Hi godawgs,
Thanks so much for your help!! Couple things before I post the log files. One thing I forgot was that when you open a browser on the PC a "taskeng.exe" window occasionally opens up but it is blank.
On OTL.exe there was no "Include 64bit scans" as shown in your picture so I couldn't check that and ran it without it checked.
On aswMBR there was no "A/V Quickscan" dropdown so I ran it as I guess a Full Scan.
Here's the OTL.Txt log
OTL logfile created on: 3/26/2014 7:03:29 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\d\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.75 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 60.07% Memory free
3.74 Gb Paging File | 2.68 Gb Available in Paging File | 71.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.05 Gb Total Space | 77.47 Gb Free Space | 56.94% Space Free | Partition Type: NTFS
Drive G: | 29.81 Gb Total Space | 29.66 Gb Free Space | 99.50% Space Free | Partition Type: FAT32
Computer Name: D-PC | User Name: d | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/03/25 16:49:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\d\Desktop\OTL (1).exe
PRC - [2014/03/04 04:39:32 | 001,751,912 | ---- | M] (Search Module Ltd.) -- C:\Program Files\Common Files\Goobzo\GBUpdate\smu.exe
PRC - [2014/01/20 22:07:30 | 000,025,600 | ---- | M] () -- C:\Program Files\pcreg\pcreg.exe
PRC - [2014/01/15 20:40:24 | 000,277,920 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
PRC - [2013/10/23 16:01:10 | 000,300,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MpCmdRun.exe
PRC - [2013/10/23 16:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/10/23 15:55:28 | 000,948,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/08/15 16:40:32 | 000,064,408 | ---- | M] (Malwarebytes Secure Backup) -- C:\Program Files\Malwarebytes Secure Backup\SMessaging.exe
PRC - [2013/08/15 16:40:32 | 000,039,832 | ---- | M] (Malwarebytes Secure Backup) -- C:\Program Files\Malwarebytes Secure Backup\SAgent.Service.exe
PRC - [2013/08/15 16:40:24 | 000,090,520 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Secure Backup\mbsbscan.exe
PRC - [2013/08/06 17:33:16 | 003,291,008 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/06/11 14:18:30 | 000,024,576 | ---- | M] () -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
PRC - [2007/12/10 23:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/16 08:41:06 | 000,978,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\d17ceca243fabda73eefb21d9bd072df\System.Configuration.ni.dll
MOD - [2014/02/14 10:37:21 | 005,462,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f87e71868aedbc6c4e8fe7160d17c4ab\System.Xml.ni.dll
MOD - [2014/02/14 10:34:43 | 012,434,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d2b605fc7deda872727d1ed37710420e\System.Windows.Forms.ni.dll
MOD - [2014/02/14 10:22:40 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8e6265a54260bddfc05951e764f5bc48\System.Drawing.ni.dll
MOD - [2014/02/14 10:21:15 | 002,295,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\bd996f730710dbbac36cba28f7214b29\System.Core.ni.dll
MOD - [2014/02/14 10:19:49 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\957628d9dd7b3bf370a56dca7835a997\System.ni.dll
MOD - [2014/02/14 10:19:36 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\694a37a84dee2cd2609a1dfab27c0433\mscorlib.ni.dll
========== Services (SafeList) ==========
SRV - [2014/03/12 11:08:29 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/03/04 04:39:32 | 001,751,912 | ---- | M] (Search Module Ltd.) [Auto | Running] -- C:\Program Files\Common Files\Goobzo\GBUpdate\smu.exe -- (SMUpd)
SRV - [2014/02/12 20:36:33 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/01/20 22:07:30 | 000,025,600 | ---- | M] () [Auto | Running] -- C:\Program Files\pcreg\pcreg.exe -- (pcregservice)
SRV - [2014/01/15 20:39:44 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe -- (McComponentHostService)
SRV - [2013/10/23 16:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/08/15 16:40:32 | 000,039,832 | ---- | M] (Malwarebytes Secure Backup) [Auto | Running] -- C:\Program Files\Malwarebytes Secure Backup\SAgent.Service.exe -- (sagentservice)
SRV - [2013/08/06 17:33:16 | 003,291,008 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2008/06/11 14:18:30 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe -- (ETService)
