My AppleID password hasn't work twice in the past couple weeks and I have had to reset it using the security questions both times. I am pretty sure it has been reset by someone else.
My computer has been crashing frequently.. this has never happened before.
There are pictures randomly appearing in My Documents of screenshots of my Fidelity balances(!!). In the log those show up as the Balance_###.html files. Note I retracted the account numbers for privacy.
I think this problem started a month or so ago when my son copied a bunch of music into a shared dropbox folder and it installed on my pc and suddenly virus warnings went off. I can't remember if it was MSE or Malwarebytes, as I have both running on my computer (with Malwarebytes set up to ignore MSE files). I disabled Malwarebytes very recently (after the virus symptoms started) to gain more free memory because it seemed like that was causing some of the crashing.
I am resetting all my passwords from a clean computer right now and will shut down this computer until I receive advice on what to do next.
Thanks.
--
OTL Log:
OTL logfile created on: 11/16/2012 4:07:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ira\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 42.54% Memory free
6.18 Gb Paging File | 4.44 Gb Available in Paging File | 71.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.32 Gb Total Space | 98.07 Gb Free Space | 45.54% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 9.60 Gb Free Space | 64.00% Space Free | Partition Type: NTFS
Computer Name: IRA-PC | User Name: Ira | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/11/16 16:06:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ira\Downloads\OTL.exe
PRC - [2012/10/31 17:15:08 | 001,242,136 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2012/10/26 14:24:12 | 001,017,184 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2012/10/26 14:14:36 | 011,715,424 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\Evernote.exe
PRC - [2012/10/26 14:14:36 | 000,395,104 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteTray.exe
PRC - [2012/09/29 18:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/12 16:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 16:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 16:19:44 | 000,947,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/08/09 22:12:18 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
PRC - [2012/07/05 17:09:38 | 000,136,616 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2012/07/05 17:09:34 | 002,114,984 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe
PRC - [2012/07/05 17:09:32 | 000,374,184 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2012/06/08 11:06:24 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2012/06/08 11:06:24 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2011/06/09 12:01:00 | 000,521,600 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\epson\EpsonCustomerParticipation\EPCP.exe
PRC - [2011/04/10 15:06:42 | 000,951,656 | ---- | M] (DisplayLink Corp.) -- C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
PRC - [2011/04/10 15:06:40 | 000,730,472 | ---- | M] (DisplayLink Corp.) -- C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
PRC - [2011/04/10 15:06:38 | 005,240,168 | ---- | M] (DisplayLink Corp.) -- C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
PRC - [2011/04/08 07:50:02 | 000,542,264 | ---- | M] (Google) -- C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
PRC - [2011/03/08 23:00:00 | 000,856,064 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
PRC - [2011/03/08 23:00:00 | 000,495,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe
PRC - [2011/02/18 10:47:12 | 000,079,192 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2010/10/12 12:56:40 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/05/04 04:25:32 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 04:25:26 | 000,167,936 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 04:25:26 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/11/12 06:07:24 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
PRC - [2007/11/12 06:07:20 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/11/12 06:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/08/28 00:51:42 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM02Mon.exe
PRC - [2007/03/21 14:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/03/21 14:00:00 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
========== Modules (No Company Name) ==========
MOD - [2012/10/31 17:15:05 | 000,460,312 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\ppgooglenaclpluginchrome.dll
MOD - [2012/10/31 17:15:04 | 012,455,448 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
