OTL logfile created on: 9/2/2012 8:55:19 AM - Run 2
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\Mark Hritz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.73 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 71.09% Memory free
5.30 Gb Paging File | 4.46 Gb Available in Paging File | 84.21% Paging File free
Paging file location(s): C:\pagefile.sys 2791 4186 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 59.89 Gb Total Space | 21.32 Gb Free Space | 35.59% Space Free | Partition Type: NTFS
Drive E: | 93.11 Gb Total Space | 93.11 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive F: | 93.21 Gb Total Space | 93.21 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Computer Name: MARK-OSX | User Name: Mark Hritz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/08/31 08:16:12 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark Hritz\Desktop\OTL.exe
PRC - [2012/08/24 07:01:40 | 007,533,992 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version7\TeamViewer.exe
PRC - [2012/08/24 07:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012/08/24 07:01:40 | 002,282,920 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version7\TeamViewer_Desktop.exe
PRC - [2012/08/24 06:55:10 | 000,106,408 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\tv_w32.exe
PRC - [2012/08/17 18:28:57 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/07/13 07:15:56 | 000,037,152 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe
PRC - [2012/07/13 07:15:56 | 000,036,640 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe
PRC - [2012/07/13 06:57:41 | 000,140,064 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
PRC - [2012/07/12 10:56:20 | 000,136,616 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2012/07/12 10:55:48 | 000,374,184 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2012/04/27 12:12:45 | 006,065,784 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
PRC - [2012/03/26 17:24:06 | 000,354,768 | ---- | M] (Plantronics, Inc.) -- C:\Program Files\Plantronics\PlantronicsURE\PlantronicsBatteryStatus.exe
PRC - [2012/03/26 17:13:10 | 000,624,080 | ---- | M] (Plantronics, Inc.) -- C:\Program Files\Plantronics\PlantronicsURE\PlantronicsURE.exe
PRC - [2011/12/12 11:03:40 | 000,290,832 | ---- | M] (Verizon) -- C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
PRC - [2011/10/16 19:41:31 | 000,201,976 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe
PRC - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/06/26 13:09:18 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2010/05/21 13:40:24 | 001,406,320 | ---- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\agent.exe
PRC - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe
PRC - [2010/03/17 16:55:42 | 001,565,696 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Verizon\McciTrayApp.exe
PRC - [2010/03/04 13:00:56 | 000,025,704 | R--- | M] (Amazon.com) -- C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
PRC - [2009/11/15 01:40:46 | 000,427,296 | ---- | M] (Apple Inc.) -- C:\Program Files\Boot Camp\KbdMgr.exe
PRC - [2009/09/25 14:16:06 | 000,093,960 | ---- | M] (Sling Media Inc.) -- C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
PRC - [2009/09/16 17:33:46 | 000,972,064 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
PRC - [2009/09/16 16:22:08 | 000,020,480 | ---- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2008/09/12 15:19:16 | 000,099,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\system32\AppleTimeSrv.exe
PRC - [2008/09/12 15:19:14 | 000,136,496 | ---- | M] () -- C:\WINDOWS\system32\AppleOSSMgr.exe
PRC - [2008/09/12 15:09:57 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2008/08/11 13:41:00 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/05/02 03:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/05/02 03:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/07/16 12:58:02 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2006/06/22 14:15:48 | 000,462,848 | ---- | M] (Southwest Airlines) -- C:\Program Files\Southwest Airlines\Ding\Ding.exe
PRC - [2005/08/23 20:00:48 | 000,430,080 | ---- | M] (J. Eric Vaughan) -- C:\Program Files\Stay On Top\StayOnTop.exe
PRC - [2004/12/03 12:04:18 | 000,396,316 | ---- | M] (Naissan Innovations, LLC) -- C:\Program Files\AtomTime Pro\AtomTime.EXE
========== Modules (No Company Name) ========== MOD - [2012/06/14 03:30:11 | 000,346,624 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PlantronicsURE\2e6ec167c4b5840a9664b469f5be76b9\PlantronicsURE.ni.exe
MOD - [2012/06/14 03:30:03 | 000,131,072 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PlantronicsBatteryS#\350c07431b81c483d0d5c4574e7dd89f\PlantronicsBatteryStatus.ni.exe
MOD - [2012/06/14 03:29:59 | 000,128,000 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Skype\388596826e6ffe5efd8189db15bdd847\Plantronics.UC.Skype.ni.dll
MOD - [2012/06/14 03:29:28 | 000,490,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.Globali#\4717fc29cf79104a64c399d51f002e2e\Plantronics.Globalization.ni.dll
MOD - [2012/06/14 03:29:22 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012/06/14 03:29:19 | 011,817,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
MOD - [2012/06/14 03:29:07 | 000,516,608 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.Utility\48f8b0fa54af59727424fa578e625e0d\Plantronics.Utility.ni.dll