SRV - [2008/01/20 22:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/10 23:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS -- (SRTSPX)
DRV - File not found [File_System | System | Stopped] -- C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS -- (SRTSP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS -- (NAVEX15)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS -- (NAVENG)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV - [2014/03/26 18:51:09 | 000,039,464 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{63131EAE-4662-4A5C-A8DB-D6CAB88CE14D}\MpKsl68b17769.sys -- (MpKsl68b17769)
DRV - [2014/03/26 18:50:58 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2014/03/04 04:39:28 | 000,031,592 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Goobzo\GBUpdate\smw.sys -- (SMUpdd)
DRV - [2013/09/27 10:53:06 | 000,104,768 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/02/19 21:32:54 | 010,919,200 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/06/11 14:13:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15)
DRV - [2008/06/06 07:13:10 | 000,145,440 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008/03/07 19:31:52 | 000,062,570 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\jl2005c.sys -- (JL2005C)
DRV - [2008/03/05 01:10:54 | 001,203,808 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,NewTabPageShow = 1
IE - HKLM\..\SearchScopes,DefaultScope = {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,NewTabPageShow = 1
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com/
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.google.com
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\..\SearchScopes,DefaultScope = {483D440A-3A50-459C-93F3-2FCD071459AF}
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js - File not found
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@lightspark.github.com/Lightspark;version=1: C:\Program Files\Lightspark 0.5.3-git\nplightsparkplugin.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/12/24 11:34:42 | 000,000,000 | ---D | M]
[2009/07/29 16:29:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Extensions
[2014/03/25 16:49:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions
[2010/07/24 07:15:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2014/03/10 22:34:27 | 000,000,000 | ---D | M] ("iWebar") -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com
[2014/03/25 16:49:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\staged
[2014/03/23 15:19:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com\extensionData
[2014/03/23 15:19:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com\extensionData\plugins
[2014/03/23 15:19:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com\extensionData\userCode
[2010/07/23 10:09:46 | 000,001,840 | ---- | M] () -- C:\Users\d\AppData\Roaming\Mozilla\Firefox\Profiles\6gn3gsks.default\searchplugins\bing.xml
[2014/02/17 19:46:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/08/14 08:01:50 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/02/17 19:46:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/14 08:01:50 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/02/17 19:46:34 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
Hosts file not found
O4 - HKLM..\Run: [EarthLink Installer] " /C File not found
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SMessaging] C:\Program Files\Malwarebytes Secure Backup\SMessaging.exe (Malwarebytes Secure Backup)
O4 - HKLM..\Run: [SOSUAUI] C:\Program Files\Malwarebytes Secure Backup\sosuploadagent.exe (Malwarebytes Secure Backup)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\d\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3730493371-2978618540-1370544531-1000\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8058310F-B522-4D7E-AD42-BB5315D9B153}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img25.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img25.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012/11/27 18:30:30 | 000,000,100 | ---- | M] () - G:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2012/11/27 18:30:30 | 000,000,204 | ---- | M] () - G:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2012/11/27 18:30:30 | 000,017,542 | ---- | M] () - G:\autorun.ico -- [ FAT32 ]
