Hello
I did the Fix and have the reports. I still have the Unidentified network and no internet. There is an odd message in the Fix report about "media disconnected", so not sure what that means. I can see that my computer is connected to the router as the light is lit in the terminal the ethernet connects to.
Thanks for you help
FIXAll processes killed
========== COMMANDS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\S-1-5-21-1885834091-318630671-1701898132-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-1885834091-318630671-1701898132-1005\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c
>Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Michael Grantham\Desktop\cmd.bat deleted successfully.
C:\Users\Michael Grantham\Desktop\cmd.txt deleted successfully.
< netsh winsock reset /c
>Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
C:\Users\Michael Grantham\Desktop\cmd.bat deleted successfully.
C:\Users\Michael Grantham\Desktop\cmd.txt deleted successfully.
< ipconfig /release /c
>Windows IP Configuration
No operation can be performed on Local Area Connection* 14 while it has its media disconnected.
No operation can be performed on Local Area Connection 2 while it has its media disconnected.
An error occurred while releasing interface Local Area Connection : An address has not yet been associated with the network endpoint.
C:\Users\Michael Grantham\Desktop\cmd.bat deleted successfully.
C:\Users\Michael Grantham\Desktop\cmd.txt deleted successfully.
< ipconfig /renew /c
>Windows IP Configuration
No operation can be performed on Local Area Connection* 14 while it has its media disconnected.
No operation can be performed on Local Area Connection 2 while it has its media disconnected.
An error occurred while renewing interface Local Area Connection : The support for the specified socket type does not exist in this address family.
C:\Users\Michael Grantham\Desktop\cmd.bat deleted successfully.
C:\Users\Michael Grantham\Desktop\cmd.txt deleted successfully.
< ipconfig /all /c >Windows IP Configuration
Host Name . . . . . . . . . . . . : Dell
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection* 14:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Juniper Network Connect Virtual Adapter
Physical Address. . . . . . . . . : 00-FF-98-0C-91-86
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Local Area Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : TAP-Win32 Adapter V9
Physical Address. . . . . . . . . : 00-FF-AD-99-9C-EE
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel® 82562V 10/100 Network Connection
Physical Address. . . . . . . . . : 00-21-9B-0D-C0-7D
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::2921:2eb3:6b79:8a04%9(Preferred)
Autoconfiguration IPv4 Address. . : 169.254.138.4(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 234889627
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-10-14-0E-00-21-9B-0D-C0-7D
DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection*:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{44C90F80-ABBA-45E7-ADA7-34981579C325}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 10:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{803BEDED-0604-417D-B848-9279D71B5F88}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 13:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{AD999CEE-11E4-46A7-85EB-AC99863B35DB}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
C:\Users\Michael Grantham\Desktop\cmd.bat deleted successfully.
C:\Users\Michael Grantham\Desktop\cmd.txt deleted successfully.
File\Folder :Commands not found.
File\Folder [emptytemp] not found.
File\Folder [Reboot] not found.
