Hi Godawgs
This is also from the OTL log:
Error - 10/13/2012 11:51:30 AM | Computer Name = Cindy-PC | Source = profsvc | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - The system cannot
find the file specified.
It appears that something happened on the 13th that caused a problem loading a registy file
That error goes back as far as my log goes. Apparently it's a regular thing....or was. Haven't checked in the error log in the last few days.
Why is version 3.2.65.1 still on your desktop and why are you still using it? Please Delete version 3.2.65.1 from the desktop!!! And use version 3.2.69.0.
Uh huh. Yes, I did as instructed. The first time you asked.
DO NOT delete the C:\_OTL folder.
I did not, I just deleted the OTL copy as instructed.
I think System restore in post 13 made earlier OTL. I did nothing. I didn't realize it either until you just said, but that's my excuse, and I'm stickin' to it. Interesting it still says Run 4 Hmmm....
That is a task to update the McAfee antivirus. It must have been installed at some time. You can delete the task from task scheduler.
I've never added or deleted anything there purposefully, I'll figure it out and do it. It can't be that difficult
Can't imagine why there would be a user account named ASP.net You, or something created it.
Here is a link to a google page on asp.net linky
If you don't recognize it and didn't create it let me know and we will delete it as part of the cleanup process.
It's always been there. I thought it was supposed to be there. It can go. You can or I will
OTL
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-1904047010-3443834183-2145573803-1007\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
========== FILES ==========
< ipcongig /flushdns /c >C:\Users\Cinjo\Desktop\cmd.bat deleted successfully.
C:\Users\Cinjo\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Cindy
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 609349334 bytes
->Java cache emptied: 6182946 bytes
->Google Chrome cache emptied: 9796623 bytes
->Flash cache emptied: 173841 bytes
User: Cinjo
->Temp folder emptied: 591819 bytes
->Temporary Internet Files folder emptied: 50133389 bytes
->Java cache emptied: 6182946 bytes
->Flash cache emptied: 174286 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56504 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 30027273 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 58413 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Test
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3574536 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 600576 bytes
Total Files Cleaned = 684.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 10282012_152308
Files\Folders moved on Reboot...
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF7388.tmp not found!
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF738F.tmp not found!
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF73EC.tmp not found!
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF73F2.tmp not found!
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF7419.tmp not found!
File\Folder C:\Users\Cinjo\AppData\Local\Temp\~DF741F.tmp not found!
C:\Users\Cinjo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AWAKTW8I\page__pid__2221652__st__30[1].htm moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
MWB
2012/10/28 02:05:38 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\VOD.exe Trojan.Clicker ALLOW
2012/10/28 02:05:38 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\Shopping.exe Trojan.Clicker ALLOW
2012/10/28 02:05:49 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\MP3.exe Trojan.Clicker ALLOW
2012/10/28 04:49:15 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\VOD.exe Trojan.Clicker ALLOW
2012/10/28 04:56:14 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\MP3.exe Trojan.Clicker ALLOW
2012/10/28 04:56:14 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\Shopping.exe Trojan.Clicker ALLOW
2012/10/28 11:48:56 -1000 CINDY-PC Cindy DETECTION C:\Program Files\Toshiba\Amazon\VOD.exe Trojan.Clicker ALLOW
2012/10/28 11:50:20 -1000 CINDY-PC Cindy DETECTION C:\Program Files\Toshiba\Amazon\Shopping.exe Trojan.Clicker ALLOW
2012/10/28 13:48:26 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\VOD.exe Trojan.Clicker ALLOW
2012/10/28 13:48:27 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\Shopping.exe Trojan.Clicker ALLOW
2012/10/28 13:48:56 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\MP3.exe Trojan.Clicker ALLOW
2012/10/28 15:04:56 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\VOD.exe Trojan.Clicker ALLOW
2012/10/28 15:04:57 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\Shopping.exe Trojan.Clicker ALLOW
2012/10/28 15:06:23 -1000 CINDY-PC Cinjo DETECTION C:\Program Files\Toshiba\Amazon\MP3.exe Trojan.Clicker ALLOW
2012/10/28 15:45:37 -1000 CINDY-PC Cinjo MESSAGE Starting database refresh
2012/10/28 15:45:58 -1000 CINDY-PC Cinjo MESSAGE Database refreshed successfully
Security Check
Results of screen317's Security Check version 0.99.54
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 8
Out of date! ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.65.1.1000
Java 7
Java version out of Date! Adobe Reader X (10.1.4)
````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check````````````````` Total Fragmentation on Drive C: 1 %
````````````````````End of Log`````````````````````` OTL:
OTL logfile created on: 10/28/2012 7:18:08 PM - Run 12
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Cinjo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19328)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 47.73% Memory free
3.98 Gb Paging File | 2.98 Gb Available in Paging File | 74.89% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 47.28 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
Computer Name: CINDY-PC | User Name: Cinjo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/10/28 15:19:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTL.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 17:19:44 | 000,947,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/07/27 10:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/02/11 13:45:54 | 001,295,736 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2011/02/11 13:45:52 | 000,054,136 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe
PRC - [2009/04/10 20:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/06/02 11:26:48 | 000,505,720 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2008/05/09 09:49:30 | 000,716,800 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2008/04/24 10:03:12 | 000,430,080 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2008/04/16 21:21:24 | 001,056,768 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2008/04/16 21:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2008/04/16 21:19:16 | 000,405,504 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2008/04/08 13:14:50 | 006,037,504 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
========== Modules (No Company Name) ========== MOD - [2012/06/14 03:43:40 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012/06/14 03:38:31 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:38:21 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/05/11 17:17:42 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/11 17:10:01 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/11 16:54:35 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 16:54:12 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/03/13 20:38:15 | 008,007,680 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2008/03/06 08:14:54 | 005,121,912 | ---- | M] () -- C:\Program Files\Toshiba\FlashCards\BlackPng.dll
MOD - [2007/12/25 10:03:40 | 000,015,184 | ---- | M] () -- C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll
MOD - [2007/12/14 19:40:00 | 000,090,112 | ---- | M] () -- C:\Program Files\Toshiba\FlashCards\TWarnMsg\TWarnMsg.dll
MOD - [2006/10/10 08:44:16 | 000,009,728 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Assist\NotifyX.dll
MOD - [2006/10/07 08:57:04 | 000,053,248 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll
========== Services (SafeList) ========== SRV - [2012/10/09 03:16:12 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/07/27 10:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/02/11 13:45:52 | 000,054,136 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2010/07/26 16:00:24 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper)
SRV - [2010/02/24 16:42:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2008/07/18 18:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/04/16 21:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2008/04/16 13:53:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [Disabled | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2008/04/15 15:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008/02/06 11:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2008/01/20 16:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/03 15:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/21 15:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Disabled | Stopped] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2006/10/05 10:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Disabled | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 13:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\viaagp.sys -- (viaagp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\uliagpkx.sys -- (uliagpkx)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\uagp35.sys -- (uagp35)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\sisagp.sys -- (sisagp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\sffp_sd.sys -- (sffp_sd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\sffp_mmc.sys -- (sffp_mmc)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\serenum.sys -- (Serenum)
DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\system32\drivers\parvdm.sys -- (Parvdm)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\nv_agp.sys -- (nv_agp)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\gagp30kx.sys -- (gagp30kx)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/08/30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/24 05:05:40 | 000,011,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWDUMon.sys -- (SWDUMon)
DRV - [2010/06/23 09:21:32 | 000,259,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/07/28 13:53:48 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/07/18 16:52:16 | 000,279,376 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tos_sps32.sys -- (tos_sps32)
DRV - [2008/04/28 14:59:18 | 000,020,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2008/01/20 16:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007/12/14 09:53:24 | 000,024,200 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2007/11/09 12:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2006/11/28 13:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/20 11:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/08 20:32:00 | 000,219,264 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10I.sys -- (KR10I)
DRV - [2006/11/08 20:31:00 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10N.sys -- (KR10N)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKLM\..\SearchScopes,DefaultScope = {D03D7F1E-2667-4FB4-9A19-35292CB10741}
IE - HKLM\..\SearchScopes\{D03D7F1E-2667-4FB4-9A19-35292CB10741}: "URL" =
http://www.google.co...ge={startPage}; IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartIE - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\..\SearchScopes,DefaultScope = {D03D7F1E-2667-4FB4-9A19-35292CB10741}
IE - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/10 14:41:52 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2012/10/25 05:02:16 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1904047010-3443834183-2145573803-1007\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicr...osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{814EBDF1-5B7A-44CF-97E4-3FB8B9056A05}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 11:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/10/28 15:19:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTL.exe
[2012/10/28 02:10:39 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\Adobe
[2012/10/27 17:06:49 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vGrabber
[2012/10/27 17:06:49 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/10/27 16:52:31 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Documents\Ulead DVD MovieFactory
[2012/10/27 16:52:29 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Documents\OneNote Notebooks
[2012/10/27 16:52:24 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Desktop\Weekly Cleanup
[2012/10/27 16:52:24 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\V Stuff
[2012/10/27 16:52:23 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\UCPL5
[2012/10/27 16:47:34 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Tools and information
[2012/10/27 16:46:20 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\SparksSpotts Family
[2012/10/27 16:46:20 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Sparkes Info
[2012/10/27 16:46:20 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\RK_Quarantine
[2012/10/27 16:46:15 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\R & T
[2012/10/27 16:46:13 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\pics
[2012/10/27 16:46:12 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\my scan results
[2012/10/27 16:46:12 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\laptop help godawgs )
[2012/10/27 16:46:11 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\laptop help
[2012/10/27 16:46:11 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Jones family
[2012/10/27 16:46:02 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Joe
[2012/10/27 16:44:30 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\GTG
[2012/10/27 16:44:29 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Desktop\desktop keep info
[2012/10/27 16:44:18 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Daniel's Music
[2012/10/27 16:44:17 | 000,399,264 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Cinjo\Desktop\unhide.exe
[2012/10/27 16:44:17 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Daniel
[2012/10/27 16:44:17 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Desktop\Best for Search
[2012/10/27 16:44:14 | 002,213,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Cinjo\Desktop\tdsskiller.exe
[2012/10/27 16:44:14 | 000,646,656 | ---- | C] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTS.scr
[2012/10/27 16:44:12 | 000,219,648 | ---- | C] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTA.exe
[2012/10/27 16:44:11 | 004,988,915 | R--- | C] (Swearware) -- C:\Users\Cinjo\Desktop\ComboFix.exe
[2012/10/27 16:44:11 | 000,694,323 | ---- | C] (Farbar) -- C:\Users\Cinjo\Desktop\FSS.exe
[2012/10/27 16:43:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Yahoo!
[2012/10/27 16:43:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\WinBatch
[2012/10/27 16:43:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Ventrilo
[2012/10/27 16:43:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Ulead Systems
[2012/10/27 16:43:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\.minecraft
[2012/10/27 16:43:53 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\TOSHIBA
[2012/10/27 16:43:53 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Symantec
[2012/10/27 16:43:50 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Skype
[2012/10/27 16:43:50 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Samsung
[2012/10/27 16:43:47 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\PeerNetworking
[2012/10/27 16:43:47 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\PDF reDirect
[2012/10/27 16:43:47 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Octoshape
[2012/10/27 16:43:46 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\mIRC
[2012/10/27 16:42:27 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Malwarebytes
[2012/10/27 16:42:11 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\InstallShield
[2012/10/27 16:42:10 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\HpUpdate
[2012/10/27 16:42:10 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\HP
[2012/10/27 16:42:10 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Google
[2012/10/27 16:40:18 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Adobe
[2012/10/27 16:40:18 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\298C9C7DADAA7E8E26A337A4FE989565
[2012/10/27 16:18:52 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\Documents\My Google Gadgets
[2012/10/27 16:18:22 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\Toshiba
[2012/10/27 16:18:17 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Real
[2012/10/27 16:18:17 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\Google
[2012/10/27 16:18:17 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Apple Computer
[2012/10/27 16:17:18 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/10/27 16:17:18 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Searches
[2012/10/27 16:17:18 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/10/27 16:17:10 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Identities
[2012/10/27 16:17:08 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Contacts
[2012/10/27 16:16:34 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\VirtualStore
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\AppData\Local\Temporary Internet Files
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Templates
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Start Menu
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\SendTo
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Recent
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\PrintHood
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\NetHood
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Documents\My Videos
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Documents\My Pictures
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Documents\My Music
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\My Documents
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Local Settings
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\AppData\Local\History
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Cookies
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\Application Data
[2012/10/27 16:15:56 | 000,000,000 | -HSD | C] -- C:\Users\Cinjo\AppData\Local\Application Data
[2012/10/27 16:15:54 | 000,000,000 | --SD | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Videos
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Saved Games
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Pictures
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Music
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Links
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Favorites
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Downloads
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Documents
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\Desktop
[2012/10/27 16:15:54 | 000,000,000 | R--D | C] -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\temp
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Mozilla
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\Microsoft Help
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Local\Microsoft
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Media Center Programs
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData\Roaming\Macromedia
[2012/10/27 16:15:54 | 000,000,000 | ---D | C] -- C:\Users\Cinjo\AppData
[2012/10/25 05:02:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/10/25 04:44:13 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/25 04:44:13 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/25 04:44:13 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/25 04:43:56 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/23 16:00:15 | 000,000,000 | ---D | C] -- C:\FRST
[2012/10/21 14:23:35 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/10/09 17:30:29 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012/10/09 17:30:21 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012/10/09 17:30:21 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
========== Files - Modified Within 30 Days ========== [2012/10/28 19:17:50 | 000,000,224 | ---- | M] () -- C:\Users\Cinjo\Desktop\Geeks to Go! – Tech experts answer your questions.url
[2012/10/28 19:16:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/28 19:09:54 | 000,881,854 | ---- | M] () -- C:\Users\Cinjo\Desktop\SecurityCheck.exe
[2012/10/28 19:06:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/28 17:37:47 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/28 17:36:47 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/28 17:36:47 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/28 17:36:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/28 15:19:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTL.exe
[2012/10/28 14:40:11 | 000,625,972 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/10/28 14:40:11 | 000,112,670 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/10/28 14:35:48 | 000,025,894 | ---- | M] () -- C:\Users\Cinjo\Desktop\taryn's resume 10.29.2012.pdf
[2012/10/28 14:23:09 | 000,006,144 | ---- | M] () -- C:\Users\Cinjo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/28 03:15:31 | 000,000,320 | ---- | M] () -- C:\Users\Cinjo\Desktop\Danny Sparks BorthwickObit Honolulu HI.url
[2012/10/27 17:10:41 | 000,000,914 | ---- | M] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/25 19:31:28 | 001,580,544 | ---- | M] () -- C:\Users\Cinjo\Desktop\RogueKiller.exe
[2012/10/25 05:02:16 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/10/25 04:42:16 | 004,988,915 | R--- | M] (Swearware) -- C:\Users\Cinjo\Desktop\ComboFix.exe
[2012/10/25 03:59:21 | 002,213,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Cinjo\Desktop\tdsskiller.exe
[2012/10/25 03:58:33 | 000,399,264 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Cinjo\Desktop\unhide.exe
[2012/10/24 03:32:13 | 000,000,877 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/21 05:55:26 | 000,061,440 | ---- | M] ( ) -- C:\Users\Cinjo\Desktop\VEW.exe
[2012/10/21 04:36:54 | 000,646,656 | ---- | M] (OldTimer Tools) -- C:\Users\Cinjo\Desktop\OTS.scr
[2012/10/20 03:07:53 | 000,694,323 | ---- | M] (Farbar) -- C:\Users\Cinjo\Desktop\FSS.exe
[2012/10/19 19:22:33 | 000,001,570 | ---- | M] () -- C:\Users\Cinjo\Desktop\remove.reg
[2012/10/19 18:54:44 | 000,000,685 | ---- | M] () -- C:\Users\Cinjo\Desktop\ERUNT.lnk
[2012/10/19 04:52:38 | 000,357,256 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/10/14 15:22:31 | 000,049,799 | ---- | M] () -- C:\Users\Cinjo\Documents\taryn's resume (skilled based).rtf
[2012/10/11 15:11:51 | 000,000,057 | ---- | M] () -- C:\ProgramData\Ament.ini
[2012/10/09 03:16:11 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/10/09 03:16:11 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/10/02 03:02:24 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ========== [2012/10/28 19:09:46 | 000,881,854 | ---- | C] () -- C:\Users\Cinjo\Desktop\SecurityCheck.exe
[2012/10/28 14:39:14 | 000,025,894 | ---- | C] () -- C:\Users\Cinjo\Desktop\taryn's resume 10.29.2012.pdf
[2012/10/28 14:22:48 | 000,006,144 | ---- | C] () -- C:\Users\Cinjo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/27 17:06:49 | 000,001,082 | ---- | C] () -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/10/27 17:06:04 | 000,001,865 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/10/27 17:06:04 | 000,001,691 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2012/10/27 17:06:04 | 000,000,949 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/10/27 17:06:04 | 000,000,914 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/27 17:06:04 | 000,000,901 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/10/27 17:06:04 | 000,000,783 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2012/10/27 17:06:04 | 000,000,430 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Dan's Pages - Shortcut.lnk
[2012/10/27 16:52:28 | 000,392,271 | ---- | C] () -- C:\Users\Cinjo\Documents\roasterbook.pdf
[2012/10/27 16:52:28 | 000,111,552 | ---- | C] () -- C:\Users\Cinjo\Documents\thank you card.gif
[2012/10/27 16:52:28 | 000,049,799 | ---- | C] () -- C:\Users\Cinjo\Documents\taryn's resume (skilled based).rtf
[2012/10/27 16:52:28 | 000,046,238 | ---- | C] () -- C:\Users\Cinjo\Documents\bookmark.htm
[2012/10/27 16:52:28 | 000,024,646 | ---- | C] () -- C:\Users\Cinjo\Documents\HDTune_Benchmark_TOSHIBA_MK1246GSX.png
[2012/10/27 16:52:28 | 000,000,478 | ---- | C] () -- C:\Users\Cinjo\Documents\joe resume.rtf
[2012/10/27 16:44:17 | 000,061,440 | ---- | C] ( ) -- C:\Users\Cinjo\Desktop\VEW.exe
[2012/10/27 16:44:17 | 000,000,166 | ---- | C] () -- C:\Users\Cinjo\Desktop\VirSCAN.org - Free Multi-Engine Online Virus Scanner v1.02, Supports 37 AntiVirus Engines!.url
[2012/10/27 16:44:17 | 000,000,133 | ---- | C] () -- C:\Users\Cinjo\Desktop\Ukulele Resource Page - Learn to play ukulele!.url
[2012/10/27 16:44:14 | 001,580,544 | ---- | C] () -- C:\Users\Cinjo\Desktop\RogueKiller.exe
[2012/10/27 16:44:14 | 000,484,445 | ---- | C] () -- C:\Users\Cinjo\Desktop\Silent Runners.vbs
[2012/10/27 16:44:14 | 000,001,570 | ---- | C] () -- C:\Users\Cinjo\Desktop\remove.reg
[2012/10/27 16:44:12 | 000,067,284 | ---- | C] () -- C:\Users\Cinjo\Desktop\ListenToYouTube.mht
[2012/10/27 16:44:12 | 000,000,954 | ---- | C] () -- C:\Users\Cinjo\Desktop\Launch Internet Explorer Browser.lnk
[2012/10/27 16:44:12 | 000,000,612 | ---- | C] () -- C:\Users\Cinjo\Desktop\jodysphonenumbers - Shortcut.lnk
[2012/10/27 16:44:12 | 000,000,126 | ---- | C] () -- C:\Users\Cinjo\Desktop\moms flower store.url
[2012/10/27 16:44:11 | 000,066,503 | ---- | C] () -- C:\Users\Cinjo\Desktop\Dads page.htm
[2012/10/27 16:44:11 | 000,000,766 | ---- | C] () -- C:\Users\Cinjo\Desktop\Blueline - Shortcut.lnk
[2012/10/27 16:44:11 | 000,000,685 | ---- | C] () -- C:\Users\Cinjo\Desktop\ERUNT.lnk
[2012/10/27 16:44:11 | 000,000,320 | ---- | C] () -- C:\Users\Cinjo\Desktop\Danny Sparks BorthwickObit Honolulu HI.url
[2012/10/27 16:44:11 | 000,000,224 | ---- | C] () -- C:\Users\Cinjo\Desktop\Geeks to Go! – Tech experts answer your questions.url
[2012/10/27 16:44:11 | 000,000,152 | ---- | C] () -- C:\Users\Cinjo\Desktop\December 21 2012 • View topic - March 11, 2011 a Massive Earthquake - your thoughts.url
[2012/10/27 16:44:10 | 000,889,856 | ---- | C] () -- C:\Users\Cinjo\Desktop\ANOTB.exe
[2012/10/27 16:40:18 | 000,024,085 | ---- | C] () -- C:\Users\Cinjo\AppData\Roaming\UserTile.png
[2012/10/27 16:17:21 | 000,000,920 | ---- | C] () -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/10/27 16:17:17 | 000,000,915 | ---- | C] () -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/10/27 16:17:08 | 000,000,886 | ---- | C] () -- C:\Users\Cinjo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2012/10/27 16:15:54 | 000,000,258 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/10/27 16:15:54 | 000,000,240 | ---- | C] () -- C:\Users\Cinjo\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/10/25 04:44:13 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/25 04:44:13 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/25 04:44:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/25 04:44:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/25 04:44:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/11 15:11:51 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/05/11 14:36:56 | 000,188,863 | ---- | C] () -- C:\Windows\hpwins22.dat.temp
[2012/05/11 14:36:55 | 000,002,979 | ---- | C] () -- C:\Windows\hpwmdl22.dat.temp
[2011/12/13 16:31:03 | 000,150,612 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2011/06/28 14:44:58 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/04/24 05:05:40 | 000,011,232 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2010/12/31 15:23:44 | 000,077,376 | ---- | C] () -- C:\Windows\hpqins05.dat
[2010/05/20 20:31:31 | 000,005,115 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
========== ZeroAccess Check ========== [2006/11/02 02:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 07:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 20:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 20:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2010/08/06 17:43:15 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\298C9C7DADAA7E8E26A337A4FE989565
[2012/05/11 19:18:47 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\Octoshape
[2012/09/21 15:08:18 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\PDF reDirect
[2010/08/10 05:05:16 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\PeerNetworking
[2011/11/29 08:22:45 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\Samsung
[2012/01/26 05:14:19 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\TOSHIBA
[2010/09/22 02:35:35 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\Ulead Systems
[2010/03/23 03:08:09 | 000,000,000 | ---D | M] -- C:\Users\Cindy\AppData\Roaming\WinBatch
[2010/08/06 17:43:15 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\298C9C7DADAA7E8E26A337A4FE989565
[2012/05/11 19:18:47 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\Octoshape
[2012/10/27 16:43:47 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\PDF reDirect
[2010/08/10 05:05:16 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\PeerNetworking
[2011/11/29 08:22:45 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\Samsung
[2012/10/27 16:43:54 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\TOSHIBA
[2012/10/27 16:43:54 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\Ulead Systems
[2012/10/27 16:43:54 | 000,000,000 | ---D | M] -- C:\Users\Cinjo\AppData\Roaming\WinBatch
[2010/11/13 02:22:36 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\OnlineArmor
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
Extras.txt
OTL Extras logfile created on: 10/28/2012 7:18:08 PM - Run 12
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Cinjo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19328)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 47.73% Memory free
3.98 Gb Paging File | 2.98 Gb Available in Paging File | 74.89% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 47.28 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
Computer Name: CINDY-PC | User Name: Cinjo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
https [open] -- Reg Error: Value error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UpdatesDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{024864D8-9EDF-43C6-B144-D2A7A11D9A42}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0957B8CC-BD1E-4C02-8A96-DBD11B5DF6D2}" = lport=139 | protocol=6 | dir=in | app=system |
"{208838A3-8460-4580-AB5C-0F021799C9C7}" = rport=445 | protocol=6 | dir=out | app=system |
"{27FDEB3A-5284-4048-8CF6-EE1310D75892}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2A733626-7291-4B5B-91FC-17735696B2CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{35B03953-554C-4846-96A2-2919DA852E6D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3A616F37-29FA-45D5-BBD0-B31CADE42962}" = rport=139 | protocol=6 | dir=out | app=system |
"{4B1DB43E-BE49-4BB5-9097-50D60ADDD7DA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4D1EF7FD-0C17-4F02-AD3B-405F729058E1}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{51018119-318D-45C0-AD1B-6AF928EF2230}" = lport=445 | protocol=6 | dir=in | app=system |
"{551E1B5B-88BA-4133-A6B2-50ACF82C2B28}" = rport=10243 | protocol=6 | dir=out | app=system |
"{591CAAA6-6184-417E-B390-F7F79ADFB709}" = lport=138 | protocol=17 | dir=in | app=system |
"{5F55AD6A-0E83-44CB-AA90-63E2B89F6094}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5F6B4DB5-450A-4647-8D06-6396CB067101}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss |
[email protected],-28539 |
"{603A8BD0-4143-44BC-803D-4A9405B04EE8}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6CB72BF9-A452-4C40-898C-C73B211A16AC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7D1F31F4-491D-410B-A79A-1FE46C2052C9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{81E1D8CD-3AE2-4DF5-AFF4-0C82BC7D8340}" = rport=138 | protocol=17 | dir=out | app=system |
"{8643C9D3-0E46-4AD5-8251-18B43F70203F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{92DEDBC8-C5E5-4CC3-A308-678C6B9C0DF5}" = lport=137 | protocol=17 | dir=in | app=system |
"{A01BF944-EB34-44A6-8906-2AB4B9DCAE8D}" = lport=54010 | protocol=6 | dir=in | name=samsung allshare slideshow service |
"{AABE8393-2CC8-4AD7-86BC-990B0A639FF0}" = rport=137 | protocol=17 | dir=out | app=system |
"{B9DAC50E-FA64-4B15-81DE-A733E2713DA4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C0779F60-15BB-4B52-9E04-938CC6C953F5}" = lport=10243 | protocol=6 | dir=in | app=system |
"{C846A653-4160-4986-AA0E-826CC05EB98A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E15C37CE-82D8-4CE1-B6DA-00B46F4F960A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E33CA958-721F-44F0-BDBF-DC38CAC91E39}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E342FAB8-FC13-4C1A-A9F7-8B63A10D45C4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{ED0EC886-E17F-4C00-A8BF-3894C9148350}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A73A87C-7E73-438C-90E9-1F79DA6BB56E}" = protocol=6 | dir=in | app=c:\windows\temp\7zs210b.tmp\symnrt.exe |
"{0E678A61-1B63-48B8-93D8-98805F397F23}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung pc share manager\wiselinkpro.exe |
"{0F5B07A5-6FCE-40DC-A386-CD59196FA0E9}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung pc share manager\wiselinkpro.exe |
"{13A1D8AF-4967-4CFD-9AAE-AC80F622645E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1A179ADC-795D-4C92-8CD5-FCAF82607811}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{249AF4DF-780F-44EE-A174-A50FCA839DE8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{2622A955-DF8E-4383-B6B5-22F13ECDCE99}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{279BA005-70A8-4F85-BEB6-531CA6D60504}" = protocol=1 | dir=in |
[email protected],-28543 |
"{29149483-E719-407C-87D1-ADF2BE1540CE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2C5FE000-3847-4529-B6A0-47A4C7B1E622}" = protocol=17 | dir=in | app=c:\windows\temp\7zs2d15\hpdiagnosticcoreui.exe |
"{30226DEA-83A9-46CE-96FE-0C99C6A0F42D}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung pc share manager\http_ss_win_pro.exe |
"{3FC59BBF-0E34-4D0E-AE38-70DEE7F72AFE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3FD2854E-4457-41FE-9ED7-7F97CC05E9A9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4112C661-99A3-4EB8-9B0E-EC4670264DF9}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{4D4EF25F-711E-43A4-A151-F8190F544E49}" = dir=in | app=c:\program files\samsung\allshare\allshareagent.exe |
"{52B9B602-8377-4ECD-86EF-50B8F9A60671}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{567D0144-38BA-47A4-AC99-EBD1907FE18E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5A4C89DE-02FA-408B-B89C-7475C608EC7E}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{5C385125-0B57-43C0-BC08-97F8EABB8978}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6CFFDE67-18DE-4E27-8559-D89F46303C98}" = protocol=1 | dir=out |
[email protected],-28544 |
"{6F4D0CAA-DB95-4873-B721-44015076EE92}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7AE1CBF8-1762-45BC-9F85-B4E93FF09D7A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7AFC3082-24A0-4D00-93EC-8B1A5D984831}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{7B196B37-D22C-4187-BCC3-BB752A083141}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung pc share manager\http_ss_win_pro.exe |
"{7BF90766-CDC0-412F-BAD9-4A90810D51FA}" = protocol=17 | dir=in | app=c:\windows\temp\7zs210b.tmp\symnrt.exe |
"{82D894EF-B995-4DE0-8888-7BD33734D3A4}" = dir=in | app=d:\setup\hpznui01.exe |
"{836C3E0B-30F0-410C-B39D-0C2107895D2D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{93B7C916-0144-4125-B964-5CDF9C144B79}" = dir=in | app=c:\program files\samsung\allshare\allsharedms\allsharedms.exe |
"{992B8D05-ECE2-465C-BA71-C9BD8070DC7F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{99672142-FFAD-4B07-8C1A-729FC9CD545E}" = protocol=58 | dir=out |
[email protected],-28546 |
"{9DD456BA-2685-40E9-B640-639BED8AD6D0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{A74FCAD5-125C-40B2-B544-E80DD02F22A3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AEDD65D0-C0AC-44E0-90EA-D093BA357BE5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{B1338F43-F9CE-4ACD-938B-9087FFFE416D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B5D5DDFC-43BB-4FEE-A38C-DA9CC1A2BC54}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BBD5A3D5-239F-4DFC-981E-CC9005EDBD74}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C0D52D64-9409-45CB-8119-8B95025EF1D6}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C8DF7560-20F2-4C10-AFCC-406E22FB177C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CC4A4B96-24CC-45F0-8E2E-C8B2BACD299D}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{CC6B71EF-1BEF-462B-A9DF-611B4D3F6A91}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CFA8155F-592E-49C0-B6C5-E55AA15985D8}" = dir=in | app=c:\program files\samsung\allshare\allshare.exe |
"{D698795C-B283-4702-BB5C-1BB753864680}" = protocol=6 | dir=out | app=system |
"{DEE4E370-FE06-409A-AE71-9CF77DA6AF12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5AF2C54-BDC3-4932-AF61-4F9BB74EB4F9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{E9AFD4DF-5107-4850-AD47-F29798EA0809}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EC137608-436E-434F-BE8D-6B380FDD855E}" = protocol=58 | dir=in |
[email protected],-28545 |
"{F1689418-10F3-42DA-8D54-41FB8959B1E9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F1E1B2A6-5D10-4860-84A5-B4B07652559B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F9459D96-6F32-423E-A507-28186354A5BD}" = protocol=6 | dir=in | app=c:\windows\temp\7zs2d15\hpdiagnosticcoreui.exe |
"TCP Query User{0971A184-A58B-4AA5-9924-0C9383DAE1BE}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{CAB65313-8F88-4A6B-BA3C-52DF5360F12A}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{471CD80E-02F4-4A43-8196-E2A8EB8B117C}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{224821ED-CADA-4A8A-AC8D-3734CC0F0931}" = Amazon Links
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java 7
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73B52EA8-8A5C-4FF5-A9F2-1A0F3259C3D2}" = TOSHIBA Application Disc Creator
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}" = QuickBooks Financial Center
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{99D518AB-77F2-405B-B52A-18FC22394CF8}" = NetZero Internet Access Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A2E5F2AA-2996-41EA-BCCD-9FD0476A5326}" = TWC Customer Controls
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E1E56B8A-1AAF-422A-91DB-625059FB9863}" = TOSHIBA Desktop Links
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EDC842C6-5607-48B9-A0B2-7D8B9BC57333}" = AD_Install
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Belarc Advisor" = Belarc Advisor 8.1
"Blueline_is1" = Blueline 1.1.1
"ERUNT_is1" = ERUNT 1.1j
"Google Desktop" = Google Desktop
"HD Tune_is1" = HD Tune 2.55
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"md5Base_is1" = md5Base version 1.2.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Picasa 3" = Picasa 3
"RealPlayer 15.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Zuma Deluxe" = Zuma Deluxe
========== Last 20 Event Log Errors ========== [ Application Events ]
Error - 10/28/2012 9:04:41 PM | Computer Name = Cindy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 10/28/2012 9:04:41 PM | Computer Name = Cindy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 44741
Error - 10/28/2012 9:04:41 PM | Computer Name = Cindy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 44741
Error - 10/28/2012 9:33:46 PM | Computer Name = Cindy-PC | Source = WinMgmt | ID = 10
Description =
Error - 10/28/2012 9:35:17 PM | Computer Name = Cindy-PC | Source = profsvc | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - The system cannot
find the file specified.
Error - 10/28/2012 9:35:21 PM | Computer Name = Cindy-PC | Source = profsvc | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - The system cannot
find the file specified.
Error - 10/28/2012 9:36:26 PM | Computer Name = Cindy-PC | Source = profsvc | ID = 1542
Description = Windows cannot load classes registry file. DETAIL - The system cannot
find the file specified.
Error - 10/28/2012 9:36:46 PM | Computer Name = Cindy-PC | Source = TOSHIBA Service Station | ID = 0
Description = Access to the temp directory is denied. Identity 'Cindy-PC\Cindy'
under which XmlSerializer is running does not have sufficient permission to access
the temp directory. CodeDom will use the user account the process is using to
do the compilation, so if the user doesnt have access to system temp directory,
you will not be able to compile. Use Path.GetTempPath() API to find out the temp
directory location.
Error - 10/28/2012 9:36:46 PM | Computer Name = Cindy-PC | Source = TOSHIBA Service Station | ID = 0
Description = TSS Load: could not communicate with TMachInfo service
Error - 10/28/2012 11:38:10 PM | Computer Name = Cindy-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 10/27/2012 10:16:11 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10010
Description =
Error - 10/27/2012 10:20:33 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10010
Description =
Error - 10/27/2012 11:09:39 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10010
Description =
Error - 10/28/2012 1:27:53 AM | Computer Name = Cindy-PC | Source = DCOM | ID = 10016
Description =
Error - 10/28/2012 7:53:22 AM | Computer Name = Cindy-PC | Source = DCOM | ID = 10016
Description =
Error - 10/28/2012 5:14:23 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10016
Description =
Error - 10/28/2012 5:24:58 PM | Computer Name = Cindy-PC | Source = Schannel | ID = 36874
Description = An SSL connection request was received from a remote client application,
but none of the cipher suites supported by the client application are supported
by the server. The SSL connection request has failed.
Error - 10/28/2012 9:33:44 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10016
Description =
Error - 10/28/2012 11:35:17 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10010
Description =
Error - 10/28/2012 11:38:33 PM | Computer Name = Cindy-PC | Source = DCOM | ID = 10016
Description =
< End of report >
And it's runnin' very spiffy, thank you! It's a much happier computer. I think my PL is going to be a 'lil late tho. Any idea what exactly happened? I know it's been not quite right and getting progressively worse.
I know I have some uninstalls (Offices) and updates, but I was waiting until this is all pau first. Thank you! Thank you
Please let me know if there's anything else?