O33 - MountPoints2\{a31009d3-82b8-11de-99db-001d72bb114f}\Shell - "" = AutoRun
O33 - MountPoints2\{a31009d3-82b8-11de-99db-001d72bb114f}\Shell\AutoRun\command - "" = G:\DPFMate.exe
O33 - MountPoints2\{e67ae022-d8d4-11e1-a592-001d72bb114f}\Shell - "" = AutoRun
O33 - MountPoints2\{e67ae022-d8d4-11e1-a592-001d72bb114f}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\drivers\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2014/03/26 18:58:21 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\d\Desktop\OTL (1).exe
[2014/03/26 18:58:09 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\d\Desktop\aswmbr (1).exe
[2014/03/26 18:50:57 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2014/03/23 17:50:14 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\System32\bootdelete.exe
[2014/03/23 17:36:44 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/03/23 17:34:44 | 009,988,304 | ---- | C] (SurfRight B.V.) -- C:\Users\d\Desktop\HitmanPro.exe
[2014/03/23 16:16:05 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Local\ElevatedDiagnostics
[2014/03/23 15:55:31 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/03/23 15:23:50 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/03/23 14:27:23 | 000,290,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\subinacl.exe
[2014/03/23 14:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft
[2014/03/23 14:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\Adware-Removal-Tool
[2014/03/19 08:52:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/03/19 08:51:56 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014/03/19 08:51:38 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014/03/19 08:51:38 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014/03/19 08:51:38 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2014/03/19 08:51:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/03/12 17:53:47 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/03/12 17:53:45 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/03/12 17:53:44 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/03/12 17:53:43 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/03/12 17:53:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/03/12 17:53:41 | 001,806,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/03/12 17:53:41 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014/03/12 17:53:38 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/03/12 09:54:18 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014/03/12 09:54:16 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2014/03/12 09:54:15 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
[2014/03/12 09:54:11 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2014/03/11 09:02:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014/03/11 08:43:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2014/03/11 07:31:56 | 000,921,512 | ---- | C] (Oracle Corporation) -- C:\Users\d\Desktop\jre-7u51-windows-i586-iftw.exe
[2014/03/10 21:25:56 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Local\Installer
[2014/03/10 21:25:50 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
[2014/03/10 21:25:50 | 000,000,000 | ---D | C] -- C:\ProgramData\SearchModule
[2014/03/10 21:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\YTDownloader
[2014/03/10 21:25:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Goobzo
[2014/03/10 21:24:25 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Local\CrashRpt
[2014/03/06 18:32:08 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Local\Kobo
[2014/03/06 18:31:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kobo
[2014/03/03 20:23:06 | 000,000,000 | ---D | C] -- C:\temp
[2014/03/02 08:44:02 | 000,000,000 | ---D | C] -- C:\Program Files\runonce
[2014/03/01 21:25:10 | 000,000,000 | ---D | C] -- C:\Windows\tmp
[2014/03/01 21:21:56 | 000,000,000 | ---D | C] -- C:\Program Files\pcreg
[2014/03/01 21:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2014/03/01 21:19:03 | 000,000,000 | ---D | C] -- C:\Program Files\Kobo
[2014/02/28 22:47:42 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Roaming\SharePod
[2014/02/28 21:52:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2014/02/28 21:49:15 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/02/28 21:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2014/02/28 20:06:16 | 000,000,000 | R--D | C] -- C:\Users\d\Downloads
[2014/02/28 20:00:12 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Roaming\uTorrent
[2014/02/28 19:51:22 | 000,000,000 | ---D | C] -- C:\Program Files\Adblock Plus for IE
[2014/02/28 19:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014/02/28 18:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2014/02/28 08:32:17 | 000,000,000 | ---D | C] -- C:\Users\d\AppData\Local\Skype
[2014/02/28 08:32:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/02/28 08:32:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2014/02/28 05:40:45 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/03/26 19:00:35 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\Online Backup Update Notifier.job
[2014/03/26 19:00:32 | 000,001,101 | ---- | M] () -- C:\Users\d\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/03/26 18:59:11 | 000,655,380 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/03/26 18:59:11 | 000,124,006 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/03/26 18:56:16 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\d\Desktop\aswmbr (1).exe
[2014/03/26 18:51:11 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/26 18:51:11 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/26 18:50:58 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2014/03/26 18:50:33 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2014/03/26 18:50:32 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\pcreg.job
[2014/03/26 18:50:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/26 18:50:12 | 1877,458,944 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/25 18:08:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/25 16:49:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\d\Desktop\OTL (1).exe
[2014/03/23 17:50:14 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\System32\bootdelete.exe
[2014/03/23 17:35:47 | 009,988,304 | ---- | M] (SurfRight B.V.) -- C:\Users\d\Desktop\HitmanPro.exe
[2014/03/23 17:03:33 | 000,290,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\subinacl.exe
[2014/03/19 08:51:23 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2014/03/19 08:51:18 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014/03/19 08:51:18 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014/03/19 08:51:17 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014/03/19 08:44:54 | 000,714,464 | ---- | M] () -- C:\Users\d\Desktop\Adware-Removal-Tool-v3.8(1).exe
[2014/03/19 08:42:12 | 000,108,944 | ---- | M] () -- C:\Users\d\Desktop\Java.exe
[2014/03/19 08:37:22 | 000,714,464 | ---- | M] () -- C:\Users\d\Desktop\Adware-Removal-Tool-v3.8.exe
[2014/03/13 21:18:17 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\At1.job
[2014/03/13 19:06:15 | 000,000,680 | ---- | M] () -- C:\Users\d\AppData\Local\d3d9caps.dat
[2014/03/13 19:02:55 | 000,304,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/03/12 11:08:29 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/03/12 11:08:28 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/03/11 18:45:15 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014/03/11 07:32:11 | 000,921,512 | ---- | M] (Oracle Corporation) -- C:\Users\d\Desktop\jre-7u51-windows-i586-iftw.exe
[2014/03/10 21:26:10 | 000,001,696 | ---- | M] () -- C:\Users\d\Desktop\YTDownloader.lnk
[2014/03/06 18:31:54 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\Kobo.lnk
[2014/03/01 21:18:52 | 026,017,384 | ---- | M] () -- C:\Users\d\Desktop\kobo-setup.exe
[2014/02/28 08:32:01 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/03/23 17:08:56 | 1877,458,944 | -HS- | C] () -- C:\hiberfil.sys
[2014/03/19 08:44:11 | 000,714,464 | ---- | C] () -- C:\Users\d\Desktop\Adware-Removal-Tool-v3.8(1).exe
[2014/03/19 08:42:03 | 000,108,944 | ---- | C] () -- C:\Users\d\Desktop\Java.exe
[2014/03/19 08:36:55 | 000,714,464 | ---- | C] () -- C:\Users\d\Desktop\Adware-Removal-Tool-v3.8.exe
[2014/03/11 07:00:30 | 000,001,113 | ---- | C] () -- C:\Users\d\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2014/03/10 21:26:10 | 000,001,696 | ---- | C] () -- C:\Users\d\Desktop\YTDownloader.lnk
[2014/03/06 18:31:54 | 000,000,762 | ---- | C] () -- C:\Users\Public\Desktop\Kobo.lnk
[2014/03/03 09:12:06 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/03/01 21:23:00 | 000,000,354 | ---- | C] () -- C:\Windows\tasks\At1.job
[2014/03/01 21:22:59 | 000,000,270 | ---- | C] () -- C:\Windows\tasks\pcreg.job
[2014/03/01 21:17:47 | 026,017,384 | ---- | C] () -- C:\Users\d\Desktop\kobo-setup.exe
[2014/02/28 08:32:01 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/04/15 18:02:51 | 000,000,316 | ---- | C] () -- C:\Users\d\AppData\Roaming\wklnhst.dat
[2010/11/09 20:59:28 | 000,029,239 | ---- | C] () -- C:\Users\d\AppData\Roaming\UserTile.png
[2010/08/31 06:46:48 | 000,000,680 | ---- | C] () -- C:\Users\d\AppData\Local\d3d9caps.dat
[2009/08/04 20:18:22 | 000,032,768 | ---- | C] () -- C:\Users\d\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 02:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/08/07 00:31:18 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\.minecraft
[2013/09/20 07:58:19 | 000,000,000 | -HSD | M] -- C:\Users\d\AppData\Roaming\dwthtiwg
[2010/11/09 20:59:27 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\PeerNetworking
[2014/02/28 22:47:42 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\SharePod
[2012/04/15 18:07:42 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\Template
[2013/05/26 15:05:18 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\TuneUp Software
[2014/03/02 16:26:03 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\uTorrent
[2012/10/05 07:12:38 | 000,000,000 | ---D | M] -- C:\Users\d\AppData\Roaming\Windows Live Writer
[2013/06/10 10:01:38 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/06/10 10:01:38 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< systemservices >
[2006/11/02 08:58:10 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006/11/02 08:58:10 | 000,032,646 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/08/05 10:37:12 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/09/25 19:42:42 | 000,000,466 | ---- | C] () -- C:\Windows\Tasks\Online Backup Update Notifier.job
[2014/03/01 21:22:59 | 000,000,270 | ---- | C] () -- C:\Windows\Tasks\pcreg.job
[2014/03/01 21:23:00 | 000,000,354 | ---- | C] () -- C:\Windows\Tasks\At1.job
< MD5 for: RPCSS.DLL >
[2009/03/03 00:39:32 | 000,551,424 | ---- | M] (Microsoft Corporation) MD5=301AE00E12408650BADDC04DBC832830 -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18226_none_69bb41ac3deac876\rpcss.dll
[2008/01/20 22:33:42 | 000,547,328 | ---- | M] (Microsoft Corporation) MD5=33FB1F0193EE2051067441492D56113C -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18000_none_69cadbfc3ddffe3c\rpcss.dll
[2009/04/11 02:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) MD5=3B5B4D53FEC14F7476CA29A20CC31AC9 -- C:\Windows\System32\rpcss.dll
[2009/04/11 02:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) MD5=3B5B4D53FEC14F7476CA29A20CC31AC9 -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6002.18005_none_6bb655083b01c988\rpcss.dll
[2009/03/03 00:32:23 | 000,551,424 | ---- | M] (Microsoft Corporation) MD5=4DFCBDEF3CCAA98F99038DED78945253 -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.22389_none_6a06ffcd57365beb\rpcss.dll
[2009/03/03 00:19:41 | 000,549,888 | ---- | M] (Microsoft Corporation) MD5=7B981222A257D076885BFFB66F19B7CE -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6000.16830_none_67c4315e40d1bb6c\rpcss.dll
[2009/03/03 00:17:45 | 000,550,400 | ---- | M] (Microsoft Corporation) MD5=B1BB45E24717A7F790B4411C4446EF5E -- C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6000.21023_none_685b771559e4be8c\rpcss.dll
< c:\program files (x86)\Google\Desktop >
< c:\program files\Google\Desktop >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is OS
Volume Serial Number is D07F-F80B
Directory of C:\
11/02/2006 08:59 AM <JUNCTION> Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
11/02/2006 08:59 AM <SYMLINKD> All Users [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data
07/29/2009 04:15 PM <JUNCTION> Application Data [C:\ProgramData]
11/02/2006 08:59 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
11/02/2006 08:59 AM <JUNCTION> Documents [C:\Users\Public\Documents]
11/02/2006 08:59 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\d
07/29/2009 04:13 PM <JUNCTION> Application Data [C:\Users\d\AppData\Roaming]
07/29/2009 04:13 PM <JUNCTION> Cookies [C:\Users\d\AppData\Roaming\Microsoft\Windows\Cookies]
07/29/2009 04:13 PM <JUNCTION> Local Settings [C:\Users\d\AppData\Local]
07/29/2009 04:13 PM <JUNCTION> My Documents [C:\Users\d\Documents]
07/29/2009 04:13 PM <JUNCTION> NetHood [C:\Users\d\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/29/2009 04:13 PM <JUNCTION> PrintHood [C:\Users\d\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/29/2009 04:13 PM <JUNCTION> Recent [C:\Users\d\AppData\Roaming\Microsoft\Windows\Recent]
07/29/2009 04:13 PM <JUNCTION> SendTo [C:\Users\d\AppData\Roaming\Microsoft\Windows\SendTo]
07/29/2009 04:13 PM <JUNCTION> Start Menu [C:\Users\d\AppData\Roaming\Microsoft\Windows\Start Menu]
07/29/2009 04:13 PM <JUNCTION> Templates [C:\Users\d\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\d\AppData\Local
07/29/2009 04:13 PM <JUNCTION> Application Data [C:\Users\d\AppData\Local]
07/29/2009 04:13 PM <JUNCTION> History [C:\Users\d\AppData\Local\Microsoft\Windows\History]
07/29/2009 04:13 PM <JUNCTION> Temporary Internet Files [C:\Users\d\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\d\Documents
07/29/2009 04:13 PM <JUNCTION> My Music [C:\Users\d\Music]
07/29/2009 04:13 PM <JUNCTION> My Pictures [C:\Users\d\Pictures]
07/29/2009 04:13 PM <JUNCTION> My Videos [C:\Users\d\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
11/02/2006 08:59 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Roaming]
11/02/2006 08:59 AM <JUNCTION> Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
11/02/2006 08:59 AM <JUNCTION> Local Settings [C:\Users\Default\AppData\Local]
11/02/2006 08:59 AM <JUNCTION> My Documents [C:\Users\Default\Documents]
11/02/2006 08:59 AM <JUNCTION> NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/02/2006 08:59 AM <JUNCTION> PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/02/2006 08:59 AM <JUNCTION> Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
11/02/2006 08:59 AM <JUNCTION> SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
11/02/2006 08:59 AM <JUNCTION> Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
11/02/2006 08:59 AM <JUNCTION> Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
11/02/2006 08:59 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Local]
11/02/2006 08:59 AM <JUNCTION> History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
11/02/2006 08:59 AM <JUNCTION> Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
11/02/2006 08:59 AM <JUNCTION> My Music [C:\Users\Default\Music]
11/02/2006 08:59 AM <JUNCTION> My Pictures [C:\Users\Default\Pictures]
11/02/2006 08:59 AM <JUNCTION> My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
203 Dir(s) 83,306,061,824 bytes free
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:AD022376
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:373E1720
< End of report >
Here's the Extras.Txt log
OTL Extras logfile created on: 3/26/2014 7:03:29 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\d\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.75 Gb Total Physical Memory | 1.05 Gb Available Physical Memory | 60.07% Memory free
3.74 Gb Paging File | 2.68 Gb Available in Paging File | 71.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.05 Gb Total Space | 77.47 Gb Free Space | 56.94% Space Free | Partition Type: NTFS
Drive G: | 29.81 Gb Total Space | 29.66 Gb Free Space | 99.50% Space Free | Partition Type: FAT32
Computer Name: D-PC | User Name: d | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- "%1" %*
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1CDC16B7-4841-4C00-B644-28CF05D52728}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{35214426-22C4-4260-AB8F-017CC34BD634}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
"{6A1E2D30-1333-47C7-9341-0A4B3A056316}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB775252-C9C5-40C3-A86D-D2969B5473D5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CF50C69-945A-49E8-A7CF-C1BAF87EF373}" = dir=out | app=c:\users\d\appdata\local\temp\file_to_run55636.exe |
"{1FAF5641-7F8B-4459-9FF0-D8916FF597F3}" = dir=out | app=c:\program files\pcreg\pcreg.exe |
"{478070A1-87CE-4CE5-8463-4628B1759C1F}" = dir=in | app=c:\users\d\appdata\local\temp\speedmax.exe |
"{51449D6A-8097-4E64-94BF-0CEC936F4020}" = dir=in | app=c:\users\d\appdata\local\temp\file_to_run551629.exe |
"{5986F901-4CDD-4759-8194-31C62D79F546}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{70A09165-B145-4F88-ADA6-D79C207A6704}" = dir=out | app=c:\program files\pcreg\service.exe |
"{7289680E-A604-4356-BC9C-697BC0022320}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{772F9862-5D42-43DB-A4C3-9217E153ACEA}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{83D6A168-8BA0-4254-9F3B-768968C6EB7D}" = dir=out | app=c:\users\d\appdata\local\temp\speedmax.exe |
"{90B5D4D3-A8EA-4748-B865-A4BE92424BC8}" = dir=in | app=c:\windows\temp\file_to_run551726.exe |
"{91D86EF1-4FA2-403F-A5BC-45E62D4088C3}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{A8D3249B-3A66-41A7-9170-99C578DE77A3}" = dir=in | app=c:\program files\pcreg\pcreg.exe |
"{C20854BE-EE88-4BC0-BE61-0E7950B974A7}" = dir=in | app=c:\users\d\appdata\local\temp\file_to_run55636.exe |
"{C2B3BD1B-B297-41CD-B2C6-0F77B9824CC2}" = dir=out | app=c:\users\d\appdata\local\temp\file_to_run551629.exe |
"{CD3BE919-BF98-43C3-8C53-E95F345EC4D7}" = dir=in | app=c:\program files\pcreg\service.exe |
"{D1FDD9AE-9C46-4FBD-AC7E-0ECAEEF14BBE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{DB1371C4-D114-49D7-AF72-81C5AD019804}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EE213794-1CF2-41B7-9F9D-B926C2831352}" = dir=in | app=c:\users\d\appdata\local\temp\file_to_run55728.exe |
"{EE6A6DE5-DD02-4F7D-A9E8-E2B475458E48}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{EF9028E4-855C-4FDB-8E64-EB0625265336}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{F333DB84-4F6D-4689-AA3A-446411EEE1C5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FA15F526-CE0B-4726-8BEA-3BB47978D267}" = dir=out | app=c:\users\d\appdata\local\temp\file_to_run55728.exe |
"{FA936468-DB32-4AF4-9A9F-70F80B6A3649}" = dir=out | app=c:\windows\temp\file_to_run551726.exe |
"{FD19A28E-F42B-4AFB-ABF7-8E931B3B7CB7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0CD47142-BA4F-46B0-AA92-2675864928B8}" = Microsoft Security Client
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{18D47FA1-0440-48D3-A7E0-DA09537FF471}" = Apple Mobile Device Support
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21B632E1-4B3D-4AC2-9ABD-E00544F67D48}" = Adblock Plus for IE (32-bit)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java 6 Update 21
"{26A24AE4-039D-4CA4-87B4-2F83217051FF}" = Java 7 Update 51
"{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4F524A2D-5637-4300-76A7-A758B70C0A03}" = Ask Toolbar
"{5228274E-59DC-4B9B-AF72-97AC81C09C8A}" = Malwarebytes Secure Backup
"{5FF27D65-35E5-4855-B7ED-59BCFBC85776}" = AVG 2013
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = CyberLink PowerDVD
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6FBC610C-94CD-4EC3-A322-74BB07AA2D6C}" = Brother HL-2140
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.5
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{fd97d1e2-368a-4cd9-af63-8eeff938044a}" = Adblock Plus for IE
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI-SV92EX Soft Modem
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dual Mode Camera_is1" = Uninstall Dual Mode Camera
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"Kobo" = Kobo
"Lightspark" = Lightspark 0.5.3-git
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 27.0.1 (x86 en-US)" = Mozilla Firefox 27.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"Search module" = Search module
"TurboTax 2009" = TurboTax 2009
"ValueApps" = ValueApps
"WinLiveSuite_Wave3" = Windows Live Essentials
"YTDownloader" = YTDownloader
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/25/2014 9:21:50 AM | Computer Name = d-PC | Source = WinMgmt | ID = 10
Description =
Error - 3/25/2014 9:26:13 AM | Computer Name = d-PC | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 6.0.6000.16386, time stamp
0x4549b0e1, faulting module SysMenu.dll, version 1.0.0.5, time stamp 0x52b449c7,
exception code 0xc0000005, fault offset 0x0006ce5c, process id 0xe38, application
start time 0x01cf482daad47c95.
Error - 3/25/2014 4:44:24 PM | Computer Name = d-PC | Source = WinMgmt | ID = 10
Description =
Error - 3/25/2014 4:49:19 PM | Computer Name = d-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 3/25/2014 4:49:19 PM | Computer Name = d-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 3/25/2014 4:49:19 PM | Computer Name = d-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 3/25/2014 4:49:19 PM | Computer Name = d-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 3/25/2014 4:53:04 PM | Computer Name = d-PC | Source = Application Hang | ID = 1002
Description = The program OTL (1).exe version 3.2.69.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1590 Start Time: 01cf486c14cd03d1 Termination Time: 8
Error - 3/26/2014 6:51:56 PM | Computer Name = d-PC | Source = WinMgmt | ID = 10
Description =
Error - 3/26/2014 6:55:31 PM | Computer Name = d-PC | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 6.0.6000.16386, time stamp
0x4549b0e1, faulting module SysMenu.dll, version 1.0.0.5, time stamp 0x52b449c7,
exception code 0xc0000005, fault offset 0x0006ce5c, process id 0x1ae4, application
start time 0x01cf49467c241658.
[ System Events ]
Error - 3/23/2014 5:41:40 PM | Computer Name = d-PC | Source = nvstor32 | ID = 262149
Description = A parity error was detected on \Device\RaidPort1.
Error - 3/23/2014 5:41:43 PM | Computer Name = d-PC | Source = nvstor32 | ID = 262149
Description = A parity error was detected on \Device\RaidPort1.
Error - 3/23/2014 5:43:10 PM | Computer Name = d-PC | Source = nvstor32 | ID = 262149
Description = A parity error was detected on \Device\RaidPort1.
Error - 3/23/2014 6:56:05 PM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/23/2014 10:00:44 PM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/24/2014 6:40:47 AM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/25/2014 9:21:51 AM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/25/2014 4:44:24 PM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/26/2014 6:51:56 PM | Computer Name = d-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 3/26/2014 7:01:16 PM | Computer Name = d-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.169.762.0 Update Source: %%859 Update Stage:
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.10401.0
Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.
< End of report >
Here's the aswMBR.txt log
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-03-26 19:20:59
-----------------------------
19:20:59.803 OS Version: Windows 6.0.6002 Service Pack 2
19:20:59.803 Number of processors: 1 586 0x7F02
19:20:59.805 ComputerName: D-PC UserName: d
19:21:00.363 Initialize success
19:21:10.779 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000051
19:21:10.782 Disk 0 Vendor: ST316081 4.AA Size: 152627MB BusType: 3
19:21:10.933 Disk 0 MBR read successfully
19:21:10.937 Disk 0 MBR scan
19:21:10.942 Disk 0 unknown MBR code
19:21:10.973 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
19:21:10.987 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 139313 MB offset 27265024
19:21:11.002 Disk 0 scanning sectors +312579760
19:21:11.187 Disk 0 scanning C:\Windows\system32\drivers
19:21:17.441 Service scanning
19:21:22.278 Service MpKsl68b17769 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{63131EAE-4662-4A5C-A8DB-D6CAB88CE14D}\MpKsl68b17769.sys **LOCKED** 32
19:21:30.811 Modules scanning
19:21:37.241 Disk 0 trace - called modules:
19:21:37.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys tcpip.sys NETIO.SYS
19:21:37.275 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8565fac8]
19:21:37.284 3 CLASSPNP.SYS[875a28b3] -> nt!IofCallDriver -> [0x84c37688]
19:21:37.295 5 acpi.sys[806146bc] -> nt!IofCallDriver -> \Device\00000051[0x84c37920]
19:21:37.305 Scan finished successfully
19:21:46.883 Disk 0 MBR has been saved successfully to "C:\Users\d\Desktop\MBR.dat"
19:21:46.894 The log file has been saved successfully to "C:\Users\d\Desktop\aswMBR.txt"
Thanks again!!!
Frank