OTL logfile created on: 17/07/2012 22:23:45 - Run 3
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\Katie Higgins\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy
1013.98 Mb Total Physical Memory | 463.91 Mb Available Physical Memory | 45.75% Memory free
2.39 Gb Paging File | 1.94 Gb Available in Paging File | 81.50% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 0.36 Gb Free Space | 0.49% Space Free | Partition Type: NTFS
Computer Name: KATIEHIGGINS | User Name: Katie Higgins | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/06/25 22:47:03 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Katie Higgins\Desktop\OTL.exe
PRC - [2012/03/28 00:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe
PRC - [2011/09/14 12:54:56 | 000,037,728 | -H-- | M] (Mindjet) -- C:\Program Files\Mindjet\MindManager 10\MmReminderService.exe
PRC - [2010/03/27 12:11:37 | 000,202,256 | -H-- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/01/31 18:29:06 | 000,196,608 | RH-- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2007/06/13 11:23:07 | 001,033,216 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/25 13:47:12 | 000,356,352 | -H-- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe
PRC - [2006/08/02 01:38:30 | 000,802,816 | -H-- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/08/02 01:32:44 | 000,696,320 | -H-- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2006/08/02 01:27:54 | 000,479,232 | -H-- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2006/06/29 08:41:22 | 000,184,320 | -H-- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
PRC - [2006/05/19 20:13:38 | 000,798,720 | -H-- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSServ.exe
PRC - [2006/03/02 23:50:52 | 000,151,552 | -H-- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\Toshiba.exe
PRC - [2006/02/07 16:30:40 | 000,035,840 | -H-- | M] (TOSHIBA Corp.) -- C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
PRC - [2006/02/02 12:11:38 | 000,073,728 | -H-- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Tvs\TvsTray.exe
PRC - [2005/08/03 14:26:02 | 000,040,960 | -H-- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe
PRC - [2005/05/12 10:31:38 | 000,118,784 | -H-- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
PRC - [2005/04/11 11:26:06 | 000,065,536 | -H-- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2005/01/18 00:38:38 | 000,040,960 | -H-- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2001/11/12 13:31:48 | 000,020,480 | -H-- | M] (X10) -- C:\Program Files\Common Files\X10\Common\X10nets.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/27 08:23:00 | 000,087,912 | -H-- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | -H-- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/09/14 12:54:12 | 000,150,856 | -H-- | M] () -- C:\Program Files\Mindjet\MindManager 10\zlib.dll
MOD - [2011/02/04 18:48:30 | 000,291,840 | -H-- | M] () -- C:\WINDOWS\system32\sbe.dll
MOD - [2010/02/05 19:14:43 | 001,291,776 | -H-- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2006/08/02 01:26:20 | 000,118,784 | -H-- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/08/02 01:24:54 | 000,348,160 | -H-- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/06/23 14:07:08 | 001,167,360 | -H-- | M] () -- C:\Program Files\Intel\Wireless\Bin\acAuth.dll
MOD - [2006/01/04 18:14:36 | 000,049,152 | -H-- | M] () -- C:\Program Files\Toshiba\TOSHIBA Applet\TouchPad_ONOFF.dll
MOD - [2005/11/23 14:55:38 | 000,118,784 | -H-- | M] () -- C:\WINDOWS\system32\TCtrlIO.dll
MOD - [2004/08/10 13:00:00 | 000,059,904 | -H-- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2004/08/10 13:00:00 | 000,014,336 | -H-- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2004/07/20 17:04:00 | 000,094,208 | -H-- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Documents and Settings\All Users\Application Data\QuestScan\questscan183.exe C:\Program Files\QuestScan\questscan.dll ludiyodum lenopabex -- (QuestScan Service)
SRV - [2012/03/28 00:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe -- (NIS)
SRV - [2010/01/15 13:49:20 | 000,227,232 | -H-- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2006/02/07 16:30:40 | 000,035,840 | -H-- | M] (TOSHIBA Corp.) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe -- (TAPPSRV)
SRV - [2005/01/18 00:38:38 | 000,040,960 | -H-- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2001/11/12 13:31:48 | 000,020,480 | -H-- | M] (X10) [Auto | Running] -- C:\Program Files\Common Files\X10\Common\X10nets.exe -- (x10nets)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/06/23 16:44:25 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012/06/22 15:43:50 | 000,369,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20120713.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012/06/22 01:00:00 | 001,589,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20120716.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/06/22 01:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/06/22 01:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/06/22 01:00:00 | 000,087,928 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20120716.002\NAVENG.SYS -- (NAVENG)