OTL by OldTimer - Version 3.2.61.3 log created on 09302012_114814
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
OTL SCAN
OTL logfile created on: 09/30/2012 11:55:22 AM - Run 6
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Michael Grantham\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19298)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy
3.24 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 70.94% Memory free
6.67 Gb Paging File | 5.82 Gb Available in Paging File | 87.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.03 Gb Total Space | 168.38 Gb Free Space | 56.50% Space Free | Partition Type: NTFS
Drive E: | 3.73 Gb Total Space | 3.46 Gb Free Space | 92.86% Space Free | Partition Type: NTFS
Computer Name: DELL | User Name: Michael Grantham | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/09/13 14:40:32 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Michael Grantham\Desktop\OTL.exe
PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/07/12 15:39:35 | 000,186,832 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/04/09 07:59:46 | 000,670,792 | ---- | M] (Juniper Networks) -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
PRC - [2012/02/23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
PRC - [2011/08/25 18:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2011/07/19 08:58:49 | 000,163,664 | R--- | M] (Storage Appliance Corporation) -- C:\ProgramData\OfficeGuardianV2N35\Reminder\SacNetAgent.exe
PRC - [2011/07/19 08:58:49 | 000,083,792 | R--- | M] (Storage Appliance Corp.) -- C:\ProgramData\OfficeGuardianV2N35\UACProxy.exe
PRC - [2011/03/25 22:32:40 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/11/11 13:31:54 | 000,334,448 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnetdhcp.exe
PRC - [2010/11/11 13:31:50 | 000,404,080 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnat.exe
PRC - [2010/11/11 13:31:36 | 000,064,112 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\hqtray.exe
PRC - [2010/11/11 12:31:44 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2010/07/21 20:17:20 | 000,069,632 | ---- | M] () -- C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe
PRC - [2009/05/21 12:14:02 | 001,025,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\gs_agent\dsc.exe
PRC - [2009/05/21 12:13:58 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 01:28:15 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/02/25 19:06:42 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/14 01:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTSrv.exe
PRC - [2007/05/23 21:02:36 | 000,139,264 | ---- | M] (Primax Electronics Ltd.) -- C:\Windows\System32\pmxmiced.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/11/08 16:01:54 | 000,049,152 | ---- | M] (Primax Electronics Ltd.) -- C:\Windows\System32\ico.exe
========== Modules (No Company Name) ========== MOD - [2012/05/30 18:45:25 | 000,082,944 | ---- | M] () -- C:\Program Files\NCH Software\ExpressZip\ezcm.dll
MOD - [2012/05/09 05:55:06 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3b7181bb19dd5dd74cd063f0312cdf57\System.Xml.ni.dll
MOD - [2012/05/09 05:52:55 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/09 05:52:40 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/11 13:31:14 | 000,068,720 | ---- | M] () -- C:\Program Files\VMware\VMware Player\zlib1.dll
MOD - [2010/11/11 13:31:00 | 000,970,352 | ---- | M] () -- C:\Program Files\VMware\VMware Player\libxml2.dll
========== Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/05 20:26:40 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/09 07:59:46 | 000,670,792 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
SRV - [2011/09/07 11:52:46 | 002,646,020 | ---- | M] (NCH Software) [On_Demand | Stopped] -- C:\Program Files\NCH Software\ExpressAccounts\expressaccounts.exe -- (ExpressAccountsService)
SRV - [2011/08/25 18:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2011/07/19 08:58:49 | 000,163,664 | R--- | M] (Storage Appliance Corporation) [Auto | Running] -- C:\ProgramData\OfficeGuardianV2N35\Reminder\SacNetAgent.exe -- (SacNetAgentService_C57C4F854F53)
SRV - [2011/07/19 08:58:49 | 000,083,792 | R--- | M] (Storage Appliance Corp.) [Auto | Running] -- C:\ProgramData\OfficeGuardianV2N35\UACProxy.exe -- (CFUACProxy_officeguardianv2n35)
SRV - [2011/05/06 11:03:10 | 000,191,752 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/03/25 22:32:40 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/11/11 13:31:54 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2010/11/11 13:31:50 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service)
SRV - [2010/11/11 13:30:44 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2010/11/11 12:31:44 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2010/08/19 13:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/07/21 20:17:20 | 000,069,632 | ---- | M] () [Auto | Running] -- C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe -- (wgsslvpnsrc)
SRV - [2009/02/25 19:06:42 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2008/12/03 19:06:57 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/08/14 01:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/01/20 21:21:41 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AERTSrv.exe -- (AERTFilters)
SRV - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [File_System | On_Demand | Stopped] -- C:\Windows\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\MICHAE~1\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012/04/09 07:27:18 | 000,026,624 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2011/12/23 07:12:12 | 000,064,512 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\System32\drivers\Lbd.sys -- (Lbd)
DRV - [2010/11/11 13:32:10 | 000,070,768 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2010/11/11 13:32:08 | 000,854,128 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV - [2010/11/11 13:30:34 | 000,024,688 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd)
DRV - [2010/11/11 13:29:26 | 000,026,352 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV - [2010/11/11 12:31:28 | 000,032,368 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV - [2010/11/11 10:04:52 | 000,036,400 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV - [2010/11/11 10:04:52 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV - [2010/08/19 13:56:38 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2010/07/21 20:17:06 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/07/14 12:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/02/22 02:44:08 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2009/04/10 23:45:24 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/02/27 13:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\BANTExt.sys -- (BANTExt)
DRV - [2008/01/20 21:21:33 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2007/10/03 15:20:32 | 000,063,008 | ---- | M] (Juniper Networks) [Kernel | System | Running] -- C:\Windows\System32\drivers\NEOFLTR_550_12129.sys -- (NEOFLTR_550_12129)
DRV - [2007/06/01 13:41:00 | 000,018,432 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pmxmouse.sys -- (pmxmouse)
DRV - [2007/05/24 16:56:00 | 000,014,336 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pmxusblf.sys -- (pmxusblf)
DRV - [2007/02/03 10:25:56 | 001,075,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Camdrl.sys -- (CamDrL)
DRV - [2002/06/10 14:24:22 | 000,188,592 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvvi500a.sys -- (LVVI500A)
DRV - [2002/06/10 14:21:02 | 000,010,254 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVBulk.sys -- (LVBulk)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4081204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4081204
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?}IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.co...ie=utf8&oe=utf8IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com/IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 7B 91 B3 17 EC CB 01 [binary data]
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRCIE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
https://isearch.avg....fr&d=2012-09-13 16:42:31&v=12.2.5.34&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "
http://www.bing.com/...TDF&PC=BBSR&q="FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://camsmd.com/ad.../?shva=1#inbox"FF - prefs.js..extensions.enabledAddons:
[email protected]:1.8
FF - prefs.js..extensions.enabledAddons:
[email protected]:1.9.3
FF - prefs.js..extensions.enabledAddons:
[email protected]:2.15
FF - prefs.js..extensions.enabledAddons: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledAddons: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledAddons:
[email protected]:3.55
FF - prefs.js..extensions.enabledItems:
[email protected]:3.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}:5.0.17
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: qrptoolbar@leapforceathome:1.83
FF - prefs.js..keyword.URL: "
https://isearch.avg....2:31&sap=ku&q="FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2011/09/24 17:55:09 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@sun.com/npsopluginmi;version=1.0: C:\Program Files\OpenOffice.org 3\program [2012/06/11 06:47:47 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\
[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@livecode.runrev.com/LiveCode Player;version=1: C:\Users\Michael Grantham\AppData\Local\RunRev\Components\LiveCodePlayer\9\nplcplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Michael Grantham\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Michael Grantham\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Michael Grantham\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/14 18:41:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/03 10:28:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/12/04 15:20:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/12/04 15:20:57 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/09/24 18:09:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Extensions
[2011/05/06 10:02:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/09/13 17:26:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions
[2011/09/24 18:09:05 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2012/03/09 14:34:43 | 000,000,000 | ---D | M] (Leapforce - Search Engine Evaluator Toolbar) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\qrptoolbar@leapforceathome(184).com
[2012/09/13 16:30:09 | 000,000,000 | ---D | M] (Leapforce - Search Engine Evaluator Toolbar) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\
[email protected][2012/07/29 08:31:28 | 000,005,582 | ---- | M] () (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\
[email protected][2012/06/01 07:58:03 | 000,617,362 | ---- | M] () (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\
[email protected][2012/09/11 06:33:21 | 000,335,583 | ---- | M] () (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\
[email protected][2012/05/04 13:19:53 | 000,344,888 | ---- | M] () (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\
[email protected][2011/11/14 22:43:31 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
[2011/01/16 11:06:42 | 000,001,832 | ---- | M] () -- C:\Users\Michael Grantham\AppData\Roaming\Mozilla\Firefox\Profiles\hpyoio3j.default\searchplugins\bing.xml
[2012/09/12 10:14:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/09/05 20:27:05 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/10/12 16:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010/10/12 16:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010/10/12 16:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010/10/12 16:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2009/11/20 15:05:31 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/10/12 18:16:54 | 000,484,768 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2009/11/20 15:05:32 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2007/03/09 18:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2010/10/12 16:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012/09/13 16:42:16 | 000,003,750 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/09/05 20:26:22 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/05 20:26:22 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/09/25 19:07:51 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\Windows\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: acddirect.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: arise.com ([ns] https in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: callswithoutwalls.com ([training] http in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: callswithoutwalls.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: cingularuniversity.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: convergysworkathome.com ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: intuit.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: intuit.com ([qtwu1.turbotaxonline] https in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: penson.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: virtualacd.biz ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: virtualized.biz ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Domains: wireless.att.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Ranges: Range1 ([*] in Trusted sites)
O15 - HKU\S-1-5-21-1885834091-318630671-1701898132-1005\..Trusted Ranges: Range2 ([http] in Trusted sites)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824}
http://www.logitech....Detection32.cab (Device Detection)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {34B453C6-CFE8-4806-B0F0-A0E06FFEBF5E}
https://iportal.west...erification.ocx (WAHSystemVerification.axVerify)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
http://i.dell.com/im...r/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creat...101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1238598588234 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC}
https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88}
http://www.convergys...om/AppHardT.CAB (WNICheck2 Class)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
http://javadl-esd.su...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 10.6.2)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://akamaicdn.we...ex/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
https://extranet.int...perSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://ns.arise.com...SetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creat...15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: GCSPlayerAxCab
https://gcslearn.par...PlayerAxCab.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD999CEE-11E4-46A7-85EB-AC99863B35DB}: DhcpNameServer = 172.17.5.27 172.17.5.28
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Users\Michael Grantham\AppData\Local\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/09/30 11:48:14 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/30 10:31:07 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/25 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\Complete Internet Repair
[2012/09/23 15:52:47 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/09/23 14:06:21 | 000,181,064 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/09/23 13:43:06 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/09/19 20:34:16 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/19 18:42:39 | 000,000,000 | ---D | C] -- C:\RegBackup
[2012/09/19 18:28:46 | 000,000,000 | ---D | C] -- C:\Tweaking.com_Windows_Repair_Logs
[2012/09/19 18:28:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/09/19 18:28:38 | 000,000,000 | ---D | C] -- C:\Program Files\Tweaking.com
[2012/09/19 18:23:16 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\G2G 0919
[2012/09/17 17:40:47 | 000,693,235 | ---- | C] (Farbar) -- C:\Users\Michael Grantham\Desktop\FSS.exe