MOD - [2012/06/14 03:27:28 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:27:15 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012/06/14 03:23:22 | 000,069,120 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2012/06/14 03:14:56 | 000,054,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Webe#\c2b202f755140fc35e817470178e5e8d\Plantronics.UC.WebexConnect.ni.dll
MOD - [2012/06/14 03:13:48 | 000,112,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.Device.#\6d8add850f05e4c0114eee5acf9e4692\Plantronics.Device.Hid.ni.dll
MOD - [2012/06/14 03:13:46 | 000,582,144 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.Device.#\3506e6ecfd990b0db4a6d03da0f02469\Plantronics.Device.Common.ni.dll
MOD - [2012/06/14 03:13:26 | 001,840,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e70343406253e43964f9fe1f42cfbd7c\System.Web.Services.ni.dll
MOD - [2012/05/13 03:29:51 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll
MOD - [2012/05/13 03:29:15 | 000,220,672 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bb26dd100d656605c576881a1a823667\CustomMarshalers.ni.dll
MOD - [2012/05/13 03:28:26 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Wind#\087dffb5022baf107cabf67fc160cea3\Plantronics.UC.WindowsMediaPlayer.ni.dll
MOD - [2012/05/13 03:28:18 | 000,018,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Shor#\d89fd09cf90ccd3c5f51459976fcfe18\Plantronics.UC.ShoreTel.ni.dll
MOD - [2012/05/13 03:28:15 | 000,112,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Sess#\b7d3a8d703c168ad2c75d38e5a779fc4\Plantronics.UC.SessionService.ni.dll
MOD - [2012/05/13 03:28:13 | 000,031,232 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Rest#\e367f351f2903b3a5232499595db52af\Plantronics.UC.Rest.JsonpExtension.ni.dll
MOD - [2012/05/13 03:27:14 | 001,706,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll
MOD - [2012/05/13 03:27:10 | 000,299,520 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Rest\39db94387b79144b635f4e914fa519dd\Plantronics.UC.Rest.ni.dll
MOD - [2012/05/13 03:27:05 | 000,155,648 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Offi#\fcdf2e64b52f861ead68166aafe1c732\Plantronics.UC.OfficeCommunicator.ni.dll
MOD - [2012/05/13 03:27:01 | 000,102,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.SP30SDKLib\4f6988a093db3c3d1403c2574a3f9f92\Interop.SP30SDKLib.ni.dll
MOD - [2012/05/13 03:27:00 | 000,065,024 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.NEC\dd78b6340b96ef4e359e0f8e6c6fd967\Plantronics.UC.NEC.ni.dll
MOD - [2012/05/13 03:26:57 | 000,039,424 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.iTun#\f2e50e34930ab574a710455b74a96278\Plantronics.UC.iTunes.ni.dll
MOD - [2012/05/13 03:26:48 | 001,070,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e09496ddb2bf6f3b69707924f2e6b5ff\System.IdentityModel.ni.dll
MOD - [2012/05/13 03:26:45 | 002,345,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll
MOD - [2012/05/13 03:26:41 | 000,256,000 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll
MOD - [2012/05/13 03:26:37 | 017,403,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll
MOD - [2012/05/13 03:26:10 | 000,735,232 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.CSFC#\d5574220d32e4d800e81ddba2737813b\Plantronics.UC.CSFClient.ni.dll
MOD - [2012/05/13 03:26:08 | 000,139,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.CSF\21f3ffe05cee04b1383bf8ed2bed5294\Plantronics.UC.CSF.ni.dll
MOD - [2012/05/13 03:26:04 | 000,057,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Cisco\e7c0f4c824348e5b0f88f2470e4d0b5d\Plantronics.UC.Cisco.ni.dll
MOD - [2012/05/13 03:26:02 | 000,015,872 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avay#\5fd5d9e7e24beaa13283b982a5c175c9\Plantronics.UC.AvayaSoftphone.ni.dll
MOD - [2012/05/13 03:26:00 | 000,067,072 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.TAPI\901c5e284c4ec9dbe4a75c4674402d75\Plantronics.UC.TAPI.ni.dll
MOD - [2012/05/13 03:25:59 | 000,015,872 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avay#\3fc9f9f9d816cc85def3e32e12c73410\Plantronics.UC.AvayaIPAgent.ni.dll
MOD - [2012/05/13 03:25:55 | 000,368,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Comm#\2590fd62f3e166474680b424af4d0220\Plantronics.UC.Common.ni.dll
MOD - [2012/05/13 03:25:53 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avaya\2257d435dc1dcd01888577478ddd97f4\Plantronics.UC.Avaya.ni.dll
MOD - [2012/05/13 03:25:49 | 000,111,616 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.License#\c1d4ceabd2c641c102905e8ece1a2391\Plantronics.License.Manager.ni.dll
MOD - [2012/05/13 03:25:43 | 000,056,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.License#\b8aa36668909c37ed79559006d59b7af\Plantronics.License.Common.ni.dll
MOD - [2012/05/13 03:25:41 | 000,076,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.FlexNet#\37d21c41c9bce51ac956a4a4347d9c3a\Plantronics.FlexNet.Adapter.ni.dll
MOD - [2012/05/13 03:25:34 | 000,078,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Util#\5fa58996878ab9421e79758ffdb59ef8\Plantronics.UC.Utility.ni.dll
MOD - [2012/05/13 03:25:07 | 000,035,840 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Plantronics.Config\299815298c225dcf520401b8f95ffc83\Plantronics.Config.ni.dll
MOD - [2012/05/13 03:24:28 | 000,696,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\log4net\cb360d948d3a415eed4a9924b14c98e5\log4net.ni.dll
MOD - [2012/05/13 03:21:42 | 000,414,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.SKYPE4COMLib\472a3c289a92db348fa8f7779d14738d\Interop.SKYPE4COMLib.ni.dll
MOD - [2012/05/13 03:21:32 | 000,214,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.FNCClient11#\69e282a3bf754cf69500be1a4d8380ca\Interop.FNCClient11Lib.ni.dll