DRV - [2012/06/19 00:03:24 | 000,821,920 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20120711.002\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/03/29 07:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\symtdi.sys -- (SYMTDI)
DRV - [2012/03/29 07:28:30 | 000,905,336 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\SymEFA.sys -- (SymEFA)
DRV - [2012/03/29 07:28:25 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\SymDS.sys -- (SymDS)
DRV - [2012/03/29 07:06:25 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\Ironx86.sys -- (SymIRON)
DRV - [2012/03/29 07:03:27 | 000,574,072 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\srtsp.sys -- (SRTSP)
DRV - [2012/03/29 07:03:27 | 000,032,888 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/11/29 23:44:14 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1307010.005\ccSetx86.sys -- (ccSet_NIS)
DRV - [2011/05/20 17:38:50 | 000,089,856 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2011/05/20 17:38:50 | 000,073,344 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2011/05/20 17:38:50 | 000,064,512 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2011/05/20 17:38:50 | 000,026,624 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2011/05/20 17:38:44 | 000,011,136 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2011/05/20 17:38:36 | 000,102,784 | RH-- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/05/20 16:27:24 | 000,030,576 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nx6000.sys -- (MSHUSBVideo)
DRV - [2009/08/05 22:48:42 | 000,054,752 | -H-- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2006/08/02 02:27:48 | 000,012,544 | -H-- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/05/30 16:42:52 | 000,045,696 | -H-- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tvs.sys -- (Tvs)
DRV - [2006/05/05 15:13:52 | 004,271,616 | -H-- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/04/02 01:46:28 | 000,471,264 | -H-- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006/03/22 07:56:24 | 001,522,688 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/12/13 17:08:44 | 001,124,097 | -H-- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005/11/30 18:12:00 | 000,162,560 | -H-- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2005/11/28 10:45:16 | 000,007,040 | -H-- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\x10hid.sys -- (X10Hid)
DRV - [2005/10/20 14:03:42 | 000,006,144 | -H-- | M] (Toshiba Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NBSMI.sys -- (TVALD)
DRV - [2005/09/09 14:47:10 | 000,009,344 | -H-- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2003/01/29 22:35:00 | 000,012,032 | -H-- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)
DRV - [2000/03/29 17:11:20 | 000,008,096 | -H-- | M] (MicroStaff Co.,Ltd.) [Kernel | Auto | Running] -- C:\windows\System32\drivers\MASPINT.SYS -- (MASPINT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://www.mywebsear...rms}&n=77ce5cea
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan...s={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan...s={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan...s={searchTerms}
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://www.mywebsear...rms}&n=77ce5cea
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...&rlz=1I7GGLL_en
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2801948
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...box_im2_test_v2
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = staff.proxy.ul.ie:80
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Documents and Settings\Katie Higgins\Desktop\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/27 12:12:40 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\IPSFFPlgn\ [2012/06/23 16:50:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\coFFPlgn\ [2012/07/17 22:14:09 | 000,000,000 | ---D | M]
[2012/06/23 19:23:12 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/09/06 10:46:55 | 000,000,000 | -H-D | M] (QuestScan) -- C:\Program Files\Mozilla Firefox\extensions\{F0E1168A-B4B5-484C-B77E-0D28E6B64096}
O1 HOSTS File: ([2004/08/10 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (dsWebAllowBHO Class) - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll (Microsoft Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll File not found