[2012/09/17 17:11:37 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\0917 Geeks to go
[2012/09/15 21:16:38 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Local\temp
[2012/09/15 21:05:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/15 21:04:52 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/15 21:03:44 | 004,754,503 | R--- | C] (Swearware) -- C:\Users\Michael Grantham\Desktop\ComboFix.exe
[2012/09/14 16:42:24 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\DG Pics
[2012/09/13 19:21:59 | 000,307,293 | ---- | C] (Farbar) -- C:\Users\Michael Grantham\Desktop\ListParts.exe
[2012/09/13 17:33:58 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\RK_Quarantine
[2012/09/13 16:44:49 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Roaming\AVG2013
[2012/09/13 16:42:53 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Roaming\TuneUp Software
[2012/09/13 16:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2012/09/13 16:35:41 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Local\MFAData
[2012/09/13 16:35:41 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Local\Avg2013
[2012/09/13 16:35:01 | 004,411,392 | ---- | C] (AVG Technologies) -- C:\Users\Michael Grantham\Desktop\avg_free_stb_all_2013_2667_cnet.exe
[2012/09/13 15:33:16 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Michael Grantham\Desktop\tdsskiller.exe
[2012/09/13 15:23:11 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\TDSS Killer
[2012/09/13 15:14:32 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\GooredFix Backups
[2012/09/13 15:13:29 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Users\Michael Grantham\Desktop\GooredFix.exe
[2012/09/13 15:05:23 | 000,000,000 | ---D | C] -- C:\_OTM
[2012/09/13 15:03:29 | 000,522,240 | ---- | C] (OldTimer Tools) -- C:\Users\Michael Grantham\Desktop\OTM.exe
[2012/09/13 14:49:41 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\RegistryBackup
[2012/09/13 14:48:38 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\Desktop\erunt
[2012/09/13 14:40:21 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Michael Grantham\Desktop\OTL.exe
[2012/09/13 13:50:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/13 08:12:07 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Local\adawarebp
[2012/09/13 07:57:40 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/09/12 19:24:34 | 000,000,000 | ---D | C] -- C:\Users\Michael Grantham\AppData\Roaming\Malwarebytes
[2012/09/12 19:24:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/12 19:24:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/14 03:13:57 | 000,024,576 | ---- | C] (BackWeb) -- C:\Users\Michael Grantham\AppData\Local\TempIadHide3.dll
========== Files - Modified Within 30 Days ========== [2012/09/30 11:57:44 | 000,666,678 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/30 11:57:43 | 000,129,844 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/30 11:49:41 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/30 11:49:36 | 000,002,000 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/30 11:49:36 | 000,002,000 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/30 11:49:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/30 11:49:30 | 3478,310,912 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/30 11:44:21 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/30 11:19:20 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1885834091-318630671-1701898132-1005UA.job
[2012/09/30 10:36:00 | 000,000,414 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{A2EB84AC-F0D6-4C6D-AC7A-CCE5C4C202C4}.job
[2012/09/27 08:38:49 | 000,051,266 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\TTbookmark09272012.htm
[2012/09/25 19:07:51 | 000,000,761 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/09/25 18:54:48 | 000,650,870 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\complete-int-repair.exe
[2012/09/24 14:19:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1885834091-318630671-1701898132-1005Core.job
[2012/09/24 12:41:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012/09/23 17:35:44 | 000,003,132 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\EventSystem.reg
[2012/09/23 17:35:08 | 000,006,288 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\BITS.reg
[2012/09/23 17:34:52 | 000,006,176 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\wuauserv.reg
[2012/09/23 17:34:32 | 000,005,256 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\wscsvc.reg
[2012/09/23 17:34:04 | 000,020,254 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\VSS.reg
[2012/09/23 17:33:40 | 000,002,066 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\SDRSVC.reg
[2012/09/23 16:05:59 | 000,317,224 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/09/23 15:53:09 | 000,181,064 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
[2012/09/23 15:43:17 | 000,000,855 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.bak
[2012/09/23 11:59:03 | 000,001,356 | ---- | M] () -- C:\Users\Michael Grantham\AppData\Local\d3d9caps.dat
[2012/09/23 11:49:46 | 000,007,166 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\services.zip
[2012/09/19 20:27:43 | 000,000,855 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts_bak_482
[2012/09/19 18:42:51 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-DELL-Microsoft®-Windows-Vista™-Ultimate-(32-bit).dat