MOD - [2012/05/13 03:21:29 | 000,144,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.Communicato#\c23505b38b9959f90a8580dd9dc1218d\Interop.CommunicatorAPI.ni.dll
MOD - [2012/05/13 03:21:26 | 000,056,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.CiscoInterf#\1e39163c67bd28bc84e9b41c76a0e73c\Interop.CiscoInterface.ni.dll
MOD - [2012/05/13 03:20:38 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012/05/13 03:20:34 | 000,440,832 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Atapi\ea18a74f1ed9daf4ffbf5ea32fd4f79f\Atapi.ni.dll
MOD - [2012/05/13 03:18:53 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012/05/13 03:17:29 | 002,295,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll
MOD - [2012/05/13 03:15:40 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/13 03:15:18 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/10/16 19:41:31 | 000,201,976 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe
MOD - [2010/03/04 13:01:02 | 000,097,384 | R--- | M] () -- C:\Program Files\Amazon\Amazon Unbox Video\LimelightDownloadManager.dll
MOD - [2009/08/08 21:55:01 | 000,507,904 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll
MOD - [2008/09/12 15:19:14 | 000,136,496 | ---- | M] () -- C:\WINDOWS\system32\AppleOSSMgr.exe
MOD - [2008/04/13 20:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 20:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2007/07/16 12:58:10 | 000,197,408 | ---- | M] () -- C:\WINDOWS\system32\vpnapi.dll
MOD - [2001/07/31 11:17:12 | 000,094,274 | ---- | M] () -- C:\WINDOWS\system32\HPBHEALR.DLL
========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (STSService)
SRV - [2012/08/27 20:35:22 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/08/24 07:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/08/23 16:37:31 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/13 07:15:56 | 000,036,640 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe -- (PSUAService)
SRV - [2012/07/13 06:57:41 | 000,140,064 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe -- (NanoServiceMain)
SRV - [2012/07/12 10:56:20 | 000,136,616 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\ramaint.exe -- (LMIMaint)
SRV - [2012/07/12 10:55:48 | 000,374,184 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011/12/12 11:03:40 | 000,290,832 | ---- | M] (Verizon) [Auto | Running] -- C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe -- (IHA_MessageCenter)
SRV - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010/03/04 13:00:56 | 000,025,704 | R--- | M] (Amazon.com) [Auto | Running] -- C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe -- (ADVService)
SRV - [2009/09/25 14:16:06 | 000,093,960 | ---- | M] (Sling Media Inc.) [Auto | Running] -- C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe -- (SlingAgentService)
SRV - [2009/09/16 16:22:08 | 000,020,480 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2008/09/12 15:19:16 | 000,099,632 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\WINDOWS\system32\AppleTimeSrv.exe -- (AppleTimeSrv)
SRV - [2008/09/12 15:19:14 | 000,136,496 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\AppleOSSMgr.exe -- (AppleOSSMgr)
SRV - [2008/05/02 03:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007/07/16 12:58:02 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2007/05/24 07:08:44 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2006/01/05 00:06:02 | 000,163,840 | ---- | M] (Alex Feinman) [On_Demand | Stopped] -- C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe -- (Imapi Helper)
SRV - [2003/10/22 11:19:22 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/07/13 07:02:48 | 000,120,616 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProt.sys -- (PSINProt)
DRV - [2012/07/13 07:02:47 | 000,179,112 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PSINKNC.sys -- (PSINKNC)
DRV - [2012/07/13 07:02:47 | 000,114,728 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProc.sys -- (PSINProc)
DRV - [2012/07/13 07:02:47 | 000,101,544 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINFile.sys -- (PSINFile)
DRV - [2012/07/13 07:02:46 | 000,149,032 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINAflt.sys -- (PSINAflt)
DRV - [2012/07/12 11:18:32 | 000,206,632 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSStrm.sys -- (NNSSTRM)
DRV - [2012/07/12 10:55:53 | 000,083,392 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/06/27 15:51:07 | 000,092,840 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNStlsc.sys -- (NNSTLSC)
DRV - [2012/06/27 15:51:06 | 000,286,376 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSProt.sys -- (NNSPROT)
DRV - [2012/06/27 15:51:06 | 000,153,000 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSPrv.sys -- (NNSPRV)
DRV - [2012/06/27 15:51:06 | 000,106,536 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSSmtp.sys -- (NNSSMTP)
DRV - [2012/06/27 15:51:05 | 000,104,104 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSPop3.sys -- (NNSPOP3)
DRV - [2012/06/27 15:51:05 | 000,051,496 | ---- | M] (Panda Security, S.L.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\NNSpihs.sys -- (NNSPIHS)
DRV - [2012/06/27 15:51:04 | 000,122,664 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSIds.sys -- (NNSIDS)
DRV - [2012/06/27 15:51:04 | 000,093,992 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSpicc.sys -- (NNSPICC)
DRV - [2012/06/27 15:51:03 | 000,120,744 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSHttp.sys -- (NNSHTTP)