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.7.1.5\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\windows\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CFSServ.exe] CFSServ.exe -NoClient File not found
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [hIxvqiEONcrb.exe] C:\Documents and Settings\All Users\Application Data\hIxvqiEONcrb.exe File not found
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 10\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] TFncKy.exe File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPSMain] C:\windows\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005..\Run: [Picasa Media Detector] C:\Documents and Settings\Katie Higgins\Desktop\Picasa2\PicasaMediaDetector.exe File not found
O4 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O7 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 0
O8 - Extra context menu item: &Search - http://tbedits.telev...EC&n=2011090605 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Send Image To MindManager - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O8 - Extra context menu item: Send Link To MindManager - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O8 - Extra context menu item: Send Page To MindManager - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O8 - Extra context menu item: Send Text To MindManager - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 10\Mm8InternetExplorer.dll (Mindjet)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfar...etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFE22642-F1FD-4B1B-BEFE-85F0689BFE5B}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKU\.DEFAULT Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-18 Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-19 Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-20 Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-1787001158-1526232164-327768440-1005 Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\windows\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Katie Higgins\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/13 15:00:59 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{0f6ef2aa-9be6-11de-a2c9-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{0f6ef2aa-9be6-11de-a2c9-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0f6ef2aa-9be6-11de-a2c9-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0f6ef2ad-9be6-11de-a2c9-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{0f6ef2ad-9be6-11de-a2c9-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0f6ef2ad-9be6-11de-a2c9-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2d3834de-0987-11e1-a686-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{2d3834de-0987-11e1-a686-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2d3834de-0987-11e1-a686-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{2d3834e0-0987-11e1-a686-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{2d3834e0-0987-11e1-a686-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2d3834e0-0987-11e1-a686-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{43b9aa36-fd7f-11df-a536-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{43b9aa36-fd7f-11df-a536-0018de7d0ddd}\Shell\open\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{473424b5-c6c8-11dd-a1b0-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
O33 - MountPoints2\{473424b5-c6c8-11dd-a1b0-0018de7d0ddd}\Shell\open\command - "" = E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
O33 - MountPoints2\{504d8cdc-69ae-11df-a412-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{504d8cdc-69ae-11df-a412-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{504d8cdc-69ae-11df-a412-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{504d8cdf-69ae-11df-a412-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{504d8cdf-69ae-11df-a412-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{504d8cdf-69ae-11df-a412-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6f109fe6-5794-11df-a3f0-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{6f109fe6-5794-11df-a3f0-0018de7d0ddd}\Shell\open\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{765bc1e8-400c-11e0-a58c-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{765bc1e8-400c-11e0-a58c-0018de7d0ddd}\Shell\open\command - "" = E:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{77391d5e-0a50-11e1-a687-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{77391d5e-0a50-11e1-a687-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77391d5e-0a50-11e1-a687-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{885d5862-de6e-11de-a322-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{885d5862-de6e-11de-a322-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{885d5862-de6e-11de-a322-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{9e1106e8-4095-11df-a3bd-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{9e1106e8-4095-11df-a3bd-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9e1106e8-4095-11df-a3bd-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{9e1106eb-4095-11df-a3bd-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{9e1106eb-4095-11df-a3bd-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9e1106eb-4095-11df-a3bd-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e5477f92-c5a8-11df-a4c0-0018de7d0ddd}\Shell\AutoRun\command - "" = F:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{e5477f92-c5a8-11df-a4c0-0018de7d0ddd}\Shell\open\command - "" = F:\HONEY\MOON\DRG.exe
O33 - MountPoints2\{ea1dd378-77ad-11df-a429-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{ea1dd378-77ad-11df-a429-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ea1dd378-77ad-11df-a429-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f4bffb8c-de68-11de-a321-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{f4bffb8c-de68-11de-a321-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f4bffb8c-de68-11de-a321-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f4bffb8f-de68-11de-a321-0018de7d0ddd}\Shell - "" = AutoRun
O33 - MountPoints2\{f4bffb8f-de68-11de-a321-0018de7d0ddd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f4bffb8f-de68-11de-a321-0018de7d0ddd}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\.DEFAULT\...exe [@ = exefile] -- Reg Error: Key error. File not found
O37 - HKU\S-1-5-18\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/17 22:22:44 | 000,688,663 | ---- | C] (Farbar) -- C:\Documents and Settings\Katie Higgins\Desktop\FSS.exe
[2012/07/02 22:16:13 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Katie Higgins\Desktop\aswMBR.exe
[2012/06/26 19:26:41 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Katie Higgins\My Documents\Dropbox
[2012/06/26 19:23:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Katie Higgins\Application Data\Dropbox
[2012/06/25 22:47:03 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Katie Higgins\Desktop\OTL.exe
[2012/06/23 22:50:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2012/06/23 22:50:18 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2012/06/23 19:24:19 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\NBRTWizard
[2012/06/23 19:24:19 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\NBRTWizard\0405000.022
[2012/06/23 19:24:07 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Bootable Recovery Tool Wizard
[2012/06/23 19:24:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton Bootable Recovery Tool Wizard
[2012/06/23 19:05:19 | 000,829,648 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Katie Higgins\Desktop\NBRT-Retail-Downloader.exe
[2012/06/23 17:41:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Katie Higgins\Local Settings\Application Data\NPE
[2012/06/23 17:38:44 | 002,841,104 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Katie Higgins\Desktop\NPE.exe
[2012/06/23 17:37:23 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/06/23 17:15:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Live Add-in
[2012/06/23 16:44:26 | 000,060,872 | ---- | C] (Symantec Corporation) -- C:\windows\System32\S32EVNT1.DLL
[2012/06/23 16:44:25 | 000,141,944 | ---- | C] (Symantec Corporation) -- C:\windows\System32\drivers\SYMEVENT.SYS
[2012/06/23 16:44:24 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/06/23 16:42:22 | 000,388,216 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\symtdi.sys
[2012/06/23 16:42:22 | 000,345,208 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\symtdiv.sys
[2012/06/23 16:42:21 | 000,318,584 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\symnets.sys
[2012/06/23 16:42:20 | 000,905,336 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\SymEFA.sys
[2012/06/23 16:42:19 | 000,574,072 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\srtsp.sys
[2012/06/23 16:42:19 | 000,340,088 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\SymDS.sys
[2012/06/23 16:42:19 | 000,032,888 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\srtspx.sys
[2012/06/23 16:42:18 | 000,149,624 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\Ironx86.sys
[2012/06/23 16:42:17 | 000,132,744 | R--- | C] (Symantec Corporation) -- C:\windows\System32\drivers\NIS\1307010.005\ccSetx86.sys
[2012/06/23 16:41:17 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\NIS
[2012/06/23 16:41:17 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\NIS\1307010.005
[2012/06/23 16:41:09 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Internet Security
