I suspect a Dell Inspiron 1721 laptop PC that belongs to a friend may have an infection. When he first gave it to me, it appeared to hang right after booting to the desktop with the hard disk LED solidly on. OS is Vista 32bit Home Premium SP1 running the factory setup with recovery partition. It only had 1GB RAM so I suspected that swap file activity was making things worse so we upgraded to 4GB RAM. After scanning/cleaning with Kaspersky Rescue Disk, it was scanned with latest MBAM which found and removed the Trojan Vundo among other things. This cleared up most of the busy disk activity however there still seems to be a period of heavy disk activity and unresponsiveness just after booting to the desktop, and after full scans with MSE and SuperAntiSpyware with only minimal detections (tracking cookies, etc) as well as installing Vista SP2, it still behaves this way. Vista does not seem to behave this way when booted to Safe Mode, and there is no extended disk activity seen or being explained in Task Manager.
Furthermore, here are some strange things that I've noticed:
1. There is an entry in the registry that I'm not familiar with that keeps reappearing even after I deleted it:
"%PROVIDERID%"="\"bin\\sprtcmd.exe\" /P %PROVIDERID%". Attempts to search for this are unsuccessful.
2. Adobe Reader v9.x keeps launching reader_sl.exe even though its registry entry has been deleted from the HKLM...Current Version\Run location.
3. User has used Limewire toolbar and Vuze in the past, some software is still present.
Please Help...
Thanks,
Jay
Here is the OTL file:
OTL Extras logfile created on: 9/23/2012 1:23:23 PM - Run 1
OTL by OldTimer - Version 3.2.66.0 Folder = C:\tools
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.37 Gb Total Physical Memory | 2.05 Gb Available Physical Memory | 60.67% Memory free
6.26 Gb Paging File | 5.10 Gb Available in Paging File | 81.49% Paging File free
Paging file location(s): c:\pagefile.sys 3071 3071 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.22 Gb Total Space | 29.47 Gb Free Space | 29.71% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.06 Gb Free Space | 50.60% Space Free | Partition Type: NTFS
Computer Name: JOHNVERO-PC | User Name: JohnVero | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08DB9E6E-26A7-4DFB-8CFF-398E9BE56F02}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{09C26420-E925-4847-AC9C-4574D150C19E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0B62AFB9-1720-4A5E-BA3F-61BE5A162F1D}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{0CF32968-4FAF-4FEE-AB43-C31063590F9E}" = lport=10244 | protocol=6 | dir=in | app=system |
"{1294169D-56F6-458A-A051-440F5E883F36}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{15411080-C4DC-4347-B224-298CCB0A623B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{16433106-DF2C-4845-8CF5-331FE64E811B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{21F1B881-18A1-4F7A-9BDD-7AB741AE51FE}" = lport=3390 | protocol=6 | dir=in | app=system |
"{2F6AB023-366D-4C71-AC1D-1E90A6A6AF49}" = rport=10244 | protocol=6 | dir=out | app=system |
"{30019836-1289-498D-AE43-05133A23CD5F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{44F9F14C-94F9-4959-9B58-70A173197365}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{478B8AB0-16B8-4792-9E9E-A2F524ED798A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5AE52322-77D6-4869-8050-C4C3FBB62AB9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{66CBDB77-23E1-402D-9072-8C4B7F633A05}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6BD3DA1E-F10F-44D4-B552-9BBA97F48C87}" = lport=3390 | protocol=6 | dir=in | app=system |
"{81D4C0C3-950C-4A29-9FB7-00EBA9283CB5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BDBD0925-BDE5-42E5-9847-8DB5794C3F01}" = lport=10244 | protocol=6 | dir=in | app=system |
"{D146336E-377D-42B3-B7A7-6A3D7A4E3798}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EB1A8FC1-46A9-4D0E-82FE-18A807EAFF1D}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{F78053A0-D2BB-4E67-A667-A387DAF01031}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{F97A0F16-E645-4F9F-932C-1109D0B3E427}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FC8E3D46-9F5F-4DD2-9C32-929746F37AF7}" = rport=10244 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{107B5A53-CBC3-44A8-9EF9-9CC5F4561CAA}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{280F429F-E66B-4F2F-A5DF-A96F0D1FFE5F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2A1CCE11-AE56-4FDA-BB6A-6B333880CB9C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{40B413EA-4441-43AF-BF90-B22575FF3652}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{56C2BF1F-1004-4B5C-8886-566A97CFEB73}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5FCA2367-2BEC-48FF-8B2E-EF4FA96405C6}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{67B4079B-C07B-4F35-B201-2EF03BBD4892}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{6C899833-AC7C-4BB9-AC24-0B302BB030A5}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{6F588EDE-1124-431B-A59D-15D7E9E4DA20}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{703174ED-E884-4B00-8B28-3A286533375B}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{72CD0D50-98DF-42EF-A8F0-F431531EDB23}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{81C88695-EE5C-43CE-B707-24EDD81B50C3}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{86BEF7D3-8DA4-41E5-8003-2E116C3F3BDC}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{8FCC64E1-8DD4-4533-B5EC-9A43D7FBE335}" = protocol=6 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