DRV - [2012/06/27 15:51:03 | 000,082,472 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSAlpc.sys -- (NNSALPC)
DRV - [2012/03/26 19:42:10 | 000,121,080 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/09/09 13:54:48 | 000,038,536 | ---- | M] (Panda Security, S.L.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NNSNAHS.sys -- (NNSNAHS)
DRV - [2011/03/10 18:04:57 | 000,046,280 | ---- | M] (Panda Security) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\PSKMAD.sys -- (PSKMAD)
DRV - [2010/03/17 16:53:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/01/28 15:40:06 | 000,033,336 | ---- | M] (M2Tech) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vadspdif.sys -- (vadspdif)
DRV - [2009/11/15 01:40:46 | 000,005,760 | ---- | M] (Apple Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\KeyAgent.sys -- (KeyAgent)
DRV - [2009/10/16 09:36:53 | 000,029,696 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\applemtp.sys -- (applemtp)
DRV - [2009/10/16 09:36:53 | 000,010,496 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\applemtm.sys -- (applemtm)
DRV - [2009/10/16 09:36:50 | 000,023,552 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KeyMagic.sys -- (KeyMagic)
DRV - [2009/08/27 15:52:48 | 000,003,768 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SndTVideo.sys -- (SndTVideo)
DRV - [2009/08/27 15:52:44 | 000,023,096 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SndTAudio.sys -- (SndTAudio)
DRV - [2008/09/12 15:09:56 | 004,751,360 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008/09/12 15:08:50 | 000,013,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/09/12 15:08:41 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/09/12 15:08:39 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/09/12 15:06:23 | 001,287,552 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2008/09/12 15:04:30 | 000,016,512 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IRFilter.sys -- (IRRemoteFlt)
DRV - [2008/09/12 15:03:30 | 000,006,784 | ---- | M] (Apple Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\MacHALDriver.sys -- (MacHALDriver)
DRV - [2008/08/11 13:41:00 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/08/11 13:41:00 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2008/04/13 14:46:31 | 000,036,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bthprint.sys -- (BTHprint)
DRV - [2008/02/29 04:13:46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2008/02/29 04:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008/02/29 04:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/07/19 09:35:20 | 000,028,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\V-usbser.sys -- (usbser)
DRV - [2007/07/16 12:57:12 | 000,306,299 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2007/07/03 19:59:10 | 000,086,824 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdserd.sys -- (sscdserd)
DRV - [2007/07/03 19:58:20 | 000,106,792 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2007/07/03 19:57:24 | 000,011,944 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2007/07/03 19:54:24 | 000,080,552 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2007/01/31 14:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2007/01/18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2006/09/28 15:32:14 | 000,009,472 | ---- | M] (June Fabrics Technology) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pnetmdm.sys -- (pnetmdm)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?} IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1343024091-789336058-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.comodo.com/search/IE - HKU\S-1-5-21-1343024091-789336058-725345543-1003\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No CLSID value found
IE - HKU\S-1-5-21-1343024091-789336058-725345543-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1343024091-789336058-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1343024091-789336058-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: """
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems:
[email protected]:7
FF - prefs.js..extensions.enabledItems: {9EB34849-81D3-4841-939D-666D522B889A}:1.5.1.119
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.11.2.1
FF - prefs.js..extensions.enabledItems: {70a9aa80-d283-4eae-8a87-ee7b769edf53}:1.0
FF - prefs.js..extensions.enabledItems: FFToolbar@upromise:7.0.2.4181
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.3.3.2
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550
FF - prefs.js..keyword.URL: "
http://us.yhs.search...2-tb-web_us&p="FF - prefs.js..network.proxy.http: ""
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.socks: ""
FF - prefs.js..network.proxy.socks_port: ""
FF - prefs.js..network.proxy.socks_remote_dns: ""
FF - prefs.js..network.proxy.ssl: ""
FF - prefs.js..network.proxy.ssl_port: ""
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Mark Hritz\Application Data\Move Networks\plugins\npqmp071502000008.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Mark Hritz\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Mark Hritz\Application Data\Move Networks\plugins\npqmp071502000008.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\mattelinc.com/HotWheelsLoader: C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\sswat_hwrc_win_live\npHotWheelsLoader.dll (Mattel, Inc)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/02 08:31:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/02 08:31:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/08/30 15:04:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Documents and Settings\Mark Hritz\Application Data\Move Networks [2010/02/25 10:55:17 | 000,000,000 | ---D | M]