[2012/06/23 16:41:08 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2012/06/23 16:41:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton Internet Security
[2012/06/23 16:31:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2012/06/23 16:30:59 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2012/06/23 16:30:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2012/06/23 16:28:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Katie Higgins\Start Menu\Programs\Norton
[2012/06/23 16:28:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Norton
[2012/06/23 16:28:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2012/06/23 14:48:44 | 000,000,000 | ---D | C] -- C:\windows\pss
[2012/06/23 14:35:02 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Katie Higgins\Recent
[2012/06/23 14:28:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Katie Higgins\My Documents\Symantec
[2012/06/23 12:54:25 | 000,000,000 | -HSD | C] -- C:\windows\CSC
[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/17 22:22:51 | 000,688,663 | ---- | M] (Farbar) -- C:\Documents and Settings\Katie Higgins\Desktop\FSS.exe
[2012/07/17 22:12:44 | 000,000,294 | -H-- | M] () -- C:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-1787001158-1526232164-327768440-1005.job
[2012/07/17 22:12:31 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2012/07/16 22:35:07 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Katie Higgins\Desktop\MBR.dat
[2012/07/16 22:18:12 | 000,001,158 | -H-- | M] () -- C:\windows\System32\wpa.dbl
[2012/07/11 21:23:04 | 000,000,256 | -H-- | M] () -- C:\windows\tasks\Epson Printer Software Downloader.job
[2012/07/02 22:16:13 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Katie Higgins\Desktop\aswMBR.exe
[2012/06/25 22:47:03 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Katie Higgins\Desktop\OTL.exe
[2012/06/23 19:50:26 | 000,008,942 | ---- | M] () -- C:\windows\System32\drivers\NIS\1307010.005\VT20120410.034
[2012/06/23 19:28:28 | 001,095,523 | ---- | M] () -- C:\windows\System32\drivers\NIS\1307010.005\Cat.DB
[2012/06/23 19:27:10 | 000,001,164 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/06/23 19:06:01 | 000,000,836 | ---- | M] () -- C:\Documents and Settings\Katie Higgins\Desktop\Norton Installation Files.lnk
[2012/06/23 19:05:22 | 000,829,648 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Katie Higgins\Desktop\NBRT-Retail-Downloader.exe
[2012/06/23 18:00:04 | 000,000,302 | -H-- | M] () -- C:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1787001158-1526232164-327768440-1005.job
[2012/06/23 17:38:45 | 002,841,104 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Katie Higgins\Desktop\NPE.exe
[2012/06/23 17:15:02 | 000,000,129 | ---- | M] () -- C:\windows\System32\MRT.INI
[2012/06/23 16:44:25 | 000,141,944 | ---- | M] (Symantec Corporation) -- C:\windows\System32\drivers\SYMEVENT.SYS
[2012/06/23 16:44:25 | 000,007,468 | ---- | M] () -- C:\windows\System32\drivers\SYMEVENT.CAT
[2012/06/23 16:44:25 | 000,000,806 | ---- | M] () -- C:\windows\System32\drivers\SYMEVENT.INF
[2012/06/23 16:44:24 | 000,060,872 | ---- | M] (Symantec Corporation) -- C:\windows\System32\S32EVNT1.DLL
[2012/06/23 16:43:43 | 000,001,964 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/06/18 21:48:21 | 000,000,256 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\fyUg1n1mhcmKGF
[2012/06/18 21:48:15 | 000,000,160 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\-fyUg1n1mhcmKGFr
[2012/06/18 21:48:15 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\-fyUg1n1mhcmKGF
[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/02 22:18:59 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Katie Higgins\Desktop\MBR.dat
[2012/06/23 19:51:10 | 000,008,942 | ---- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\VT20120410.034
[2012/06/23 19:27:10 | 000,001,164 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/06/23 19:24:19 | 000,000,172 | ---- | C] () -- C:\windows\System32\drivers\NBRTWizard\0405000.022\isolate.ini
[2012/06/23 17:15:02 | 000,000,129 | ---- | C] () -- C:\windows\System32\MRT.INI
[2012/06/23 16:44:35 | 001,095,523 | ---- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\Cat.DB
[2012/06/23 16:44:26 | 000,007,468 | ---- | C] () -- C:\windows\System32\drivers\SYMEVENT.CAT
[2012/06/23 16:44:25 | 000,000,806 | ---- | C] () -- C:\windows\System32\drivers\SYMEVENT.INF
[2012/06/23 16:43:43 | 000,001,964 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/06/23 16:41:29 | 000,003,434 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymEFA.inf
[2012/06/23 16:41:29 | 000,002,852 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymDS.inf
[2012/06/23 16:41:29 | 000,001,469 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymNetV.inf