MOD - [2012/10/31 17:15:02 | 004,007,448 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\pdf.dll
MOD - [2012/10/31 17:13:35 | 000,156,712 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\avutil-51.dll
MOD - [2012/10/31 17:13:34 | 000,274,984 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\avformat-54.dll
MOD - [2012/10/31 17:13:32 | 002,168,360 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll
MOD - [2012/09/08 12:16:30 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2012/09/08 12:16:20 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2012/08/29 06:50:42 | 021,009,920 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libcef.dll
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/07/04 16:32:36 | 000,004,608 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2010/07/04 14:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
========== Services (SafeList) ==========
SRV - [2012/10/09 10:21:20 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/29 18:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 18:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/12 16:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/09/12 16:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/09/05 20:26:40 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/05 17:09:38 | 000,136,616 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\ramaint.exe -- (LMIMaint)
SRV - [2012/07/05 17:09:32 | 000,374,184 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2012/06/08 11:06:24 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2011/06/09 12:01:00 | 000,521,600 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\epson\EpsonCustomerParticipation\EPCP.exe -- (EpsonCustomerParticipation)
SRV - [2011/04/10 15:06:38 | 005,240,168 | ---- | M] (DisplayLink Corp.) [Auto | Running] -- C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe -- (DisplayLinkService)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/12 06:07:20 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/11/12 06:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ==========
DRV - [2012/11/16 11:53:39 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{52BB06D7-3FA5-46E2-B854-331EC90EB6A0}\MpKsl9ccc6c9e.sys -- (MpKsl9ccc6c9e)
DRV - [2012/09/29 18:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/08/30 21:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/07/05 17:10:02 | 000,083,392 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2012/06/08 11:06:24 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2012/06/08 11:06:24 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2011/04/10 20:08:50 | 000,021,888 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\DisplayLinkUsbPort_5.6.31854.0.sys -- (DisplayLinkUsbPort)
DRV - [2011/04/10 15:07:03 | 000,182,896 | ---- | M] (DisplayLink Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dlkmd.sys -- (dlkmd)
DRV - [2011/04/10 15:07:03 | 000,027,648 | ---- | M] (DisplayLink Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DisplayLinkGAport.sys -- (DisplayLinkGA)
DRV - [2011/04/10 15:07:03 | 000,024,448 | ---- | M] (DisplayLink Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DisplayLinkmirrorport.sys -- (DisplayLinkmirror)
DRV - [2011/04/10 15:07:03 | 000,014,448 | ---- | M] (DisplayLink Corp.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\dlkmdldr.sys -- (dlkmdldr)
DRV - [2010/07/04 14:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2008/06/23 07:45:44 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/05/04 04:25:24 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/03/06 02:58:44 | 000,111,616 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2008/01/20 21:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2008/01/20 21:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007/11/12 06:07:28 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/10/10 17:03:00 | 000,235,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/09/26 08:12:00 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007/09/06 11:35:16 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/09/06 11:35:14 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/09/06 11:35:12 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/08/28 00:51:44 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2006/11/02 02:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.dell.com
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/...q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/...q={searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://loginprodx.a...ps&OLDSESSION="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/14 09:19:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/14 09:19:34 | 000,000,000 | ---D | M]
[2012/10/04 19:08:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ira\AppData\Roaming\Mozilla\Extensions
[2012/10/24 15:29:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ira\AppData\Roaming\Mozilla\Firefox\Profiles\w095yorr.default\extensions
[2012/10/04 19:09:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/09/08 10:51:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/12 08:36:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/09/05 20:27:05 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/20 11:56:43 | 000,091,584 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2012/06/20 11:56:44 | 000,091,584 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/08/14 16:49:30 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2012/08/30 10:38:59 | 000,003,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/09/05 20:26:22 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/05 20:26:22 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.att.yahoo.com/mail
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.att.yahoo.com/mail
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 6 U35 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Vuru = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjkomipldgcookljbkgffaegdaaohllb\2.0_0\
CHR - Extension: YouTube = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: LastPass = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.14_0\
CHR - Extension: RSS Subscription Extension (by Google) = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.0_0\
CHR - Extension: Evernote Web Clipper = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.8_0\
CHR - Extension: Google Reader = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0\
CHR - Extension: Gmail = C:\Users\Ira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AffixaPersonalSettings] C:\Program Files\Affixa\AffixaHandler.exe (Notably Good Ltd)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXRCV] C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIHVA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe File not found
O4 - HKCU..\Run: [PxDotNetLoader] C:\Program Files\Fidelity Investments\Fidelity Active Trader\System\ATPStartupAssistant.exe (Fidelity Investments)
O4 - Startup: C:\Users\Ira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ira\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Ira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.68.162 68.87.74.162 10.1.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9297EE24-D99A-4587-AF5B-874E7D15022E}: DhcpNameServer = 68.87.68.162 68.87.74.162 10.1.10.1
O18 - Protocol\Handler\x-atng {7e8717b0-d862-11d5-8c9e-00010304f989} - C:\Program Files\Fidelity Investments\Fidelity Active Trader\System\atngprot.dll (Fidelity Investments)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ira\Pictures\favorites\bryce, zion, gc\zionlasvegas 013.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ira\Pictures\favorites\bryce, zion, gc\zionlasvegas 013.jpg
O27 - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3f44a66b-2f2d-11e0-b9b4-0023ae1521e0}\Shell - "" = AutoRun
O33 - MountPoints2\{3f44a66b-2f2d-11e0-b9b4-0023ae1521e0}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/11/16 15:26:05 | 000,000,000 | ---D | C] -- C:\Users\Ira\AppData\Local\MicrosoftStore
[2012/11/15 14:43:54 | 000,000,000 | ---D | C] -- C:\Jts
[2012/11/14 09:20:17 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/11/14 09:19:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 09:18:47 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/11/13 19:20:37 | 000,000,000 | ---D | C] -- C:\Users\Ira\Documents\ipad 3 surely redundant
[2012/11/13 14:01:25 | 000,000,000 | -HSD | C] -- C:\Users\Ira\Documents\cache
[2012/11/13 14:01:19 | 000,000,000 | ---D | C] -- C:\Users\Ira\AppData\Roaming\webex
[2012/11/13 14:00:50 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2012/11/12 12:13:03 | 000,000,000 | ---D | C] -- C:\Program Files\Database Oasis
[2012/11/12 12:13:02 | 000,000,000 | ---D | C] -- C:\Users\Ira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Database Oasis
[2012/11/04 12:55:34 | 000,000,000 | --SD | C] -- C:\Users\Ira\Documents\My Data Sources
[2012/10/29 10:12:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2012/10/25 08:49:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/08/13 14:20:21 | 000,454,120 | ---- | C] (CBS Interactive) -- C:\Users\Ira\cnet_spywareblastersetup44_exe.exe
[2011/07/25 11:09:39 | 016,208,688 | ---- | C] (Dropbox, Inc.) -- C:\Users\Ira\Dropbox 1.1.35.exe
========== Files - Modified Within 30 Days ==========
[2012/11/16 16:06:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/16 16:06:00 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/16 15:21:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/16 14:22:08 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 14:22:08 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 13:35:01 | 000,005,627 | ---- | M] () -- C:\Users\Ira\Documents\Positions by Account for Ira and Carrie.csv
[2012/11/16 11:50:28 | 000,106,562 | ---- | M] () -- C:\Users\Ira\Documents\JCP VL nov 2012.pdf
[2012/11/16 08:29:54 | 000,640,658 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/11/16 08:29:54 | 000,118,878 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/11/16 08:23:29 | 000,000,426 | ---- | M] () -- C:\Windows\tasks\SyncBack Ira Backup.job
[2012/11/16 08:22:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/16 08:22:02 | 3210,784,768 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/16 08:21:11 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/11/15 15:38:45 | 000,000,940 | ---- | M] () -- C:\Users\Ira\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/11/14 13:38:08 | 000,067,656 | ---- | M] () -- C:\Users\Ira\Documents\RRD E release 3Q 2012.pdf
[2012/11/14 11:30:53 | 000,062,750 | ---- | M] () -- C:\Users\Ira\Documents\IGT trade chart.pdf
[2012/11/14 11:09:18 | 000,080,545 | ---- | M] () -- C:\Users\Ira\Documents\WTW VL nov 2012.pdf
[2012/11/14 10:32:19 | 000,039,485 | ---- | M] () -- C:\Users\Ira\Documents\RAD ATP chart.pdf
[2012/11/14 10:10:19 | 000,270,568 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/11/14 09:20:58 | 000,002,651 | ---- | M] () -- C:\Users\Ira\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2012/11/13 15:05:00 | 004,664,231 | ---- | M] () -- C:\Users\Ira\Documents\Jeffereis PB pitch v12.1pptx.pdf
[2012/11/13 13:02:29 | 000,120,147 | ---- | M] () -- C:\Users\Ira\Documents\IGT VL nov 2012.pdf
[2012/11/13 11:13:38 | 000,080,115 | ---- | M] () -- C:\Users\Ira\Documents\IGT E disc QE.pdf
[2012/11/13 10:10:09 | 000,054,197 | ---- | M] () -- C:\Users\Ira\Documents\JCP chart nov 14 2012.pdf
[2012/11/13 09:26:20 | 000,200,426 | ---- | M] () -- C:\Users\Ira\Documents\hedging strategies using options.pdf
[2012/11/12 20:57:54 | 000,002,609 | ---- | M] () -- C:\Users\Ira\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2012/11/12 20:57:36 | 000,108,449 | ---- | M] () -- C:\Users\Ira\Documents\DO VL nov 2012.pdf
[2012/11/12 14:51:40 | 000,122,357 | ---- | M] () -- C:\Users\Ira\Documents\short int test.pdf
[2012/11/12 14:14:37 | 000,242,883 | ---- | M] () -- C:\Users\Ira\Documents\GoDaddy 1 yr renewal.pdf
[2012/11/12 13:43:27 | 002,296,282 | ---- | M] () -- C:\Users\Ira\Documents\IAB singleFundGetStarted.pdf
[2012/11/12 12:17:45 | 000,183,294 | ---- | M] () -- C:\Users\Ira\Documents\Database Oasis purchase receipt.pdf
[2012/11/12 12:13:19 | 000,001,831 | ---- | M] () -- C:\Users\Ira\Desktop\Database Oasis.lnk
[2012/11/12 11:14:43 | 000,039,092 | ---- | M] () -- C:\Users\Ira\Documents\RRD VL nov 2012.pdf
[2012/11/12 10:45:32 | 000,176,392 | ---- | M] () -- C:\Users\Ira\Documents\RRD S&P neg outlook.pdf
[2012/11/10 11:11:06 | 000,474,331 | ---- | M] () -- C:\Users\Ira\Documents\bond funds.pdf
[2012/11/10 10:22:46 | 000,083,277 | ---- | M] () -- C:\Users\Ira\Documents\HPQ VL oct 2012.pdf
[2012/11/08 10:54:36 | 000,607,527 | ---- | M] () -- C:\Users\Ira\Documents\interactive broker friends family advisor example.pdf
[2012/11/07 16:04:38 | 000,030,197 | ---- | M] () -- C:\Users\Ira\Documents\Balance_x(numbers retracted).html
[2012/11/07 16:04:38 | 000,030,158 | ---- | M] () -- C:\Users\Ira\Documents\Balance_X(numbers retracted).html
[2012/11/07 16:04:38 | 000,022,936 | ---- | M] () -- C:\Users\Ira\Documents\Balance_(numbers retracted).html
[2012/11/07 16:04:38 | 000,022,928 | ---- | M] () -- C:\Users\Ira\Documents\Balance_X(numbers retracted).html
[2012/11/07 16:04:33 | 000,000,000 | ---- | M] () -- C:\Users\Ira\Documents\about
[2012/11/07 12:08:01 | 000,031,311 | ---- | M] () -- C:\Users\Ira\Documents\Balance_Z(numbers retracted).html
[2012/11/07 11:51:05 | 000,010,755 | ---- | M] () -- C:\Users\Ira\Documents\Positions by Account retracted.csv
[2012/11/07 10:05:23 | 000,002,650 | ---- | M] () -- C:\Users\Ira\Documents\Account Balances (Brokerage).csv
[2012/11/05 13:43:05 | 000,399,897 | ---- | M] () -- C:\Users\Ira\Documents\Five ways to save a Web page _ How To - CNET.pdf
[2012/11/02 16:31:36 | 000,109,859 | ---- | M] () -- C:\Users\Ira\Documents\about_blank.pdf
[2012/11/02 11:16:38 | 000,008,597 | ---- | M] () -- C:\Users\Ira\Documents\VoluntaryCorporateActionPending10292012.pdf
[2012/11/01 15:37:35 | 000,566,723 | ---- | M] () -- C:\Users\Ira\Documents\L 10q Q3 2012.pdf
[2012/11/01 15:30:39 | 006,512,188 | ---- | M] () -- C:\Users\Ira\Documents\Investment Performance Measurement.pdf
[2012/11/01 08:09:51 | 000,021,438 | ---- | M] () -- C:\Users\Ira\Documents\oct 31 2012.csv
[2012/11/01 08:06:33 | 000,022,986 | ---- | M] () -- C:\Users\Ira\Documents\ACTIVITY month oct 12.csv
[2012/10/30 13:52:42 | 000,483,399 | ---- | M] () -- C:\Users\Ira\Documents\roger k estate tax article.pdf
[2012/10/28 09:59:44 | 000,000,000 | ---- | M] () -- C:\Users\Ira\Documents\LOG
[2012/10/28 09:51:09 | 000,014,112 | ---- | M] () -- C:\Users\Ira\Documents\ARI I.csv.ods
[2012/10/28 09:27:57 | 000,019,849 | ---- | M] () -- C:\Users\Ira\Documents\ARI I.csv
[2012/10/25 15:26:08 | 000,064,221 | ---- | M] () -- C:\Users\Ira\Documents\RRD VL aug 2012.pdf
[2012/10/25 09:12:47 | 000,033,895 | ---- | M] () -- C:\Users\Ira\Documents\FFIV VL sept 2012.pdf
[2012/10/24 10:21:00 | 001,292,619 | ---- | M] () -- C:\Users\Ira\Documents\photo my signature.JPG
[2012/10/24 10:16:32 | 000,019,968 | ---- | M] () -- C:\Users\Ira\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/23 13:41:39 | 000,101,003 | ---- | M] () -- C:\Users\Ira\Documents\JEF VL oct 2012.pdf
[2012/10/19 08:11:33 | 000,369,359 | ---- | M] () -- C:\Users\Ira\Documents\bookmarks_10_19_12.html
[2012/10/18 17:24:14 | 000,069,297 | ---- | M] () -- C:\Users\Ira\Documents\snapshot backup.JPG
[2012/10/18 15:19:46 | 000,002,143 | ---- | M] () -- C:\Users\Public\Desktop\Fidelity Active Trader Pro.lnk
[2012/10/18 15:19:46 | 000,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Fidelity Active Trader Pro Beta 9.7.lnk
========== Files Created - No Company Name ==========
[2012/11/16 13:34:59 | 000,005,627 | ---- | C] () -- C:\Users\Ira\Documents\Positions by Account for Ira and Carrie.csv
[2012/11/16 11:35:27 | 000,106,562 | ---- | C] () -- C:\Users\Ira\Documents\JCP VL nov 2012.pdf
[2012/11/15 10:15:25 | 3210,784,768 | -HS- | C] () -- C:\hiberfil.sys
[2012/11/14 13:37:02 | 000,067,656 | ---- | C] () -- C:\Users\Ira\Documents\RRD E release 3Q 2012.pdf
[2012/11/14 11:28:40 | 000,062,750 | ---- | C] () -- C:\Users\Ira\Documents\IGT trade chart.pdf
[2012/11/14 11:01:16 | 000,080,545 | ---- | C] () -- C:\Users\Ira\Documents\WTW VL nov 2012.pdf
[2012/11/14 10:31:33 | 000,039,485 | ---- | C] () -- C:\Users\Ira\Documents\RAD ATP chart.pdf
[2012/11/13 11:19:42 | 000,120,147 | ---- | C] () -- C:\Users\Ira\Documents\IGT VL nov 2012.pdf
[2012/11/13 11:10:53 | 000,080,115 | ---- | C] () -- C:\Users\Ira\Documents\IGT E disc QE.pdf
[2012/11/13 10:08:39 | 000,054,197 | ---- | C] () -- C:\Users\Ira\Documents\JCP chart nov 14 2012.pdf
[2012/11/13 09:26:20 | 000,200,426 | ---- | C] () -- C:\Users\Ira\Documents\hedging strategies using options.pdf
[2012/11/12 19:30:48 | 000,108,449 | ---- | C] () -- C:\Users\Ira\Documents\DO VL nov 2012.pdf
[2012/11/12 14:45:44 | 000,122,357 | ---- | C] () -- C:\Users\Ira\Documents\short int test.pdf
[2012/11/12 14:14:37 | 000,242,883 | ---- | C] () -- C:\Users\Ira\Documents\GoDaddy 1 yr renewal.pdf
[2012/11/12 13:43:27 | 002,296,282 | ---- | C] () -- C:\Users\Ira\Documents\IAB singleFundGetStarted.pdf
[2012/11/12 12:17:45 | 000,183,294 | ---- | C] () -- C:\Users\Ira\Documents\Database Oasis purchase receipt.pdf
[2012/11/12 12:13:19 | 000,001,831 | ---- | C] () -- C:\Users\Ira\Desktop\Database Oasis.lnk
[2012/11/12 10:47:07 | 000,039,092 | ---- | C] () -- C:\Users\Ira\Documents\RRD VL nov 2012.pdf
[2012/11/12 10:35:34 | 000,176,392 | ---- | C] () -- C:\Users\Ira\Documents\RRD S&P neg outlook.pdf
[2012/11/10 11:11:00 | 000,474,331 | ---- | C] () -- C:\Users\Ira\Documents\bond funds.pdf
[2012/11/09 14:21:47 | 000,083,277 | ---- | C] () -- C:\Users\Ira\Documents\HPQ VL oct 2012.pdf
[2012/11/08 10:54:29 | 000,607,527 | ---- | C] () -- C:\Users\Ira\Documents\interactive broker friends family advisor example.pdf
[2012/11/07 11:51:03 | 000,010,755 | ---- | C] () -- C:\Users\Ira\Documents\Positions by Account retracted.csv
[2012/11/07 10:15:46 | 000,031,311 | ---- | C] () -- C:\Users\Ira\Documents\Balance_Z(numbers retracted).html
[2012/11/07 09:59:35 | 000,002,650 | ---- | C] () -- C:\Users\Ira\Documents\Account Balances (Brokerage).csv
[2012/11/05 13:43:05 | 000,399,897 | ---- | C] () -- C:\Users\Ira\Documents\Five ways to save a Web page _ How To - CNET.pdf
[2012/11/02 16:28:04 | 000,109,859 | ---- | C] () -- C:\Users\Ira\Documents\about_blank.pdf
[2012/11/02 11:16:23 | 000,008,597 | ---- | C] () -- C:\Users\Ira\Documents\VoluntaryCorporateActionPending10292012.pdf
[2012/11/01 15:30:36 | 006,512,188 | ---- | C] () -- C:\Users\Ira\Documents\Investment Performance Measurement.pdf
[2012/11/01 09:00:30 | 000,030,197 | ---- | C] () -- C:\Users\Ira\Documents\Balance_X(numbers retracted).html
[2012/11/01 09:00:15 | 000,030,158 | ---- | C] () -- C:\Users\Ira\Documents\Balance_(numbers retracted).html
[2012/11/01 09:00:15 | 000,022,936 | ---- | C] () -- C:\Users\Ira\Documents\Balance_(numbers retracted).html
[2012/11/01 09:00:15 | 000,022,928 | ---- | C] () -- C:\Users\Ira\Documents\Balance_X(numbers retracted).html
[2012/11/01 08:09:50 | 000,021,438 | ---- | C] () -- C:\Users\Ira\Documents\oct 31 2012.csv
[2012/11/01 08:06:30 | 000,022,986 | ---- | C] () -- C:\Users\Ira\Documents\ACTIVITY month oct 12.csv
[2012/10/30 13:52:42 | 000,483,399 | ---- | C] () -- C:\Users\Ira\Documents\roger k estate tax article.pdf
[2012/10/30 13:19:01 | 000,566,723 | ---- | C] () -- C:\Users\Ira\Documents\L 10q Q3 2012.pdf
[2012/10/28 09:59:44 | 000,000,000 | ---- | C] () -- C:\Users\Ira\Documents\LOG
[2012/10/28 09:51:09 | 000,014,112 | ---- | C] () -- C:\Users\Ira\Documents\ARI I.csv.ods
[2012/10/28 09:27:55 | 000,019,849 | ---- | C] () -- C:\Users\Ira\Documents\ARI I.csv
[2012/10/25 09:12:41 | 000,033,895 | ---- | C] () -- C:\Users\Ira\Documents\FFIV VL sept 2012.pdf
[2012/10/22 19:45:35 | 000,101,003 | ---- | C] () -- C:\Users\Ira\Documents\JEF VL oct 2012.pdf
[2012/10/19 08:11:32 | 000,369,359 | ---- | C] () -- C:\Users\Ira\Documents\bookmarks_10_19_12.html
[2012/10/18 17:24:12 | 000,069,297 | ---- | C] () -- C:\Users\Ira\Documents\snapshot backup.JPG
[2012/10/18 15:19:46 | 000,002,143 | ---- | C] () -- C:\Users\Public\Desktop\Fidelity Active Trader Pro.lnk
[2012/10/18 15:19:46 | 000,002,032 | ---- | C] () -- C:\Users\Public\Desktop\Fidelity Active Trader Pro Beta 9.7.lnk
[2012/10/06 10:53:58 | 000,000,079 | ---- | C] () -- C:\Windows\EWF645.ini
[2012/10/06 10:03:27 | 002,719,723 | ---- | C] () -- C:\Users\Ira\active trader pro manual.pdf
[2012/05/30 12:57:22 | 000,061,935 | ---- | C] () -- C:\Users\Ira\MLI VL may 2012.pdf
[2012/04/03 09:29:15 | 000,007,295 | ---- | C] () -- C:\Users\Ira\Irene 2011 exp for condo.csv
[2011/11/22 15:27:42 | 001,268,302 | ---- | C] () -- C:\Users\Ira\JEF 10Q ended 9_2011.pdf
[2011/11/09 10:59:23 | 000,000,000 | ---- | C] () -- C:\Windows\System32\dlumd9.dll
[2011/11/09 10:59:23 | 000,000,000 | ---- | C] () -- C:\Windows\System32\dlumd11.dll
[2011/11/09 10:59:23 | 000,000,000 | ---- | C] () -- C:\Windows\System32\dlumd10.dll
[2011/08/09 12:37:26 | 038,785,536 | ---- | C] () -- C:\Users\Ira\ATsetup.msi
[2011/08/04 08:18:09 | 001,035,926 | ---- | C] () -- C:\Users\Ira\MozBackup-1.5.1-EN.exe
[2011/06/30 14:49:42 | 000,038,456 | ---- | C] () -- C:\Users\Ira\AppData\Roaming\Comma Separated Values (Windows).ADR
[2011/05/31 14:39:23 | 000,180,624 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2011/02/17 13:13:43 | 000,005,972 | ---- | C] () -- C:\Users\Ira\AppData\Local\d3d9caps.dat
[2011/02/09 23:03:48 | 000,000,314 | ---- | C] () -- C:\Windows\primopdf.ini
[2011/01/16 22:42:07 | 000,019,968 | ---- | C] () -- C:\Users\Ira\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/08 23:38:39 | 000,000,120 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2011/01/07 16:54:32 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/01/07 16:54:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/01/07 16:24:29 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2011/01/04 18:50:17 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2011/01/04 18:50:16 | 001,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2011/01/04 18:50:16 | 001,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2011/01/04 18:50:16 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2011/01/04 18:50:16 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2011/01/04 18:50:13 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2010/05/12 23:57:50 | 000,380,074 | ---- | C] () -- C:\Program Files\Claim_your_free_PDF_converter.pdf
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 01:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/08/14 14:57:07 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Affixa
[2011/01/10 11:30:57 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Blackberry Desktop
[2012/11/16 08:25:13 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Dropbox
[2012/10/10 11:55:35 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Epson
[2011/10/30 15:39:34 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\GogTasks
[2012/10/06 11:25:59 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Leadertech
[2012/10/16 09:04:20 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Mapi2Xml
[2011/01/17 09:15:24 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\MozBackup
[2012/11/14 11:28:42 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\PrimoPDF
[2011/01/10 11:10:13 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\Research In Motion
[2012/11/13 14:01:27 | 000,000,000 | ---D | M] -- C:\Users\Ira\AppData\Roaming\webex
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 30 bytes -> C:\Users\Ira\Documents\Balance_about:blank.html
@Alternate Data Stream - 30 bytes -> C:\Users\Ira\Documents\about:blank.html
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
--
OTL extras:
OTL Extras logfile created on: 11/16/2012 4:07:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ira\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 42.54% Memory free
6.18 Gb Paging File | 4.44 Gb Available in Paging File | 71.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.32 Gb Total Space | 98.07 Gb Free Space | 45.54% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 9.60 Gb Free Space | 64.00% Space Free | Partition Type: NTFS
Computer Name: IRA-PC | User Name: Ira | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07A061F7-E38E-40FE-8444-1A90D7435634}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{5467663C-2AE7-46DE-B98D-F3A32BFFAA14}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{8429BB68-1B4A-4E92-A40D-DAAEA37F01EB}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{B3725B5F-616D-42B7-BEB7-31A4501EE401}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{F35B7929-1235-43C3-9E03-373B446ADAC4}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{030569C0-7011-47C3-ACA3-44D000EE5CD1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1F4B4AB9-DF76-439A-AFB9-075DCBFD14A3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1FA85B3B-91BC-449D-BB6D-AD106927796D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{245CC05F-66BD-401E-82AB-765003A90F06}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{42846F74-4DC3-4942-A854-E2CECCE0ABB7}" = protocol=6 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{562D95DD-A508-4BE4-9623-759807065535}" = protocol=6 | dir=in | app=c:\users\ira\appdata\local\temp\wzse0.tmp\common\epsonnet setup\eneasyapp.exe |
"{5640A7DF-2D82-4F65-96E8-BB86C3836683}" = protocol=17 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe |
"{631C5BD3-0B40-4038-9D46-02A61D5BE275}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9AE25A8F-093D-4689-82C3-0CD88D6B88B8}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{A1460E59-942F-44CB-BAA7-7C8A755DD918}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{A7DF1F01-612C-4F97-B354-AFAC81D4375F}" = protocol=17 | dir=in | app=c:\users\ira\appdata\local\temp\wzse0.tmp\common\epsonnet setup\eneasyapp.exe |
"{A88D5B19-5AE3-4C4F-BF87-2D9FE83CA9ED}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AF3429C4-8F1B-4CF9-999F-DDF8D69EA7BF}" = protocol=17 | dir=in | app=c:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe |
"{D51E3A7C-340C-4DD6-80F1-2B631C3F1F0E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E2B0D965-05F7-4E07-9BB9-7F70672BC3E1}" = protocol=6 | dir=in | app=c:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe |
"{E9BA5A0D-F643-458C-9846-091B5FA2B89C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{14225D76-96EC-445D-8129-7B65B0C779EF}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{1DC59950-01BC-431E-8F4E-B9F5D1D14EB7}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{2DD61538-8017-4F56-BBE1-1FC88DFB036C}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{8CD3FBC5-49EF-417F-B14B-D42D39660C43}C:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{9C4ED932-CDB1-47A1-96E7-BA18C4CBE7CE}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"TCP Query User{A9A24788-DB01-4F42-9BEB-58243D4D8B82}C:\program files\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\program files\google\chrome\application\chrome.exe |
"TCP Query User{FE11D29D-02A6-4641-83DE-87BF5A6D0900}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{10BBBBBC-AB90-4980-8D37-0129576DFBB8}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
"UDP Query User{44AB5F3B-8F95-4EB4-80C3-0C646EFFF1D8}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{677F35F4-4446-41DF-8666-99B5B60BC42A}C:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\ira\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{739299D6-2E71-4E97-AFE5-82D8CF538DB5}C:\program files\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\program files\google\chrome\application\chrome.exe |
"UDP Query User{7BDA1CD6-8442-433E-966C-1525A4B6DE0C}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{BC918C07-A1CC-4477-9CE4-514B268AAE90}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{CB9D30B7-06DD-4525-BD02-74F8E8E7FFD8}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A1E0BDA-5E8F-436d-8BE5-7E97C5CB899D}" = Quicken 2012
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{10F63395-157F-4B93-AB4D-702A2FF11942}" = Epson Download Navigator
"{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}" = iSEEK AnswerWorks English Runtime
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22461A1C-BD68-4D90-9897-1DB146D55ECB}" = LogMeIn
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java 6 Update 35
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{294EAADF-E50F-4DD8-AD8D-19587EA10512}" = Modem Diagnostic Tool
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{444DB2B5-28BB-4934-8AFD-2900EB4E873F}" = NBV-100U
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{64BA551C-9AF6-495C-93F3-D1270E0045FC}" = Epson Connect
"{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7AC47574-7DAD-487C-A2BA-BD242E536753}" = Database Oasis
"{814FA673-A085-403C-9545-747FC1495069}" = Epson Customer Participation
"{861C4DFA-E691-4BA6-BE6B-D5BA211990B6}" = DisplayLink Core Software
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8CC68433-5837-4075-B81F-EA7E4F14CE60}" = iCloud
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOKR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOKR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOKR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOKR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOKR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A7-0409-0000-0000000FF1CE}" = Calendar Printing Assistant for Microsoft Office Outlook 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOKR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{91120000-001A-0000-0000-0000000FF1CE}_OUTLOOKR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C329579-EA62-4D83-9BDE-FBD0BDA8FD6E}" = Affixa
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software 6.0.1.3100
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{C261E913-1B30-4B72-895A-3815D149B726}" = Fidelity Active Trader Pro®
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{CD2A9B1C-5A9F-4FCB-947F-A2CE5241EB26}" = GogTasks
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EF7E46B8-1FB7-11E2-B6B3-984BE15F174E}" = Evernote v. 4.5.10
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}" = Epson Event Manager
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"Affixa 3.12.0624" = Affixa 3.2012.6.24
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"EPSON WorkForce 645 Series" = EPSON WorkForce 645 Series Printer Uninstall
"Google Calendar Sync" = Google Calendar Sync
"Google Chrome" = Google Chrome
"hdparm" = hdparm
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"OUTLOOKR" = Microsoft Office Outlook 2007
"PrimoPDF" = PrimoPDF -- brought to you by Nitro PDF Software
"ProInst" = Intel® PROSet/Wireless Software
"smartmontools" = smartmontools
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SyncBack_is1" = SyncBack
"Unlocker" = Unlocker 1.9.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Dropbox" = Dropbox
"LastPass" = LastPass (uninstall only)
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
Error - 5/11/2012 10:21:22 AM | Computer Name = Ira-PC | Source = ESENT | ID = 902
Description = Windows (2552) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x015303E0 Session-context: 0x00000000 Session-context ThreadId: 0x00000CD4 Current
ThreadId: 0x00001004
[ OSession Events ]
Error - 7/5/2011 4:09:39 PM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 40
seconds with 0 seconds of active time. This session ended with a crash.
Error - 7/14/2011 3:36:14 PM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 40
seconds with 0 seconds of active time. This session ended with a crash.
Error - 10/20/2011 11:51:51 AM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 213
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/9/2011 5:17:10 PM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2494
seconds with 2400 seconds of active time. This session ended with a crash.
Error - 12/20/2011 5:22:42 PM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/2/2012 1:36:44 PM | Computer Name = Ira-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 597
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 11/15/2012 11:13:53 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/15/2012 11:14:23 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 11/15/2012 11:16:41 AM | Computer Name = Ira-PC | Source = DCOM | ID = 10016
Description =
Error - 11/15/2012 11:17:11 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/15/2012 11:17:11 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7024
Description =
Error - 11/15/2012 11:17:11 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7031
Description =
Error - 11/16/2012 9:23:17 AM | Computer Name = Ira-PC | Source = DCOM | ID = 10016
Description =
Error - 11/16/2012 9:23:48 AM | Computer Name = Ira-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/16/2012 12:52:05 PM | Computer Name = Ira-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.139.2168.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8904.0 Error
code: 0x80070643 Error description: Fatal error during installation.
Error - 11/16/2012 12:53:05 PM | Computer Name = Ira-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =
< End of report >