[2010/02/15 02:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Extensions
[2010/02/15 02:24:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/09/02 08:31:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions
[2010/04/27 15:38:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/04 03:16:27 | 000,000,000 | ---D | M] (Page Speed Closure Compiler Extension) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\{70a9aa80-d283-4eae-8a87-ee7b769edf53}
[2012/07/05 14:39:57 | 000,000,000 | ---D | M] (WebSlingPlayer) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\{9EB34849-81D3-4841-939D-666D522B889A}
[2010/04/27 15:38:46 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2012/08/27 23:20:27 | 000,000,000 | ---D | M] (Page Speed) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/05/27 15:25:42 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Documents and Settings\Mark Hritz\Application Data\Mozilla\Firefox\Profiles\pyglmphs.default\extensions\
[email protected][2012/08/23 16:37:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/08/23 16:37:11 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/08/23 16:37:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/08/30 20:13:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\updated\extensions
[2012/08/30 20:13:17 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\updated\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/08/30 20:13:38 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\updated\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/08/30 20:13:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\updated\distribution\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MARK HRITZ\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PYGLMPHS.DEFAULT\EXTENSIONS\{1392B8D2-5C05-419F-A8F6-B9F15A596612}
[2011/09/21 09:24:25 | 000,455,818 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\MARK HRITZ\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PYGLMPHS.DEFAULT\EXTENSIONS\
[email protected][2012/03/24 11:50:19 | 001,184,804 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\MARK HRITZ\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PYGLMPHS.DEFAULT\EXTENSIONS\
[email protected][2012/08/23 16:37:35 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/07/28 12:07:36 | 000,069,632 | ---- | M] (UPS) -- C:\Program Files\mozilla firefox\plugins\NPEltr32.dll
[2012/07/21 10:43:28 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/21 10:43:28 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ========== CHR - homepage:
http://www.google.com/CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage:
http://www.google.com/CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: UPS Thermal 2442 Printer Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPEltr32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Mark Hritz\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\Mark Hritz\Application Data\Move Networks\plugins\npqmp071502000008.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: HotWheels Loader (Enabled) = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\sswat_hwrc_win_live\npHotWheelsLoader.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: Java Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Google Drive = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: YouTube = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: MightyText - Send/Receive SMS Text Messages = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dkfhfaphfkopdgpbfkebjfcblcafcmpi\7.7_0\
CHR - Extension: Google Calendar = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Games = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fobcpibfeplaikcclojfdhfdmbbeofai\1.1_0\
CHR - Extension: Chrome Remote Desktop BETA = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp\1.6.1180.51_0\
CHR - Extension: Music = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hgakehlldcacnfhjampnkihibmkgclhk\1.1_0\
CHR - Extension: Keep My Opt-Outs = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hhnjdplhmcnkiecampfdgfjilccfpfoe\1.0.14_0\
CHR - Extension: Google Talk Launcher = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icjglmbkgdgdgdigllcokdabceikdppi\1.0.6_0\
CHR - Extension: Twitter Notifier = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ikknnkomiokeodcdkknnhgjmncfiefmn\4.1.1_0\
CHR - Extension: Calculator = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao\1.0.9_0\
CHR - Extension: Scratchpad = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kjebfhglflhjjjiceimfkgicifkhjlnm\3.0.17_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\
CHR - Extension: Gmail = C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/01 21:50:24 | 000,443,130 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15227 more lines...
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [Apple_KbdMgr] C:\Program Files\Boot Camp\KbdMgr.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AtomTime] C:\Program Files\AtomTime Pro\AtomTime.EXE (Naissan Innovations, LLC)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PlantronicsBatteryStatus.exe] C:\Program Files\Plantronics\PlantronicsURE\PlantronicsBatteryStatus.exe (Plantronics, Inc.)
O4 - HKLM..\Run: [PlantronicsURE.exe] C:\Program Files\Plantronics\PlantronicsURE\PlantronicsURE.exe (Plantronics, Inc.)