[2012/06/23 16:41:29 | 000,001,441 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymNet.inf
[2012/06/23 16:41:29 | 000,001,388 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\srtspx.inf
[2012/06/23 16:41:28 | 000,001,388 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\srtsp.inf
[2012/06/23 16:41:28 | 000,000,827 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\ccSetx86.inf
[2012/06/23 16:41:28 | 000,000,742 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\Iron.inf
[2012/06/23 16:41:24 | 000,004,782 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymVTcer.dat
[2012/06/23 16:41:19 | 000,007,877 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\symnetv.cat
[2012/06/23 16:41:19 | 000,007,458 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymNet.cat
[2012/06/23 16:41:18 | 000,007,492 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymDS.cat
[2012/06/23 16:41:18 | 000,007,456 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\SymEFA.cat
[2012/06/23 16:41:18 | 000,007,454 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\srtspx.cat
[2012/06/23 16:41:18 | 000,007,450 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\srtsp.cat
[2012/06/23 16:41:18 | 000,007,450 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\iron.cat
[2012/06/23 16:41:17 | 000,007,468 | R--- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\ccsetx86.cat
[2012/06/23 16:41:17 | 000,000,172 | ---- | C] () -- C:\windows\System32\drivers\NIS\1307010.005\isolate.ini
[2012/06/23 16:28:13 | 000,000,836 | ---- | C] () -- C:\Documents and Settings\Katie Higgins\Desktop\Norton Installation Files.lnk
[2012/06/23 15:06:15 | 000,000,873 | ---- | C] () -- C:\Documents and Settings\Katie Higgins\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
[2012/06/18 21:48:15 | 000,000,160 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\-fyUg1n1mhcmKGFr
[2012/06/18 21:48:15 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\-fyUg1n1mhcmKGF
[2012/06/18 21:48:09 | 000,000,256 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\fyUg1n1mhcmKGF
[2011/09/06 10:44:31 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\4170748d032383168d51801edfb0776a_c
[2011/09/06 10:35:41 | 000,161,736 | -H-- | C] () -- C:\Program Files\64res.dll
[2011/01/26 02:26:39 | 000,375,104 | -H-- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/10 20:21:12 | 000,000,056 | -H-- | C] () -- C:\windows\System32\ezsidmv.dat
[2010/07/19 22:36:49 | 000,000,000 | -H-- | C] () -- C:\windows\EEventManager.INI
[2008/10/04 19:34:54 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Katie Higgins\Application Data\wklnhst.dat
[2007/04/15 15:57:15 | 000,062,976 | -H-- | C] () -- C:\Documents and Settings\Katie Higgins\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/25 16:02:10 | 000,000,136 | -H-- | C] () -- C:\Documents and Settings\Katie Higgins\Local Settings\Application Data\fusioncache.dat
========== LOP Check ==========
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Administrator\Application Data\toshiba
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2010/07/18 21:24:09 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2011/09/28 16:55:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\FUJIFILM
[2010/01/29 12:34:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2010/01/29 12:33:29 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2011/10/28 14:45:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Mindjet
[2011/04/06 09:30:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2012/06/23 16:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/01/29 12:34:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoMail
[2010/04/23 12:59:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2009/10/26 18:12:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/03/22 13:02:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\SPSS
[2012/04/05 21:38:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2010/07/18 21:22:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2011/11/07 22:28:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Vodafone
[2011/07/17 16:27:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Default User\Application Data\toshiba
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Default User\Application Data\Windows Desktop Search
[2012/07/02 21:01:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Dropbox
[2011/01/14 14:11:03 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Epson
[2007/04/15 11:21:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\FUJIFILM
[2006/12/30 19:50:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\InterVideo
[2008/02/11 13:07:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Lexmark Imaging Studio