[2012/09/19 18:28:39 | 000,002,068 | ---- | M] () -- C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/09/19 18:26:48 | 000,346,950 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\SharedAccess.reg
[2012/09/19 18:26:25 | 005,313,275 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2012/09/17 17:34:22 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts_bak_792
[2012/09/17 17:17:14 | 000,693,235 | ---- | M] (Farbar) -- C:\Users\Michael Grantham\Desktop\FSS.exe
[2012/09/15 21:03:44 | 004,754,503 | R--- | M] (Swearware) -- C:\Users\Michael Grantham\Desktop\ComboFix.exe
[2012/09/15 13:23:00 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\AppleSoftwareUpdate.job
[2012/09/14 16:45:58 | 126,310,400 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\RepairDiscWindowsVista32-bit.iso
[2012/09/14 16:43:26 | 000,621,056 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\WiNToBootic.exe
[2012/09/13 19:21:59 | 000,307,293 | ---- | M] (Farbar) -- C:\Users\Michael Grantham\Desktop\ListParts.exe
[2012/09/13 17:33:32 | 001,378,816 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\RogueKiller.exe
[2012/09/13 16:35:02 | 004,411,392 | ---- | M] (AVG Technologies) -- C:\Users\Michael Grantham\Desktop\avg_free_stb_all_2013_2667_cnet.exe
[2012/09/13 16:31:07 | 000,131,072 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\2012-09-13-1.rateraide
[2012/09/13 15:33:20 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Michael Grantham\Desktop\tdsskiller.exe
[2012/09/13 15:20:58 | 002,193,184 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\tdsskiller.zip
[2012/09/13 15:13:30 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Users\Michael Grantham\Desktop\GooredFix.exe
[2012/09/13 15:03:31 | 000,522,240 | ---- | M] (OldTimer Tools) -- C:\Users\Michael Grantham\Desktop\OTM.exe
[2012/09/13 14:58:44 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/13 14:40:32 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Michael Grantham\Desktop\OTL.exe
[2012/09/13 13:54:14 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/13 06:37:54 | 000,000,050 | R--- | M] () -- C:\Users\Michael Grantham\Desktop\stinger092012.opt
[2012/09/12 08:38:13 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2012/09/12 08:38:13 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2012/09/01 20:32:09 | 000,084,452 | ---- | M] () -- C:\Users\Michael Grantham\Desktop\RaterAide.backup
[2012/08/31 17:18:45 | 000,002,093 | ---- | M] () -- C:\Users\Michael Grantham\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
========== Files Created - No Company Name ========== [2012/09/30 10:36:00 | 000,000,414 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{A2EB84AC-F0D6-4C6D-AC7A-CCE5C4C202C4}.job
[2012/09/30 08:06:53 | 3478,310,912 | -HS- | C] () -- C:\hiberfil.sys
[2012/09/27 08:38:48 | 000,051,266 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\TTbookmark09272012.htm
[2012/09/25 18:56:10 | 000,650,870 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\complete-int-repair.exe
[2012/09/23 11:51:06 | 000,006,288 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\BITS.reg
[2012/09/23 11:51:06 | 000,006,176 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\wuauserv.reg
[2012/09/23 11:51:06 | 000,003,132 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\EventSystem.reg
[2012/09/23 11:51:05 | 000,020,254 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\VSS.reg
[2012/09/23 11:51:05 | 000,005,256 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\wscsvc.reg
[2012/09/23 11:51:05 | 000,002,066 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\SDRSVC.reg
[2012/09/23 11:50:44 | 000,007,166 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\services.zip
[2012/09/19 20:25:08 | 000,303,616 | ---- | C] ( ) -- C:\SetACL.exe
[2012/09/19 18:42:51 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-DELL-Microsoft®-Windows-Vista™-Ultimate-(32-bit).dat
[2012/09/19 18:28:39 | 000,002,068 | ---- | C] () -- C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/09/19 18:28:05 | 000,346,950 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\SharedAccess.reg
[2012/09/19 18:28:01 | 005,313,275 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\tweaking.com_windows_repair_aio_setup.exe
[2012/09/14 16:43:50 | 126,310,400 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\RepairDiscWindowsVista32-bit.iso
[2012/09/14 16:43:25 | 000,621,056 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\WiNToBootic.exe
[2012/09/13 18:54:19 | 000,131,072 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\2012-09-13-1.rateraide
[2012/09/13 17:33:31 | 001,378,816 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\RogueKiller.exe
[2012/09/13 15:16:31 | 002,193,184 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\tdsskiller.zip
[2012/09/13 13:50:48 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/12 20:48:18 | 000,000,050 | R--- | C] () -- C:\Users\Michael Grantham\Desktop\stinger092012.opt
[2012/09/01 20:32:09 | 000,084,452 | ---- | C] () -- C:\Users\Michael Grantham\Desktop\RaterAide.backup
[2012/06/28 16:53:16 | 000,000,886 | ---- | C] () -- C:\Users\Michael Grantham\.recently-used.xbel
[2012/01/20 14:34:18 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2012/01/20 14:34:18 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/11/29 12:46:53 | 000,000,590 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011/10/04 08:10:23 | 000,135,702 | ---- | C] () -- C:\Windows\hpwins10.dat.osupcopy
[2011/10/04 08:09:28 | 000,136,359 | ---- | C] () -- C:\Windows\hpwins10.dat.temp
[2011/10/04 08:09:28 | 000,001,042 | ---- | C] () -- C:\Windows\hpwmdl10.dat.temp
[2011/10/04 08:08:57 | 000,001,042 | ---- | C] () -- C:\Windows\hpwmdl10.dat
[2011/09/25 08:40:19 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/09/25 08:40:19 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/09/25 08:39:47 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/09/25 08:39:35 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/09/25 06:30:06 | 000,005,632 | ---- | C] () -- C:\Users\Michael Grantham\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/24 19:55:16 | 000,294,912 | ---- | C] () -- C:\Windows\System32\liplW7.dll
[2011/09/24 19:55:16 | 000,290,816 | ---- | C] () -- C:\Windows\System32\liplA6.dll
[2011/09/24 19:55:16 | 000,278,528 | ---- | C] () -- C:\Windows\System32\liplPX.dll
[2011/09/24 19:55:16 | 000,278,528 | ---- | C] () -- C:\Windows\System32\liplP6.dll
[2011/09/24 19:55:16 | 000,278,528 | ---- | C] () -- C:\Windows\System32\liplM6.dll
[2011/09/24 19:55:16 | 000,020,480 | ---- | C] () -- C:\Windows\System32\lipl.dll
[2011/09/24 19:54:48 | 000,005,187 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011/09/24 19:37:16 | 000,001,356 | ---- | C] () -- C:\Users\Michael Grantham\AppData\Local\d3d9caps.dat
[2011/09/24 18:25:18 | 000,022,732 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2011/07/28 19:38:28 | 000,000,664 | ---- | C] () -- C:\Windows\System32\d3d9caps.dat
[2011/07/13 09:14:58 | 000,000,241 | ---- | C] () -- C:\Windows\QSync.INI
[2011/07/13 09:13:50 | 000,000,780 | ---- | C] () -- C:\Windows\_delis32.ini
[2011/07/13 09:12:42 | 000,081,920 | ---- | C] () -- C:\Windows\bwUnin-6.1.4.36-8876480L.exe
[2009/03/23 11:15:57 | 000,044,602 | ---- | C] () -- C:\Users\Michael Grantham\AppData\Roaming\wklnhst.dat
========== LOP Check ========== [2011/09/24 18:17:54 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Juniper Networks
[2011/09/24 18:17:54 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Juniper Networks
[2011/09/24 18:08:20 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\acccore
[2012/07/29 07:40:32 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Ad-Aware Antivirus
[2011/09/24 18:08:22 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Avaya
[2011/09/24 18:08:22 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\AVG10
[2012/09/13 16:44:49 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\AVG2013
[2011/09/24 18:08:22 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\AVG9
[2011/09/24 18:08:22 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\CoffeeCup Software
[2011/12/23 11:38:13 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\CvgQuickConnect
[2011/09/24 18:08:31 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\DassaultSystemes
[2012/06/28 17:40:29 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\gtk-2.0
[2012/03/10 16:51:06 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\ICAClient
[2012/06/28 16:50:01 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Image Zone Express
[2012/07/02 09:34:46 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Juniper Networks
[2011/09/24 18:09:05 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\OpenOffice.org
[2011/09/24 18:09:07 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\PCDr
[2011/09/24 18:09:10 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Printer Info Cache
[2011/10/05 12:44:33 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Recordpad
[2011/10/12 09:05:06 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\RightNow_Technologies
[2012/05/07 14:21:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\SecondLife
[2011/09/24 18:09:13 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Template
[2011/09/24 18:09:13 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Thunderbird
[2012/09/13 16:42:53 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\TuneUp Software
[2012/05/23 05:44:13 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Utherverse
[2012/08/05 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\uTorrent
[2011/09/24 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\VirtualStore
[2011/09/24 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\VS Media Inc
[2011/10/12 08:38:23 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\WatchGuard
[2011/09/24 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\webex
[2011/09/24 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Windows Desktop Search
[2011/09/24 18:09:14 | 000,000,000 | ---D | M] -- C:\Users\Michael Grantham\AppData\Roaming\Windows Search
[2011/09/22 16:47:32 | 000,000,290 | ---- | M] () -- C:\Windows\Tasks\debutShakeIcon.job
[2011/09/30 12:46:00 | 000,000,298 | ---- | M] () -- C:\Windows\Tasks\expressShakeIcon.job
[2008/01/20 21:54:58 | 000,003,456 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/06 12:47:00 | 000,000,294 | ---- | M] () -- C:\Windows\Tasks\scribeShakeIcon.job
[2012/09/30 10:36:00 | 000,000,414 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{A2EB84AC-F0D6-4C6D-AC7A-CCE5C4C202C4}.job
========== Purity Check ========== < End of report >