O4 - HKLM..\Run: [PSUAMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKU\S-1-5-21-1343024091-789336058-725345543-1003..\Run: [699D660B7DDCBEB8C5A6CACA73D2DF4CFFD1BE20._service_run] C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKU\S-1-5-21-1343024091-789336058-725345543-1003..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKU\S-1-5-21-1343024091-789336058-725345543-1003..\Run: [Mattel HWRC Launcher] C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Startup\DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
O4 - Startup: C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Startup\PC Sleep.lnk = C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Installer\{FBAFC5DB-5511-4150-91EC-995E9BB2D099}\_4ae13d6c.exe ()
O4 - Startup: C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Startup\Stay On Top.lnk = C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Installer\{5C6C0192-BA75-4932-8931-B2FF88346E49}\_16dd6dc4.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1343024091-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1343024091-789336058-725345543-1003\..Trusted Domains: internet ([]about in Internet)
O15 - HKU\S-1-5-21-1343024091-789336058-725345543-1003\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1343024091-789336058-725345543-1003\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
https://activatemywi...i Installer.cab (Support.com Configuration Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1229476777125 (MUWebControl Class)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}
http://lads.myspace....ceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549}
http://plugin.slingb...SlingPlayer.cab (WebSlingPlayer)
O16 - DPF: {F4D10716-6F96-48E9-8A08-7E3AD71054AD}
https://qbo.intuit.c...11/qboimax9.cab (QuickBooks Online Edition Import Utilities Class v9)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA964EDF-1DAC-47D6-B8D4-6694DCA78CE8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA964EDF-1DAC-47D6-B8D4-6694DCA78CE8}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E745A1FC-2A42-4461-AAFC-5100B3C8391D}: NameServer = 192.168.1.1,208.67.222.222
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: <Company name>)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logitech\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/17 01:18:59 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ========== [2012/09/02 08:49:34 | 010,651,696 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark Hritz\Desktop\mbam-consumer.exe
[2012/09/02 08:41:41 | 000,046,280 | ---- | C] (Panda Security) -- C:\WINDOWS\System32\drivers\PSKMAD.sys
[2012/09/02 07:52:01 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/01 08:39:16 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mark Hritz\Desktop\tdsskiller.exe
[2012/08/31 08:21:24 | 001,973,368 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Mark Hritz\Desktop\avg_remover_stf_x86_2012_2125.exe
[2012/08/31 08:16:20 | 000,598,528 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mark Hritz\Desktop\OTL.exe
[2012/08/30 09:35:57 | 000,000,000 | ---D | C] -- C:\Envelope Manager
[2012/08/29 17:33:58 | 298,569,104 | ---- | C] (Intuit, Inc. ) -- C:\Documents and Settings\Mark Hritz\Desktop\QuickBooksPro2008.exe
[2012/08/29 17:33:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Application Data\Download Manager
[2012/08/29 13:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AnswerWorks 5.0
[2012/08/29 13:26:26 | 004,200,024 | ---- | C] (Amyuni Technologies
http://www.amyuni.com) -- C:\WINDOWS\System32\cdintf400.dll
[2012/08/29 13:26:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Quicken 2012
[2012/08/29 13:11:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Desktop\Quicken
[2012/08/29 13:08:08 | 101,538,008 | ---- | C] (Intuit Inc. ) -- C:\Documents and Settings\Mark Hritz\My Documents\Quicken_Deluxe_2012.exe
[2012/08/28 09:06:42 | 000,000,000 | ---D | C] -- C:\endicia bu
[2012/08/27 20:51:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Desktop\backup
[2012/08/23 16:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/08/22 18:25:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Desktop\Music
[2012/08/22 18:25:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Desktop\Files from work
[2012/08/22 18:12:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Desktop\misc files
[2012/08/22 08:12:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Google Chrome
[2012/08/03 09:38:41 | 018,376,624 | ---- | C] (Mooii) -- C:\Documents and Settings\Mark Hritz\Desktop\PhotoScape_V3.6.2.exe
[2010/10/06 00:41:57 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Mark Hritz\Application Data\pcouffin.sys
========== Files - Modified Within 30 Days ========== [2012/09/02 08:48:49 | 001,376,768 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\RogueKiller.exe
[2012/09/02 08:43:40 | 000,002,351 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Startup\Stay On Top.lnk
[2012/09/02 08:43:38 | 000,002,355 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Start Menu\Programs\Startup\PC Sleep.lnk
[2012/09/02 08:42:41 | 000,190,797 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/09/02 08:42:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/02 08:38:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/09/02 08:32:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/02 08:26:51 | 010,651,696 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark Hritz\Desktop\mbam-consumer.exe
[2012/09/02 08:21:02 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-789336058-725345543-1003UA.job
[2012/09/02 08:21:00 | 000,000,946 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-789336058-725345543-1003Core.job
[2012/09/01 08:49:30 | 000,511,265 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\adwcleaner.exe
[2012/09/01 08:38:34 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mark Hritz\Desktop\tdsskiller.exe
[2012/08/31 08:28:46 | 000,182,632 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/31 08:21:13 | 001,973,368 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Mark Hritz\Desktop\avg_remover_stf_x86_2012_2125.exe
[2012/08/31 08:16:12 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark Hritz\Desktop\OTL.exe
[2012/08/30 22:38:15 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\MBR.dat
[2012/08/30 22:10:00 | 000,011,385 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\gsview32.ini
[2012/08/30 22:08:57 | 000,011,998 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\102-2144650-6802617.pdf
[2012/08/30 16:12:52 | 000,702,933 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\Label-240879312-361497992.pdf