"{97292801-F92D-455A-98C8-7595B80807A2}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{99BFABAC-B01A-42E1-8E01-556EC0FA3D29}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A759A3D5-1C59-4E49-8466-8E952876421A}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{AA3A040C-D6DA-404F-BE93-1632B3C36DFC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C3166996-B589-44F5-AD48-CCCDFB46E9ED}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{C502A3D1-9C03-4EB2-A7CF-DD63E226A0BD}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{C9ABFC17-67A6-4C0B-A3D8-A85C341C8C05}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{D47B441F-4C40-4F20-B5FA-A59F8ED851BC}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D67E3620-155B-4A92-BE11-8DB660CC114D}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{DD408540-61B1-4B64-B991-F60A030764EF}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{E5C2228F-3B72-46B9-B8C2-3D9B05FAAF4B}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{E6E17B79-2E2C-40E5-BF0C-E36BD9D88763}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{EDC18B07-151F-429D-95AF-A6A3D5BDE389}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{F2415763-E2CF-4AB6-9EA7-C5913F584F80}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{F5311C53-0C20-4160-B760-E352D1F9792A}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{F894C982-F437-4777-B801-146D73E49B61}" = protocol=17 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
"TCP Query User{397AFE5F-94B9-4CC3-8EFB-DF91420F4E88}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{4BEFF2F7-A23B-4F6D-B65C-2349A6609D35}C:\program files\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"TCP Query User{62977F0E-9B34-4945-8151-0BF326A6BA00}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{6786F229-3162-4593-95B3-38BD1F3FFF8F}C:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
"TCP Query User{D926C06E-C9BA-4DD1-86CB-578481BF61B4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{F42D4D66-1C15-4895-B512-45276B52056D}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{33BFA42D-F8C4-43AE-AC9E-E53478E49F23}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{42A2EA26-5B50-4BD5-95D8-BA994F682CE2}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{5F9FD809-42DF-4090-B6B1-556A4283BEF6}C:\program files\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare\bearshare.exe |
"UDP Query User{8F0EBB6A-0F29-4A22-871F-3D260434BF36}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{9A087399-52DE-4225-A9FC-4AFF16B44B16}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{CA9B0EBB-F8E2-41E5-8589-24B97487A1C1}C:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\yahoo! music jukebox\yahoomusicengine.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02C85D5D-77CA-7173-5775-AFB9CC835F33}" = CCC Help Finnish
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{085FE193-B676-11D4-82BC-00A0C993905F}" = Thomas Bros. Street Guide Digital Edition
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0A331B03-B20D-D63E-7CFA-6DE03CD85972}" = CCC Help Chinese Traditional
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D6D96F4-0CAF-4522-B05F-70A88EDECDFD}" = ArcSoft Print Creations
"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{0F95AA42-0FF6-4D48-9CA1-64C8D0777500}" = QuickSet
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{179950A7-026A-3F96-9540-3C528A96C5C0}" = Catalyst Control Center Localization Danish
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1882BDBB-0DFD-FAE6-77FA-E3445D821F18}" = CCC Help Norwegian
"{2357B8BC-88C9-4A72-818C-050CC4EB0778}" = AOL Install
"{2452E3E3-B627-7371-F43F-68149C528556}" = CCC Help French
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java 6 Update 35
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{310A99AD-E8DD-CF60-CDD3-ED197E106A80}" = Catalyst Control Center Localization Russian
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java SE Runtime Environment 6
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36D252B0-6856-4395-4BBE-DEC2E56DCB24}" = Catalyst Control Center Localization Dutch
"{3736E75B-0FD7-F5A3-15F1-EE07B633AEE5}" = Catalyst Control Center Localization Finnish
"{393AAD92-9760-9B0D-43C1-C6C5E89EFA67}" = Catalyst Control Center Localization Swedish
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E25E350-949F-4DB7-8288-2A60E018B4C1}" = Games, Music, & Photos Launcher
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4248C264-C1BF-8414-4B16-F61FF0BC49A7}" = Catalyst Control Center Localization Spanish
"{48FC3614-221A-4272-5AFC-50EC406606FE}" = Catalyst Control Center Localization Chinese Traditional
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A2BD145-6614-B0A5-0E1A-5367A3451691}" = CCC Help Chinese Standard
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{55D070A2-9EA5-8C26-5F74-835BAC086523}" = Catalyst Control Center Localization German
"{59361F9F-A413-83EC-E269-6D34CC697878}" = CCC Help Portuguese
"{5B35C417-2649-11D6-83D1-0050FC01225C}" = FirstClass® Client
"{5B9A8ECB-A06B-A5AF-A7AD-B2E1A9B09AE8}" = CCC Help Korean
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}" = EarthLink Setup Files
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6BAFE5C7-FAAE-7F8C-39C0-BA8BD7A6786F}" = Catalyst Control Center Localization Chinese Standard
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BBAAE1-61A5-5F40-9BF3-95992B29F8A7}" = Catalyst Control Center Graphics Full Existing
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A97828F-C89C-C290-E11D-57A33DD523CB}" = Catalyst Control Center Localization Portuguese
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7D3A926D-D61E-6063-1C0D-18A4365D5033}" = ccc-core-static
"{7E532356-3BAE-4832-A253-2F1094FE5C40}" = Catalyst Control Center Localization Norwegian
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{88937F68-8C7A-A5DC-4004-2A2E0ECCC2DB}" = Catalyst Control Center Localization Japanese
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C454737-22A5-43F6-B09F-A4B3F7BD3468}" = CCC Help Spanish
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9C769AD0-00EE-8A6A-8C2A-F51BAABCCE02}" = CCC Help Dutch
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9E3DCAB8-285C-464F-DBCB-0052F92FEEF2}" = Catalyst Control Center Graphics Light
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A8B9FBF8-7986-6CF7-C31C-20A19E7D1717}" = ccc-utility
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{ACB4C93A-594E-E76A-3349-EEF2D6A723D6}" = Catalyst Control Center Localization Italian
"{ACDF5DEF-413F-A546-6F35-66CE215BDCCB}" = Skins
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2BFD108-1E93-06C5-F34E-48B92C358EDD}" = CCC Help Swedish
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{B970E87C-274D-5ADC-41BB-8C81926AF300}" = CCC Help Russian
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C6CC1EA6-12E2-219A-F8A1-1058AB678E08}" = CCC Help Italian
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CCFF1E13-77A2-4032-8B12-7566982A27DF}" = Internet Service Offers Launcher
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF8BA296-55D7-8B51-6C4E-4789A1D003BE}" = Catalyst Control Center Localization French
"{D03E7B00-CA85-4684-9321-1888873C34BD}" = ArcSoft PhotoImpression 6
"{D0DDF9EE-C67F-368B-EB42-ECB44FD7556D}" = Adobe Photoshop.com Inspiration Browser
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D62A9D43-39A4-337B-A432-1C6DB13087B8}" = CCC Help English
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D8210D47-2F24-99C7-9183-E093FBF14D92}" = CCC Help Japanese
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DCDCFE99-36A7-6B89-8329-BAB033D99577}" = CCC Help German
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DE623944-11D0-4CD3-17BE-FDF0F5309FD5}" = CCC Help Danish
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{E194308F-9718-7425-BCC1-FAAF46A188CB}" = Catalyst Control Center Core Implementation
"{E314D889-0C82-9F5F-A9EE-699109226856}" = Catalyst Control Center Graphics Full New
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E713653C-8312-4BC6-AFC9-ADE1F2F04AB9}" = ATI PCI Express (3GIO) Filter Driver
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{EDC5E937-F707-4241-BB2F-111C4B83FF2C}" = WebPAM
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EFBE2318-89B7-4A5F-8912-23DB04761C31}" = Catalyst Control Center - Branding
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FC516A10-B335-4FB5-8EA2-0DB8E57E044C}" = Sprint SmartView
"{FF61246F-8BD1-165A-5F50-B6DFECE53025}" = Catalyst Control Center Localization Korean
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Photoshop CS4_is1" = Adobe Photoshop CS4
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"DTCLookup" = DTCLookup
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Google Desktop" = Google Desktop
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{EDC5E937-F707-4241-BB2F-111C4B83FF2C}" = WebPAM
"legacyqcam_10.51" = Logitech Legacy USB Camera Driver Package
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MyPublisher" = MyPublisher
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1" = Adobe Photoshop.com Inspiration Browser
"Vuze" = Vuze
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/23/2012 9:24:09 AM | Computer Name = JohnVero-PC | Source = ESENT | ID = 215
Description = WinMail (4076) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.
Error - 9/23/2012 9:25:04 AM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 9:28:21 AM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 9:28:23 AM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:46:01 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:46:34 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:46:41 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:47:36 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:47:36 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 9/23/2012 12:48:52 PM | Computer Name = JohnVero-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
[ Broadcom Wireless LAN Events ]
Error - 11/25/2007 11:16:27 AM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 07:16:27, Sun, Nov 25, 07 Error - Unable to gain access to user store
Error - 11/30/2007 7:50:46 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 15:50:46, Fri, Nov 30, 07 Error - Unable to gain access to user store
Error - 12/15/2007 6:57:42 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 14:57:42, Sat, Dec 15, 07 Error - Unable to gain access to user store
Error - 2/4/2008 3:36:29 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 11:36:29, Mon, Feb 04, 08 Error - Unable to gain access to user store
Error - 2/12/2008 8:51:49 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 16:51:42, Tue, Feb 12, 08 Error - Unable to gain access to user store
Error - 2/12/2008 9:20:10 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 17:20:09, Tue, Feb 12, 08 Error - Unable to gain access to user store
Error - 4/3/2008 12:21:55 AM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 21:21:55, Wed, Apr 02, 08 Error - Unable to gain access to user store
Error - 5/21/2008 8:18:16 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 17:18:15, Wed, May 21, 08 Error - Unable to gain access to user store
Error - 6/3/2008 10:03:22 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 19:03:22, Tue, Jun 03, 08 Error - Unable to gain access to user store
Error - 6/9/2008 9:57:45 PM | Computer Name = JohnVero-PC | Source = WLAN-Tray | ID = 0
Description = 18:57:38, Mon, Jun 09, 08 Error - Unable to gain access to user store
[ Media Center Events ]
Error - 5/22/2008 8:24:19 PM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.
Error - 5/31/2008 8:00:09 PM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.
Error - 6/2/2008 12:37:10 AM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.
Error - 4/29/2009 11:01:26 PM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 5/7/2009 1:29:10 PM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 6/9/2009 1:46:35 PM | Computer Name = JohnVero-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ System Events ]
Error - 9/23/2012 12:48:51 PM | Computer Name = JohnVero-PC | Source = RemoteAccess | ID = 20151
Description = The Control Protocol EAP in the Point to Point Protocol module C:\Windows\System32\rasppp.dll
returned an error while initializing. The specified module could not be found.
Error - 9/23/2012 12:48:51 PM | Computer Name = JohnVero-PC | Source = RasMan | ID = 20063
Description = Remote Access Connection Manager failed to start because the Point
to Point Protocol failed to initialize. The specified module could not be found.
Error - 9/23/2012 12:48:51 PM | Computer Name = JohnVero-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 9/23/2012 12:48:55 PM | Computer Name = JohnVero-PC | Source = RemoteAccess | ID = 20070
Description = Point to Point Protocol engine was unable to load the C:\Program Files\Cingular\Communication
Manager\EapTtls.dll module. The specified module could not be found.
Error - 9/23/2012 12:48:55 PM | Computer Name = JohnVero-PC | Source = RemoteAccess | ID = 20151
Description = The Control Protocol EAP in the Point to Point Protocol module C:\Windows\System32\rasppp.dll
returned an error while initializing. The specified module could not be found.
Error - 9/23/2012 12:48:55 PM | Computer Name = JohnVero-PC | Source = RasMan | ID = 20063
Description = Remote Access Connection Manager failed to start because the Point
to Point Protocol failed to initialize. The specified module could not be found.
Error - 9/23/2012 12:48:55 PM | Computer Name = JohnVero-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 9/23/2012 12:48:58 PM | Computer Name = JohnVero-PC | Source = RemoteAccess | ID = 20070
Description = Point to Point Protocol engine was unable to load the C:\Program Files\Cingular\Communication
Manager\EapTtls.dll module. The specified module could not be found.
Error - 9/23/2012 12:48:58 PM | Computer Name = JohnVero-PC | Source = RemoteAccess | ID = 20151
Description = The Control Protocol EAP in the Point to Point Protocol module C:\Windows\System32\rasppp.dll
returned an error while initializing. The specified module could not be found.
Error - 9/23/2012 12:48:58 PM | Computer Name = JohnVero-PC | Source = RasMan | ID = 20063
Description = Remote Access Connection Manager failed to start because the Point
to Point Protocol failed to initialize. The specified module could not be found.
< End of report >