[2008/07/03 00:25:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\LimeWire
[2011/06/23 07:45:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\NCH Swift Sound
[2011/04/21 19:13:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\SPSSInc
[2009/07/21 12:55:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Template
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\toshiba
[2011/04/13 15:31:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\TP
[2011/11/07 22:29:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Vodafone
[2006/09/22 23:08:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Katie Higgins\Application Data\Windows Desktop Search
[2006/09/22 23:12:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\LocalService\Application Data\X10 Commander
[2012/07/11 21:23:04 | 000,000,256 | -H-- | M] () -- C:\windows\Tasks\Epson Printer Software Downloader.job
[2010/12/12 14:59:44 | 000,000,304 | -H-- | M] () -- C:\windows\Tasks\photostageSevenDays.job
[2010/12/15 14:59:02 | 000,000,304 | -H-- | M] () -- C:\windows\Tasks\photostageShakeIcon.job
[2006/12/25 16:01:03 | 000,000,258 | -H-- | M] () -- C:\windows\Tasks\Registration reminder 1.job
[2006/12/25 16:01:04 | 000,000,258 | -H-- | M] () -- C:\windows\Tasks\Registration reminder 3.job
========== Purity Check ==========
< End of report >
Farbar Service Scanner Version: 08-07-2012
Ran by Katie Higgins (administrator) on 17-07-2012 at 22:44:28
Running from "C:\Documents and Settings\Katie Higgins\Desktop"
Microsoft Windows XP Professional Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
File Check:
========
C:\windows\system32\dhcpcsvc.dll
[2006-09-13 13:41] - [2006-05-19 13:59] - 0111616 ___AH (Microsoft Corporation) EF545E1A4B043DA4C84E230DD471C55F
C:\windows\system32\Drivers\afd.sys
[2006-09-13 13:41] - [2008-08-14 10:51] - 0138368 ___AH (Microsoft Corporation) 55E6E1C51B6D30E54335750955453702
C:\windows\system32\Drivers\netbt.sys
[2006-09-13 13:42] - [2004-08-10 13:00] - 0162816 ___AH (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B
C:\windows\system32\Drivers\tcpip.sys
[2006-09-13 13:42] - [2008-06-20 11:45] - 0360320 ___AH (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9
C:\windows\system32\Drivers\ipsec.sys
[2006-09-13 13:42] - [2004-08-10 13:00] - 0074752 ___AH (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1
C:\windows\system32\dnsrslvr.dll
[2006-09-13 13:41] - [2008-02-20 06:32] - 0045568 ___AH (Microsoft Corporation) AAC8FFBFD61E784FA3BAC851D4A0BD5F
C:\windows\system32\ipnathlp.dll
[2006-09-13 13:42] - [2004-08-10 13:00] - 0331264 ___AH (Microsoft Corporation) 36CC8C01B5E50163037BEF56CB96DEFF
C:\windows\system32\netman.dll
[2006-09-13 13:42] - [2005-08-22 19:29] - 0197632 ___AH (Microsoft Corporation) 36739B39267914BA69AD0610A0299732
C:\windows\system32\wbem\WMIsvc.dll
[2006-09-13 14:54] - [2004-08-10 13:00] - 0144896 ___AH (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E
C:\windows\system32\srsvc.dll
[2006-09-13 14:57] - [2004-08-10 13:00] - 0170496 ___AH (Microsoft Corporation) 92BDF74F12D6CBEC43C94D4B7F804838
C:\windows\system32\Drivers\sr.sys
[2006-09-13 14:57] - [2004-08-10 13:00] - 0073472 __AHC (Microsoft Corporation) E41B6D037D6CD08461470AF04500DC24
C:\windows\system32\wscsvc.dll
[2006-09-13 13:42] - [2004-08-10 13:00] - 0081408 __AHC (Microsoft Corporation) 4D59DAA66C60858CDF4F67A900F42D4A
C:\windows\system32\wbem\WMIsvc.dll
[2006-09-13 14:54] - [2004-08-10 13:00] - 0144896 ___AH (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E
C:\windows\system32\wuauserv.dll
[2006-09-13 14:58] - [2004-08-10 13:00] - 0006656 ___AH (Microsoft Corporation) 13D72740963CBA12D9FF76A7F218BCD8
C:\windows\system32\qmgr.dll
[2006-09-13 14:58] - [2004-08-10 13:00] - 0382464 ___AH (Microsoft Corporation) 2C69EC7E5A311334D10DD95F338FCCEA
C:\windows\system32\es.dll
[2006-09-13 13:42] - [2008-07-07 21:06] - 0253952 ___AH (Microsoft Corporation) A4AB3DCA4A383F0DF4988ABDEB84F9A4
C:\windows\system32\cryptsvc.dll
[2006-09-13 13:41] - [2004-08-10 13:00] - 0060416 ___AH (Microsoft Corporation) 10654F9DDCEA9C46CFB77554231BE73B
C:\windows\system32\svchost.exe
[2006-09-13 13:42] - [2004-08-10 13:00] - 0014336 ___AH (Microsoft Corporation) 8F078AE4ED187AAABC0A305146DE6716
C:\windows\system32\rpcss.dll
[2006-09-13 13:42] - [2009-02-09 11:01] - 0401408 ___AH (Microsoft Corporation) 24B5D53B9ACCC1E2EDCF0A878D6659D4
C:\windows\system32\services.exe
[2006-09-13 13:42] - [2009-02-06 11:22] - 0110592 ___AH (Microsoft Corporation) 4712531AB7A01B7EE059853CA17D39BD
Extra List:
=======
AegisP(9) fssfltr(10) Gpc(6) IPSec(4) NetBT(5) PSched(7) s24trans(8) SYMTDI(12) Tcpip(3)
0x0C000000040000000100000002000000030000000C0000000B00000005000000060000000700000008000000090000000A000000
IpSec Tag value is correct.
**** End of log ****