[2012/08/30 15:04:49 | 000,001,694 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/08/30 15:04:48 | 000,001,676 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[2012/08/30 14:18:29 | 000,002,117 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/08/30 14:18:29 | 000,001,844 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Pro 2008.lnk
[2012/08/30 11:37:52 | 000,000,776 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\orders.rtf
[2012/08/30 08:56:42 | 000,000,446 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\qbregistration.dat
[2012/08/29 17:49:11 | 000,000,396 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\alphanet.qbw.nd
[2012/08/29 17:34:49 | 298,569,104 | ---- | M] (Intuit, Inc. ) -- C:\Documents and Settings\Mark Hritz\Desktop\QuickBooksPro2008.exe
[2012/08/29 17:31:30 | 000,559,800 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\Setup_QuickBooksPro2008.exe
[2012/08/29 13:26:19 | 000,001,577 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Quicken Deluxe 2012.lnk
[2012/08/29 13:26:10 | 000,000,165 | ---- | M] () -- C:\WINDOWS\Quicken.ini
[2012/08/29 13:08:25 | 101,538,008 | ---- | M] (Intuit Inc. ) -- C:\Documents and Settings\Mark Hritz\My Documents\Quicken_Deluxe_2012.exe
[2012/08/28 11:44:40 | 000,012,364 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\FAX_20120828_1346166317_4.efx
[2012/08/28 10:13:12 | 000,049,404 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\waffle_vodka.jpg
[2012/08/28 09:12:10 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DYMO Printable Postage.lnk
[2012/08/27 20:35:21 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/08/27 20:35:20 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/08/27 19:31:09 | 113,967,104 | R--- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\alphanet.qbw
[2012/08/27 08:24:08 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/08/23 21:55:14 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\Firefox Recovery Key.html
[2012/08/23 10:34:48 | 000,189,257 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\screenshot.jpg
[2012/08/23 10:34:23 | 000,015,360 | -H-- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\photothumb.db
[2012/08/22 10:16:04 | 000,058,526 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\2012-32.pdf
[2012/08/22 10:14:01 | 000,007,572 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\PamFax.pdf
[2012/08/22 08:13:03 | 000,002,331 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\Google Chrome.lnk
[2012/08/22 08:13:03 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/21 22:47:20 | 000,000,437 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\My Documents\shipping label template.rtf
[2012/08/21 10:19:15 | 000,037,510 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\EMS 8-25.PDF
[2012/08/17 13:01:20 | 000,137,391 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\My Documents\fax page
[2012/08/16 12:04:14 | 000,037,248 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\EXPRESS 8-18.PDF
[2012/08/14 22:03:53 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/08/03 09:42:20 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/03 09:42:20 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\Mark Hritz\Desktop\PhotoScape.lnk
[2012/08/03 09:38:50 | 018,376,624 | ---- | M] (Mooii) -- C:\Documents and Settings\Mark Hritz\Desktop\PhotoScape_V3.6.2.exe
========== Files Created - No Company Name ========== [2012/09/02 08:52:47 | 001,376,768 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\RogueKiller.exe
[2012/09/01 08:51:14 | 000,511,265 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\adwcleaner.exe
[2012/08/30 22:08:56 | 000,011,998 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\102-2144650-6802617.pdf
[2012/08/30 21:55:56 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\MBR.dat
[2012/08/30 16:12:49 | 000,702,933 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\Label-240879312-361497992.pdf
[2012/08/30 14:24:12 | 000,062,752 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\qbmapilibrary.dll
[2012/08/30 11:37:50 | 000,000,776 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\orders.rtf
[2012/08/30 09:27:38 | 000,001,844 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Pro 2008.lnk
[2012/08/30 08:56:42 | 000,000,446 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\qbregistration.dat
[2012/08/29 17:36:13 | 000,000,396 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\alphanet.qbw.nd
[2012/08/29 17:36:12 | 113,967,104 | R--- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\alphanet.qbw
[2012/08/29 17:33:16 | 000,559,800 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\Setup_QuickBooksPro2008.exe
[2012/08/29 13:26:19 | 000,001,577 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Quicken Deluxe 2012.lnk
[2012/08/28 11:44:43 | 000,012,364 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\FAX_20120828_1346166317_4.efx
[2012/08/28 10:13:16 | 000,049,404 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\waffle_vodka.jpg
[2012/08/28 09:12:10 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DYMO Printable Postage.lnk
[2012/08/23 21:55:03 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\Firefox Recovery Key.html
[2012/08/23 10:34:48 | 000,189,257 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\screenshot.jpg
[2012/08/22 18:25:02 | 000,052,304 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\ups forms.efx
[2012/08/22 10:16:03 | 000,058,526 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\2012-32.pdf
[2012/08/22 08:13:03 | 000,002,331 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\Google Chrome.lnk
[2012/08/22 08:13:03 | 000,002,309 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/22 08:11:33 | 000,000,998 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-789336058-725345543-1003UA.job
[2012/08/22 08:11:31 | 000,000,946 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-789336058-725345543-1003Core.job
[2012/08/21 10:19:14 | 000,037,510 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\EMS 8-25.PDF
[2012/08/17 13:01:20 | 000,137,391 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\My Documents\fax page
[2012/08/16 12:04:11 | 000,037,248 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Desktop\EXPRESS 8-18.PDF
[2012/07/27 10:07:11 | 000,007,572 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\PamFax.pdf
[2012/06/04 14:42:59 | 000,021,682 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\info
[2012/05/07 10:29:03 | 000,023,966 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\email
