWS\System32\tablet.dat
[2011/05/31 18:02:59 | 000,015,744 | -H-- | C] () -- C:\WINDOWS\System32\Wintab.dll
[2011/02/04 10:25:36 | 000,004,943 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\pyknfeyt.slj
[2009/11/24 13:44:19 | 000,000,704 | -H-- | C] () -- C:\Program Files\FOXUSER.FPT
[2009/11/24 13:44:19 | 000,000,665 | -H-- | C] () -- C:\Program Files\FOXUSER.DBF
[2009/08/17 21:14:07 | 000,005,663 | -H-- | C] () -- C:\WINDOWS\System32\Ludap17.ini
[2009/04/16 22:08:31 | 000,116,224 | -H-- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2009/03/29 21:29:24 | 000,126,976 | -H-- | C] () -- C:\WINDOWS\System32\EEBAPI.dll
[2009/03/29 21:29:24 | 000,094,208 | -H-- | C] () -- C:\WINDOWS\System32\EEBDSCVR.dll
[2009/03/29 21:29:24 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\System32\EBAPI.dll
[2009/02/20 11:40:18 | 000,000,125 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/12/14 14:37:06 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\Arlie Norwood\Local Settings\Application Data\fusioncache.dat
[2008/05/02 00:59:42 | 000,000,791 | -H-- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/04/10 21:32:27 | 000,000,032 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/04/10 10:18:31 | 000,044,344 | -H-- | C] () -- C:\WINDOWS\System32\drivers\i1display.sys
[2008/04/10 10:05:06 | 000,000,197 | -H-- | C] () -- C:\WINDOWS\i1Share.ini
[2008/04/10 10:00:17 | 000,044,344 | -H-- | C] () -- C:\WINDOWS\System32\drivers\EyeOneDp.sys
[2008/04/10 09:58:03 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\AutoRun.ini
[2008/03/25 11:53:15 | 000,040,721 | -H-- | C] () -- C:\Program Files\lax.jar
[2008/03/25 11:53:15 | 000,004,098 | -H-- | C] () -- C:\Program Files\eZsuite.lax
[2008/03/25 11:53:15 | 000,002,066 | -H-- | C] () -- C:\Program Files\Launcher.jar
[2007/05/03 01:04:50 | 000,765,952 | -H-- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/05/03 01:04:49 | 000,180,224 | -H-- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/04/26 22:31:21 | 000,117,005 | -H-- | C] () -- C:\WINDOWS\HPHins10.dat
[2007/04/26 22:31:21 | 000,002,314 | -H-- | C] () -- C:\WINDOWS\hphmdl10.dat
[2007/04/26 22:22:25 | 000,116,979 | -H-- | C] () -- C:\WINDOWS\HPHins10.dat.temp
[2007/04/26 22:22:25 | 000,002,314 | -H-- | C] () -- C:\WINDOWS\hphmdl10.dat.temp
[2007/04/18 11:55:56 | 000,000,029 | -H-- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2007/04/03 20:07:52 | 000,044,344 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Seqcal.sys
[2007/03/02 22:05:05 | 000,013,312 | -H-- | C] () -- C:\Documents and Settings\Arlie Norwood\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/19 14:42:21 | 000,077,824 | -H-- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2007/02/19 14:27:23 | 000,000,201 | -H-- | C] () -- C:\WINDOWS\PowerReg.dat
[2007/02/19 14:24:20 | 000,290,919 | -H-- | C] () -- C:\WINDOWS\System32\pythoncom21.dll
[2007/02/19 14:24:20 | 000,057,344 | -H-- | C] () -- C:\WINDOWS\System32\PyWinTypes21.dll
[2007/02/19 14:23:02 | 000,096,768 | -H-- | C] () -- C:\WINDOWS\SlantAdj.dll
[2007/02/19 14:23:02 | 000,003,136 | -H-- | C] () -- C:\WINDOWS\Ade001.bin
[2007/02/19 14:23:02 | 000,000,072 | -H-- | C] () -- C:\WINDOWS\System32\epDPE.ini
[2007/02/19 14:20:48 | 000,000,196 | -H-- | C] () -- C:\WINDOWS\EPSON 1260_1660 Installer.ini
[2007/01/19 14:34:26 | 000,003,920 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/19 14:34:26 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\CFF56F9C53.sys
[2007/01/15 01:25:03 | 000,021,791 | -H-- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
[2007/01/15 01:25:03 | 000,001,037 | -H-- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
[2007/01/15 01:24:43 | 000,038,576 | -H-- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2007/01/15 01:24:43 | 000,010,225 | -H-- | C] () -- C:\WINDOWS\System32\axperf.ini
[2007/01/15 01:24:41 | 000,011,435 | -H-- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2007/01/12 16:00:14 | 000,162,943 | -H-- | C] () -- C:\WINDOWS\FotoFusion Uninstaller.exe
[2007/01/09 23:35:00 | 000,003,774 | -H-- | C] () -- C:\WINDOWS\mozver.dat
[2007/01/09 22:52:05 | 000,000,013 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\13.sys
[2007/01/09 21:23:24 | 000,000,106 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS
[2007/01/09 21:19:21 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\nsreg.dat
[2007/01/04 07:39:48 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2007/01/04 07:35:36 | 000,000,654 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2007/01/04 07:31:45 | 000,000,126 | -H-- | C] () -- C:\WINDOWS\wininit.ini
[2007/01/04 07:10:46 | 000,049,152 | -H-- | C] () -- C:\WINDOWS\setpwrcg.exe
[2007/01/04 07:10:44 | 000,090,112 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2007/01/04 07:09:55 | 000,000,301 | -H-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/02/28 06:00:00 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/02/28 06:00:00 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/28 06:00:00 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/28 06:00:00 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/28 06:00:00 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/28 06:00:00 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/28 06:00:00 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/28 06:00:00 | 000,004,461 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/02/28 06:00:00 | 000,001,788 | -H-- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2005/11/10 01:56:34 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\px.ini
[2005/03/08 00:17:08 | 000,000,054 | -H-- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004/08/10 13:12:05 | 000,000,780 | -H-- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 13:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 13:02:15 | 000,023,348 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:01:18 | 000,001,793 | -H-- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:57:15 | 002,233,840 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 12:51:20 | 000,610,114 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 12:51:20 | 000,133,896 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 12:51:16 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/08/23 22:56:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/04/24 23:51:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2008/04/16 14:59:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/09/08 15:18:03 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Drobo
[2011/06/22 11:25:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\LumaPix
[2011/07/15 00:52:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2010/12/22 15:31:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\onOne Software
[2007/01/13 10:30:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2011/02/01 11:13:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Raize
[2008/09/28 19:54:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2008/05/02 00:59:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2011/07/28 10:25:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2012/02/01 12:15:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/01/09 00:59:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2007/05/21 22:32:03 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Azureus
[2007/02/13 20:34:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\CoffeeCup Software
[2008/04/19 11:29:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Dimdim
[2007/02/28 22:16:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\EPSON
[2008/01/07 20:19:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Imagenomic
[2007/01/08 22:45:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Leadertech
[2007/01/16 20:50:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\LumaPix
[2007/11/16 19:12:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Netscape
[2007/06/21 22:43:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\OLYMPUS
[2007/06/09 21:58:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Arlie Norwood\Application Data\Opera
[2012/02/01 10:10:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\At1.job
[2012/02/01 20:40:07 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\At2.job
[2012/02/01 20:55:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\At3.job
[2012/02/01 14:00:04 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\At4.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEB71B81
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E74F5F70
< End of report >
Here is the extras.txt file that was also created.
OTL Extras logfile created on: 2/1/2012 10:51:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Arlie Norwood\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.51% Memory free
3.85 Gb Paging File | 3.28 Gb Available in Paging File | 85.29% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.85 Gb Total Space | 5.77 Gb Free Space | 3.95% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 197.68 Gb Free Space | 21.22% Space Free | Partition Type: NTFS
Drive G: | 3.77 Gb Total Space | 3.19 Gb Free Space | 84.47% Space Free | Partition Type: FAT32
Drive H: | 2048.00 Gb Total Space | 1434.65 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
Drive N: | 465.76 Gb Total Space | 14.10 Gb Free Space | 3.03% Space Free | Partition Type: NTFS
Drive O: | 2048.00 Gb Total Space | 2030.59 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive P: | 232.88 Gb Total Space | 0.27 Gb Free Space | 0.12% Space Free | Partition Type: NTFS
Computer Name: DC0XMBC1 | User Name: Arlie Norwood | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\WS_FTP\WS_FTP95.exe" = C:\Program Files\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 -- (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe" = C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe:*:Enabled:CrazyTalk
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
"C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2005\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager -- (iAnywhere Solutions, Inc.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 -- (Adobe Systems Incorporated)
"C:\Program Files\Drobo\Drobo Dashboard\Support\DDService.exe" = C:\Program Files\Drobo\Drobo Dashboard\Support\DDService.exe:*:Enabled:Drobo Dashboard Service -- (Data Robotics, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth
"C:\Documents and Settings\Maija Norwood\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Maija Norwood\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox
"C:\Program Files\Intuit\QuickBooks 2010\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2010\QBDBMgrN.exe:*:Enabled:QuickBooks 2010 Data Manager -- (Intuit, Inc.)
"C:\Program Files\HP\HP Deskjet 3000 J310 series\Bin\DeviceSetup.exe" = C:\Program Files\HP\HP Deskjet 3000 J310 series\Bin\DeviceSetup.exe:LocalSubNet:Enabled:HP Device Setup -- (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Deskjet 3000 J310 series\Bin\HPNetworkCommunicator.exe" = C:\Program Files\HP\HP Deskjet 3000 J310 series\Bin\HPNetworkCommunicator.exe:LocalSubNet:Enabled:HP Network Communicator -- (Hewlett-Packard Co.)
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant -- (SingleClick Systems)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{022B0C16-18C9-464A-8BC6-2B2CC6342E5F}" = Image Trends' ShineOff Plug-In 1.0.2
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{0700E22B-A422-40A5-BD20-04BF618CA0F9}" = QuickBooks Pro 2010
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{07D7D276-46D2-42F5-BC90-0906C330746E}" = Microsoft Windows Vista Client Headers and Libraries (6001.16533.121)
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}" = Intel® PRO Network Connections
"{0C8EE4CE-981E-4E7C-A2B5-2EA68A645589}" = D4100_Help
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1AFB6EA5-DBD0-43A4-AA56-4D1EBF8E39D8}" = HP Deskjet 3000 J310 series Basic Device Software
"{1B041548-33BC-4174-8B97-ADC9B7948488}" = Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{20B8FD81-A71D-42ea-B887-07A616069E63}" = D4100
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2238A301-6A20-4bdb-A655-C84AB629F6B6}" = hph_readme
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{235674B0-A35F-4811-8A8F-E8F42A919EA3}" = PhotoPresets with One-Click WOW!
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2373A92B-1C1C-4E71-B494-5CA97F96AA19}" = Microsoft SQL Server 2005
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{25F31730-1B6C-4E8E-A3B9-818DC0CD961D}" = Seagate Manager Installer
"{2928F0D5-DABC-4637-A6B3-740629075555}" = RocketFish 5.1 PCI Sound Card
"{2B2BEF9D-BF66-4BCF-B3DE-8C23DC516317}" = Basic Date Picker v1.3
"{2E572661-94BA-829F-80B0-0776F4832B09}" = The Photographer's Ephemeris
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{333B10B5-5DD1-44C0-891C-9738FDE14CC1}" = Drobo Dashboard
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36E7A382-E7DF-4C07-9CCA-9415C1E208AF}" = SNAP 3.0.1 Downloader
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3BDB182E-8371-46BD-AC39-C14A91D5EEF8}" = Microsoft SQL Server 2005 Reporting Services
"{3CD2DC4F-F3F6-4E62-B22B-773CA9D784EB}" = Image Trends' PearlyWhites Plug-In 2.0.2
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{49140327-BEBF-43dd-B386-43311A065609}" = hph_ProductContext
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 4.1
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{554EB98C-D995-471F-8874-D2BA7BF5EB3E}" = Noiseware Professional Edition
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5821459E-A8E1-42D1-A8B5-34AB19A75E79}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{59679381-3F22-4A40-A7AD-890242D74DF4}" = Plug-in Suite 5.1.1
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{5DE0220D-1A71-3C1B-9BE1-DF8D3D392BC4}" = Microsoft Document Explorer 2008
"{5DEDD928-2CBE-35E9-B002-85232EDB120A}" = Microsoft .NET Framework 2.0 Service Pack 1
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{623B8278-8CAD-45C1-B844-58B687C07805}" = Bing Bar Platform
"{6297F8EC-D821-4B33-B845-8A8D1A0DF472}" = Lightroom
"{63A5DC0D-1EDD-4D69-8F31-87FAEB1F7084}" = Microsoft SQL Server 2005 Notification Services
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{654A65DA-7173-4B51-ACEB-F855201EE033}" = HP Deskjet 3000 J310 series Help
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{68CE30BC-365D-4BC6-A8F4-520899B6FECD}" = Microsoft Windows SDK Intellisense and Reference Assemblies (6001.16533.121)
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F684F0C-D0AB-4C6F-9D87-1B285D1566EF}" = Image Trends' PearlyWhites Plug-In 1.0.1
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7C515D87-2DCD-422B-B993-3FE8A71B3DDB}" = Noiseware Professional Plug-in
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C62A94B-4AB6-485F-A111-93056684D340}" = SQLXML4
"{8CD05946-4102-3560-B475-9EA2C5B22388}" = Microsoft Device Emulator version 3.0 - ENU
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90032DD0-ABEE-4424-AC1E-B076BDD4E350}" = Microsoft SQL Server 2005 Tools
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPROR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{903B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Professional 2003
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{930A590D-29F8-4554-8DC8-27B8A17DD637}" = Microsoft Windows Vista Client Utilities for Win32 Development (6001.16533.121)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{982DB00A-9C4E-436B-8707-18E113BAA44C}" = Microsoft SQL Server 2005 Analysis Services
"{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3EABC0-CA06-11D4-BF77-00104B130C19}" = EPSON TWAIN 5
"{9D404F8F-05A1-4734-9550-6EC2FEE916B8}" = HP Photosmart and Deskjet 7.0 Software
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3D44AD8-D3C9-45E4-B861-3B653C6EF620}" = Rhapsody MP3 Download Manager
"{A5BB0E8C-6BCE-3486-A705-82F5707C5059}" = Windows SDK .Net Tools
"{A5CCD0C8-6D5E-4515-BDD7-2A22D5D91033}" = Nero 8 Essentials
"{A6DE1AAE-B147-4B08-A61C-BA471D86AC4D}" = DB VGA Cam
"{A919EFA5-ADD6-42CB-AE11-EE5DAAB686D5}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{A922F4CD-6129-4B8A-A00D-C6185C1A39B2}" = Microsoft Windows Vista Client Common Utilities (6001.16533.121)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B0513493-04B9-4F21-B4AB-83E750D54256}" = Adobe Photoshop Lightroom 2.7
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B5688129-7595-4E5B-9990-CEF981A31264}" = SyncToy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B69CC1A5-0404-11D6-ABCB-005004C21D30}" = EPSON Copy Utility
"{B6CB9E38-ED2F-33C6-9A58-11A37F4F5C96}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{B7B3E9B3-FB14-4927-894B-E9124509AF5A}" = Adobe Flash Player 10 ActiveX
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BBEB5679-6E2C-47C6-A9B5-3C6D4CD19B60}" = hph_software_req
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C76AA8ED-44F5-41B1-BAE6-A2E43C1CAA4F}" = Image Trends' ShineOff Plug-In 2.0.2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECCAEF3-D37A-48D5-8E39-8D0727C8C6E2}" = ACH Origination Application
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{D0ACE207-0F90-402C-8CFA-2CB3D44CE689}" = Adobe Photoshop Lightroom 3.6
"{D6346347-B8CD-4B52-BF5F-9676CDE79801}" = hph_software
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DE1A361F-31DC-4AC5-ABBA-2323BC505880}" = LexarMedia ImageRescue Software
"{E0A41F96-7231-4AE8-A654-EEB34F935462}" = Microsoft SQL Server 2005 Integration Services
"{E2B31B67-9795-4EF9-9AC6-B683E7B11BE6}_is1" = FotoFusion v4
"{E3B039DD-C2DD-4765-800A-3572BC75458D}" = SNAP 3.0.1
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9B4A5F2-CAF7-4727-BB22-1939FD659019}" = HP Deskjet 3000 J310 series Product Improvement Study
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{EBC91840-41E1-4CC3-AC11-0B889546223C}" = Microsoft IntelliPoint 5.5
"{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}" = Adobe Stock Photos 1.0
"{EE174FE1-2276-46E9-8C54-9E8C51D528CB}" = ACHFORPC
"{F0BD17B0-086B-11DD-BD0B-0800200C9A66}" = Dimdim Web Meeting Publisher For IE
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F958F15A-4CE2-44E7-8179-97BBDCAF401A}" = OLYMPUS Master 2
"{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}" = Windows Resource Kit Tools
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter" = AC3Filter (remove only)
"Active@ ISO Burner v 1.1" = Active@ ISO Burner v 1.1
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"avast5" = avast! Internet Security
"CCleaner" = CCleaner
"ColorChecker Passport_is1" = ColorChecker Passport 1.0
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"EPSON Photo Print" = EPSON Photo Print
"EPSON Printer and Utilities" = EPSON Printer Software
"Eye-One Match_is1" = Eye-One Match 3.6.1
"Eye-One Share" = Eye-One Share
"eZsports" = eZsports
"eZsuite" = eZsuite
"Flexrise.9F3FBFC56E7DF11606748B3513468A7A7FB809D1.1" = The Photographer's Ephemeris
"FotoFusion" = FotoFusion
"Google Chrome" = Google Chrome
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo Creations" = HP Photo Creations
"i1ColorPoint 1.0" = i1ColorPoint 1.0
"InstallShield_{25F31730-1B6C-4E8E-A3B9-818DC0CD961D}" = Seagate Manager Installer
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU" = Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MVApplication1" = Memorex exPressit Label Design Studio
"MyPublisher" = MyPublisher
"MyWebSearch bar Uninstall" = My Web Search
"NetDevil_LEGO_Universe_is1" = LEGO Universe
"NVIDIA Drivers" = NVIDIA Drivers
"Photodex Presenter" = Photodex Presenter
"PROR" = Microsoft Office Professional 2007
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"ReNamer_is1" = ReNamer
"SearchAssist" = SearchAssist
"Silent Package Run-Time Sample" = EPSON Scanner Reference Guide
"Tax Forms Helper 2009_is1" = Tax Forms Helper 2009 9.0
"Tax Forms Helper 2010_is1" = Tax Forms Helper 2010 9.5
"Tax Forms Helper 2011_is1" = Tax Forms Helper 2011 10.0
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"VISPROR" = Microsoft Office Visio Professional 2007
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"Wacom Tablet Driver" = Wacom Tablet
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.2 final uninstall
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 1/28/2010 10:47:42 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 1/28/2010 10:47:42 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 1/28/2010 10:47:43 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 1/28/2010 10:47:43 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 3/31/2010 4:07:45 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 3/31/2010 4:07:45 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 3/31/2010 4:07:45 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 3/31/2010 4:07:45 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 4/3/2010 10:24:53 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
Error - 5/13/2010 4:06:00 AM | Computer Name = DC0XMBC1 | Source = avast! | ID = 33554522
Description =
[ Application Events ]
Error - 2/1/2012 5:16:01 PM | Computer Name = DC0XMBC1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 -- The installer
has encountered an unexpected error installing this package. This may indicate
a problem with this package. The error code is 2721. The arguments are: CA_ScheduleUpdateAssemblyRB.3643236F_FC70_11D3_A536_0090278A1BB8,
,
Error - 2/1/2012 5:16:01 PM | Computer Name = DC0XMBC1 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update 'KB958481'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET Framework
2.0-KB958481_20120201_211601265-Msi0.txt.
Error - 2/1/2012 5:16:01 PM | Computer Name = DC0XMBC1 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb958481,
P2 1033, P3 1603, P4 msi, P5 f, P6 9.0.31211.0, P7 install, P8 x86, P9 xp, P10
2721.
Error - 2/1/2012 5:16:06 PM | Computer Name = DC0XMBC1 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft visual studio 2008-kb952241,
P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.30612.0, P7 install, P8 x86, P9 xp, P10
0.
Error - 2/1/2012 5:16:14 PM | Computer Name = DC0XMBC1 | Source = NativeWrapper | ID = 5000
Description =
Error - 2/1/2012 5:16:25 PM | Computer Name = DC0XMBC1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 -- The installer
has encountered an unexpected error installing this package. This may indicate
a problem with this package. The error code is 2721. The arguments are: CA_ScheduleUpdateAssemblyRB.3643236F_FC70_11D3_A536_0090278A1BB8,
,
Error - 2/1/2012 5:16:26 PM | Computer Name = DC0XMBC1 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update 'KB974417'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET Framework
2.0-KB974417_20120201_211625421-Msi0.txt.
Error - 2/1/2012 5:16:26 PM | Computer Name = DC0XMBC1 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb974417,
P2 1033, P3 1603, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
2721.
Error - 2/1/2012 7:02:07 PM | Computer Name = DC0XMBC1 | Source = Ci | ID = 4127
Description = Content index on c:\documents and settings\all users\application data\microsoft\visio\catalog.wci
could not be initialized. Error 2147942405.
Error - 2/1/2012 7:02:07 PM | Computer Name = DC0XMBC1 | Source = Ci | ID = 4127
Description = Content index on c:\documents and settings\all users\application data\microsoft\visio\catalog.wci
could not be initialized. Error 2147942405.
[ OSession Events ]
Error - 1/14/2009 1:51:56 PM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 7211
seconds with 480 seconds of active time. This session ended with a crash.
Error - 10/28/2009 9:49:16 AM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 74103
seconds with 960 seconds of active time. This session ended with a crash.
Error - 11/16/2009 2:09:18 AM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 289
seconds with 0 seconds of active time. This session ended with a crash.
Error - 5/18/2010 12:19:55 PM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 39
seconds with 0 seconds of active time. This session ended with a crash.
Error - 8/7/2010 12:34:59 PM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 267663
seconds with 5880 seconds of active time. This session ended with a crash.
Error - 10/17/2010 8:27:17 AM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 144307
seconds with 3660 seconds of active time. This session ended with a crash.
Error - 10/1/2010 1:24:56 AM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 272
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2/7/2011 10:13:49 AM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 832559
seconds with 14820 seconds of active time. This session ended with a crash.
Error - 2/9/2011 11:23:23 PM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 220163
seconds with 8640 seconds of active time. This session ended with a crash.
Error - 12/16/2011 4:06:36 PM | Computer Name = DC0XMBC1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 367017
seconds with 8760 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2/1/2012 10:20:10 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 10:20:13 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 10:20:16 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 10:20:19 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:33 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:36 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:39 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:42 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:45 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
Error - 2/1/2012 11:39:48 PM | Computer Name = DC0XMBC1 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk2\D, has a bad block.
< End of report >