[2012/02/14 19:28:28 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/08/11 10:18:41 | 000,142,359 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\102-0229827-3240243
[2011/05/11 12:01:24 | 000,006,272 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\NanoRepository.bin
[2011/04/20 14:23:09 | 000,020,836 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\details
[2011/04/12 18:28:25 | 000,000,227 | ---- | C] () -- C:\WINDOWS\DAZZLE.INI
[2011/02/01 15:59:36 | 000,103,016 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\fedex.com
[2010/10/06 00:41:57 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Application Data\inst.exe
[2010/10/06 00:41:57 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Application Data\pcouffin.cat
[2010/10/06 00:41:57 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Application Data\pcouffin.inf
[2010/10/05 16:47:30 | 000,000,125 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/05/22 01:11:23 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\.recently-used.xbel
[2010/01/05 08:51:26 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\prvlcl.dat
[2009/02/25 01:56:20 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Application Data\$_hpcst$.hpc
[2009/01/12 12:39:21 | 000,011,385 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\gsview32.ini
[2009/01/08 03:07:23 | 000,073,728 | ---- | C] () -- C:\Documents and Settings\Mark Hritz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2010/03/06 19:35:51 | 001,084,873 | ---- | M] (non) -- C:\AAGPS Driver-Windows.exe
[2010/03/06 19:35:53 | 000,286,720 | ---- | M] () -- C:\AAGPS Update 34_5.exe
< MD5 for: EXPLORER.EXE >[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: QMGR.DLL >[2004/08/04 08:00:00 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll
[2008/04/13 20:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ServicePackFiles\i386\qmgr.dll
[2008/04/13 20:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\bits\qmgr.dll
[2008/04/13 20:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll
[2004/08/04 08:00:00 | 000,382,464 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Documents and Settings\Mark Hritz\Local Settings\Temp\qmgr.dll
< MD5 for: SERVICES >[2004/08/04 08:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >[2012/07/27 16:51:34 | 000,586,083 | ---- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.CSS >[2005/06/29 14:48:58 | 000,014,339 | ---- | M] () MD5=9D415BDEF74ADF7B0CD791E40A911A38 -- C:\Program Files\Intuit\QuickBooks 2008\Components\Services\services.css
[2012/04/18 18:06:44 | 000,000,093 | ---- | M] () MD5=F15FB82C578490B209442B8C1D5076CC -- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
< MD5 for: SERVICES.EXE >[2009/02/06 07:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/04 08:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SERVICES.HTML >[2008/04/16 12:29:04 | 000,004,166 | ---- | M] () MD5=DB0CABD236311DDEB186C9B8A13F39A6 -- C:\Program Files\BillP Studios\WinPatrol\services.html
< MD5 for: SERVICES.INI >[2012/04/18 18:06:44 | 000,000,012 | ---- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 -- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
< MD5 for: SERVICES.LNK >[2008/12/17 01:19:06 | 000,001,602 | ---- | M] () MD5=3F489F178343080741F81CEF9F648F3A -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >[2004/08/04 08:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.SBS >[2011/03/01 09:58:46 | 000,034,818 | ---- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B -- C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SVCHOST.EXE >[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004/08/04 08:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >[2004/08/04 08:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004/08/04 08:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s >"Type" = 32
"Start" = 3
"ErrorControl" = 1
"ImagePath" = %SystemRoot%\system32\svchost.exe -k netsvcs -- [2008/04/13 20:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation)
"DisplayName" = Background Intelligent Transfer Service
"DependOnService" = Rpcss [binary data] -- [2009/02/09 08:10:48 | 000,401,408 | ---- | M] (Microsoft Corporation)
"DependOnGroup" = [binary data]
"ObjectName" = LocalSystem
"Description" = Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled.
"FailureActions" = 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 68 E3 0C 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll" = C:\WINDOWS\system32\qmgr.dll -- [2008/04/13 20:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security" = [Binary data over 100 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Enum]
"0" = Root\LEGACY_BITS\0000
"Count" = 1
"NextInstance" = 1
< HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Local\AutoProxyCache /s > < %systemdrive%\$Recycle.Bin|@;true;true;true > < C:\Program Files\Common Files\ComObjects\*.* /s > ========== Drive Information ========== Physical Drives
---------------
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: Hitachi HTS543232L9SA02
Partitions: 4
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - Fixed\thard disk media
Interface type: 1394
Media Type: Fixed\thard disk media
Model: LaCie d2 quadra IEEE 1394 SBP2 Device
Partitions: 4
Status: OK
Status Info: 0
Partitions
---------------
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 512
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 237.00GB
Starting Offset: 209735680
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 1.00GB
Starting Offset: 255111311360
Hidden sectors: 0
DeviceID: Disk #0, Partition #3
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 60.00GB
Starting Offset: 255761317888
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 512
Hidden sectors: 0
DeviceID: Disk #1, Partition #1
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 93.00GB
Starting Offset: 210763776
Hidden sectors: 0
DeviceID: Disk #1, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 93.00GB
Starting Offset: 100210311168
Hidden sectors: 0
DeviceID: Disk #1, Partition #3
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 279.00GB
Starting Offset: 200317861888
Hidden sectors: 0
< type c:\diskreport.txt /c >Microsoft DiskPart version 5.1.3565
Copyright © 1999-2003 Microsoft Corporation.
On computer: MARK-OSX
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
Volume 0 D DVD-ROM 0 B
Volume 1 C BOOTCAMP NTFS Partition 60 GB Healthy Boot
Volume 2 E LACIE_WIN_1 FAT32 Partition 93 GB Healthy
Volume 3 F LACIE_WIN_2 FAT32 Partition 93 GB Healthy
========== Alternate Data Streams ========== @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >