OTL logfile created on: 4/11/2011 8:34:57 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 16.43 Gb Free Space | 56.09% Space Free | Partition Type: NTFS
Drive D: | 119.75 Gb Total Space | 10.49 Gb Free Space | 8.76% Space Free | Partition Type: NTFS
Computer Name: RICK | User Name: Rick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/11 20:33:47 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
PRC - [2011/02/16 15:49:08 | 000,088,176 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2011/01/17 17:15:32 | 000,822,560 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcupdate.exe
PRC - [2011/01/17 16:15:32 | 001,193,848 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2010/12/08 14:11:38 | 000,136,584 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2010/12/08 14:11:32 | 000,374,152 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/10/13 23:28:54 | 000,188,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2010/10/13 23:28:54 | 000,171,168 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2010/10/13 23:28:54 | 000,141,792 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2008/06/15 15:34:20 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2008/05/14 12:56:46 | 000,602,112 | ---- | M] (Remote Backup Systems, Inc.) -- C:\Program Files\Remote Backup\rbackup.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/01/07 17:30:56 | 000,864,256 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\ControlCenter2\brctrcen.exe
PRC - [2003/02/11 18:48:40 | 001,741,280 | ---- | M] () -- C:\Service2000DBS\DLC\bin\_mprshut.exe
PRC - [2003/02/11 18:48:26 | 001,371,312 | ---- | M] () -- C:\Service2000DBS\DLC\bin\_mprosrv.exe
PRC - [2002/05/06 21:05:32 | 000,020,480 | ---- | M] () -- C:\Service2000DBS\DLC\bin\admsrvc.exe
PRC - [2000/06/02 14:11:36 | 000,020,542 | ---- | M] () -- C:\Service2000DBS\DLC\jre\bin\java.exe
========== Modules (SafeList) ==========
MOD - [2011/04/11 20:33:47 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe
MOD - [2011/03/09 16:54:14 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/04/05 18:15:07 | 000,215,552 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\WINDOWS\system32\itlpfw32.dll -- (itlperf)
SRV - [2011/02/16 15:49:08 | 000,088,176 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/12/08 14:11:38 | 000,136,584 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2010/12/08 14:11:32 | 000,374,152 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/11/08 13:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/10/13 23:28:54 | 000,188,136 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2010/10/13 23:28:54 | 000,171,168 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2010/10/13 23:28:54 | 000,141,792 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\WINDOWS\system32\mfevtps.exe -- (mfevtp)
SRV - [2010/10/07 21:34:28 | 000,364,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2010/03/10 11:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2008/06/15 15:34:20 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2008/05/14 12:56:46 | 000,602,112 | ---- | M] (Remote Backup Systems, Inc.) [Auto | Running] -- C:\Program Files\Remote Backup\rbackup.exe -- (Remote Backup 2007)
SRV - [2002/05/06 21:05:32 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\Service2000DBS\DLC\bin\admsrvc.exe -- (AdminService9.1D)
========== Driver Services (SafeList) ==========
DRV - [2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/12/08 14:12:02 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/10/13 23:28:54 | 000,386,840 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2010/10/13 23:28:54 | 000,313,288 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2010/10/13 23:28:54 | 000,152,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2010/10/13 23:28:54 | 000,095,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2010/10/13 23:28:54 | 000,088,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendiskmp)
DRV - [2010/10/13 23:28:54 | 000,088,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendisk)
DRV - [2010/10/13 23:28:54 | 000,084,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2010/10/13 23:28:54 | 000,084,072 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdi2k.sys -- (mfetdi2k)
DRV - [2010/10/13 23:28:54 | 000,055,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cfwids.sys -- (cfwids)
DRV - [2010/10/13 23:28:54 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2010/05/10 14:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/08/14 09:45:24 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/08/14 09:45:24 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2009/03/14 09:38:31 | 000,016,512 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2008/07/24 19:46:12 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2008/07/24 19:46:10 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/04/21 17:20:06 | 000,097,816 | ---- | M] (FAMv4) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\FAMv4.sys -- (FAMv4)
DRV - [2007/11/10 04:20:02 | 000,029,728 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2007/09/20 19:07:40 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007/09/20 19:07:38 | 000,053,632 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007/09/19 05:16:32 | 004,617,728 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2000/07/24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\BrPar.sys -- (BrPar)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...007&form=ZGAPHP
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
IE - HKU\.DEFAULT\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...007&form=ZGAPHP
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
IE - HKU\S-1-5-18\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nexpart.com/login.php
IE - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{85A5768E-D111-4DB3-B3C7-E2D6DCF684E6}: D:\Documents and Settings\Rick\Local Settings\Application Data\{85A5768E-D111-4DB3-B3C7-E2D6DCF684E6} [2011/04/05 15:17:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/04/07 10:53:49 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/28 21:03:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/24 08:51:44 | 000,000,000 | ---D | M]
[2009/03/14 13:55:02 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Rick\Application Data\Mozilla\Extensions
[2011/01/13 13:16:35 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Rick\Application Data\Mozilla\Firefox\Profiles\tntfiq57.default\extensions
[2009/11/05 18:19:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Rick\Application Data\Mozilla\Firefox\Profiles\tntfiq57.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/13 13:16:35 | 000,000,000 | ---D | M] (ShopAtHome.com Intelligent Shopping Toolbar) -- D:\Documents and Settings\Rick\Application Data\Mozilla\Firefox\Profiles\tntfiq57.default\extensions\[email protected]
[2011/01/03 20:55:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/25 18:45:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/03 20:55:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/03/16 09:50:22 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/04/07 10:53:49 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2010/10/13 23:28:54 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/04/07 11:32:38 | 000,001,919 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml
Hosts file not found
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110228200346.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - File not found
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\..Trusted Domains: server ([]* in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1237040245250 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\itlntfy: DllName - itlnfw32.dll - File not found
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/15 00:23:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1606980848-1454471165-682003330-1003\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/11 20:24:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/04/11 18:54:40 | 000,000,000 | RH-D | C] -- D:\Documents and Settings\Rick\Recent
[2011/04/11 18:52:25 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/04/11 18:52:24 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/04/11 07:15:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/04/09 19:11:21 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/04/09 19:11:21 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Google
[2011/04/09 10:51:18 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/04/08 02:15:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Identities
[2011/04/07 20:01:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/04/07 11:32:36 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Mozilla
[2011/04/06 22:25:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/04/06 22:25:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/04/06 08:48:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/04/06 08:33:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Sun
[2011/04/05 19:18:35 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/04/05 19:18:29 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Application Data\Adobe
[2011/04/05 15:34:50 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/04/05 15:33:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/04/05 15:17:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Rick\Local Settings\Application Data\{85A5768E-D111-4DB3-B3C7-E2D6DCF684E6}
[2011/04/05 15:15:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Rick\Application Data\Liobid
[2011/04/05 15:15:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Rick\Application Data\Ekam
[4 D:\Documents and Settings\Rick\My Documents\*.tmp files -> D:\Documents and Settings\Rick\My Documents\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/11 20:28:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/11 20:24:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/11 20:24:13 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/04/11 20:23:56 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/11 20:23:55 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\Cafczyevo.job
[2011/04/11 20:23:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/11 20:08:20 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\CopyNetworkBackupsToArchive.job
[2011/04/11 20:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2011/04/11 19:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2011/04/11 18:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2011/04/11 17:15:49 | 000,010,752 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\Board.xlr
[2011/04/11 17:15:49 | 000,005,702 | ---- | M] () -- D:\Documents and Settings\Rick\Application Data\wklnhst.dat
[2011/04/11 17:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2011/04/11 16:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2011/04/11 15:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2011/04/11 14:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2011/04/11 13:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2011/04/11 12:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2011/04/11 11:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2011/04/11 10:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2011/04/11 09:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2011/04/11 08:53:53 | 000,024,576 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\dailytime.xlr
[2011/04/11 08:52:55 | 000,025,088 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\dailytime2.xlr
[2011/04/11 08:39:10 | 000,012,800 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\bankbal.xlr
[2011/04/11 08:06:21 | 000,000,007 | ---- | M] () -- C:\WINDOWS\System32\Class15
[2011/04/11 08:06:21 | 000,000,005 | ---- | M] () -- C:\WINDOWS\System32\Band4
[2011/04/11 08:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2011/04/11 07:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2011/04/11 06:49:18 | 000,000,112 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\kAp70y4.dat
[2011/04/11 06:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2011/04/11 05:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2011/04/11 04:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2011/04/11 03:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2011/04/11 02:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2011/04/11 01:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2011/04/11 00:18:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2011/04/11 00:16:27 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\rb-Incr_Daily.job
[2011/04/11 00:00:03 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\Backup Service2000.job
[2011/04/10 23:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2011/04/10 22:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2011/04/10 21:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2011/04/10 02:03:50 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/09 00:16:36 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\rb-Incr_Sat.job
[2011/04/08 22:31:13 | 000,000,374 | ---- | M] () -- C:\WINDOWS\tasks\CopyTomsBackupToServer.job
[2011/04/08 21:03:37 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\1 Friday Full Backup.job
[2011/04/07 21:01:44 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\5 Thursday Incremental Backup.job
[2011/04/07 15:08:41 | 000,018,944 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\03.31.11.xlr
[2011/04/06 21:03:43 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\4 Wednesday Incremental Backup.job
[2011/04/06 13:50:19 | 000,049,152 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\RentalCars.xlr
[2011/04/06 09:53:46 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wlukakoyupune.dat
[2011/04/06 09:30:32 | 000,014,630 | -HS- | M] () -- D:\Documents and Settings\Rick\Local Settings\Application Data\3s01332t76tp114a55yo
[2011/04/06 09:30:32 | 000,014,630 | -HS- | M] () -- D:\Documents and Settings\All Users\Application Data\3s01332t76tp114a55yo
[2011/04/06 09:12:57 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/04/06 07:15:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Lpavaci.bin
[2011/04/05 21:00:07 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\3 Tuesday Incremental Backup.job
[2011/04/05 16:16:19 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/05 16:16:19 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/04/05 15:23:42 | 000,000,258 | ---- | M] () -- C:\WINDOWS\tasks\rb-Full.job
[2011/04/05 15:16:13 | 000,000,000 | ---- | M] () -- D:\Documents and Settings\Rick\NULL
[2011/04/05 15:14:41 | 000,143,360 | RHS- | M] () -- C:\WINDOWS\System32\TsWpfWrpg.dll
[2011/04/05 13:38:01 | 000,015,872 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\fax.wps
[2011/04/04 21:01:32 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\2 Monday Incremental Backup.job
[2011/04/04 15:04:12 | 000,017,920 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\Rental402.2008.xlr
[2011/04/03 05:01:41 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\First Sunday Image of C.job
[2011/04/03 04:37:43 | 000,000,250 | ---- | M] () -- C:\WINDOWS\tasks\FirstSundayCopyImagesOfC.job
[2011/04/01 09:13:01 | 000,015,872 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\AR.xlr
[2011/03/30 11:57:42 | 000,010,752 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\InkCartridge.xlr
[2011/03/25 16:50:22 | 000,010,752 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\oilchange.xlr
[2011/03/25 08:44:17 | 000,010,752 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\password.xlr
[2011/03/18 09:43:20 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\protrace.1684
[2011/03/15 14:09:44 | 000,000,548 | ---- | M] () -- D:\Documents and Settings\Rick\Desktop\Shortcut to 03.31.11.xlr.lnk
[2011/03/15 14:09:01 | 000,018,944 | ---- | M] () -- D:\Documents and Settings\Rick\My Documents\02.28.11.xlr
[4 D:\Documents and Settings\Rick\My Documents\*.tmp files -> D:\Documents and Settings\Rick\My Documents\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/11 08:06:21 | 000,000,007 | ---- | C] () -- C:\WINDOWS\System32\Class15
[2011/04/11 08:06:21 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\Band4
[2011/04/09 19:23:21 | 000,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/09 19:23:20 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2011/04/09 19:00:19 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2011/04/09 19:00:18 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2011/04/06 08:23:01 | 000,014,630 | -HS- | C] () -- D:\Documents and Settings\Rick\Local Settings\Application Data\3s01332t76tp114a55yo
[2011/04/06 08:23:01 | 000,014,630 | -HS- | C] () -- D:\Documents and Settings\All Users\Application Data\3s01332t76tp114a55yo
[2011/04/05 15:36:23 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/05 15:26:03 | 000,000,112 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\kAp70y4.dat
[2011/04/05 15:18:02 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Wlukakoyupune.dat
[2011/04/05 15:18:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Lpavaci.bin
[2011/04/05 15:16:13 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\Rick\NULL
[2011/04/05 15:14:41 | 000,143,360 | RHS- | C] () -- C:\WINDOWS\System32\TsWpfWrpg.dll
[2011/04/05 15:14:41 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\tasks\Cafczyevo.job
[2011/03/18 09:43:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\protrace.1684
[2011/03/15 14:09:44 | 000,000,548 | ---- | C] () -- D:\Documents and Settings\Rick\Desktop\Shortcut to 03.31.11.xlr.lnk
[2011/03/15 14:09:19 | 000,018,944 | ---- | C] () -- D:\Documents and Settings\Rick\My Documents\03.31.11.xlr
[2010/06/18 15:16:55 | 000,005,702 | ---- | C] () -- D:\Documents and Settings\Rick\Application Data\wklnhst.dat
[2009/11/06 13:54:14 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2009/10/22 13:23:37 | 000,000,024 | ---- | C] () -- C:\WINDOWS\brqikmon.ini
[2009/10/19 11:42:41 | 000,000,040 | ---- | C] () -- C:\WINDOWS\BO6050D.INI
[2009/10/19 11:36:49 | 000,000,296 | ---- | C] () -- C:\WINDOWS\BRDIAG.INI
[2009/10/19 11:36:49 | 000,000,026 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2009/10/19 11:36:49 | 000,000,015 | ---- | C] () -- C:\WINDOWS\BRVIDEO.INI
[2009/10/19 11:36:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\bw6050d.ini
[2009/10/19 11:36:48 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC32.DLL
[2009/10/19 11:36:48 | 000,004,608 | ---- | C] () -- C:\WINDOWS\System32\BRGSRC16.DLL
[2009/10/19 11:35:00 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2009/10/14 10:45:51 | 000,003,584 | ---- | C] () -- D:\Documents and Settings\Rick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/11 16:53:18 | 000,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2009/09/11 16:53:18 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2009/09/11 16:46:07 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2009/09/11 16:46:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat
[2009/09/11 16:35:38 | 000,000,209 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2009/09/11 16:35:38 | 000,000,092 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2009/09/11 16:35:38 | 000,000,065 | ---- | C] () -- C:\WINDOWS\System32\BD7420.dat
[2009/09/11 16:35:38 | 000,000,064 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2009/09/11 16:33:36 | 000,027,019 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2009/09/11 16:17:02 | 000,000,467 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/03/28 09:52:26 | 000,000,162 | -H-- | C] () -- C:\Program Files\Common Files\client.lcs
[2009/03/23 13:04:29 | 000,000,106 | ---- | C] () -- D:\Documents and Settings\Rick\Application Data\AVSDVDPlayer.m3u
[2009/03/16 10:00:33 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/03/16 10:00:32 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/03/15 00:25:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/03/15 00:20:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/03/14 16:00:12 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/03/14 15:57:33 | 000,177,056 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/14 13:55:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/03/14 13:33:42 | 000,000,195 | ---- | C] () -- C:\WINDOWS\OPLW.INI
[2009/03/14 12:41:56 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/03/14 11:35:16 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\ProExtra.dll
[2009/03/14 11:35:15 | 003,080,237 | ---- | C] () -- C:\WINDOWS\System32\Msowc.dll
[2009/03/14 09:39:59 | 000,001,732 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2009/03/14 08:43:27 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/10/04 04:14:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/10/04 04:14:00 | 001,626,112 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2007/10/04 04:14:00 | 001,478,656 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/10/04 04:14:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2007/10/04 04:14:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/10/04 04:14:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/10/04 04:14:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2007/10/04 04:14:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2007/10/04 04:14:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004/08/03 21:07:22 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/02 10:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2002/03/04 10:16:34 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2001/08/23 16:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 16:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 16:00:00 | 000,441,124 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 16:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 16:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 16:00:00 | 000,071,060 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 16:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 16:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 16:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 16:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2009/04/30 12:33:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Applications
[2011/04/11 07:15:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/09/11 16:33:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/01/08 16:59:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Application Data\SACore
[2009/03/17 12:04:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\Bullzip
[2010/01/05 15:10:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/04/05 15:17:25 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\Ekam
[2011/04/06 10:40:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\Liobid
[2010/11/16 09:07:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\ScanSoft
[2009/08/28 09:50:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\TeamViewer
[2009/03/26 13:53:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Rick\Application Data\Template
[2011/04/08 21:03:37 | 000,000,274 | ---- | M] () -- C:\WINDOWS\Tasks\1 Friday Full Backup.job
[2011/04/04 21:01:32 | 000,000,288 | ---- | M] () -- C:\WINDOWS\Tasks\2 Monday Incremental Backup.job
[2011/04/05 21:00:07 | 000,000,290 | ---- | M] () -- C:\WINDOWS\Tasks\3 Tuesday Incremental Backup.job
[2011/04/06 21:03:43 | 000,000,290 | ---- | M] () -- C:\WINDOWS\Tasks\4 Wednesday Incremental Backup.job
[2011/04/07 21:01:44 | 000,000,292 | ---- | M] () -- C:\WINDOWS\Tasks\5 Thursday Incremental Backup.job
[2011/04/11 00:18:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2011/04/11 09:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2011/04/11 10:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2011/04/11 11:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2011/04/11 12:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2011/04/11 13:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2011/04/11 14:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2011/04/11 15:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2011/04/11 16:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2011/04/11 17:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2011/04/11 18:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2011/04/11 01:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2011/04/11 19:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2011/04/11 20:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2011/04/10 21:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2011/04/10 22:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2011/04/10 23:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2011/04/11 02:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2011/04/11 03:00:02 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2011/04/11 04:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2011/04/11 05:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2011/04/11 06:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2011/04/11 07:00:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2011/04/11 08:00:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
[2011/04/11 00:00:03 | 000,000,286 | ---- | M] () -- C:\WINDOWS\Tasks\Backup Service2000.job
[2011/04/11 20:23:55 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\Tasks\Cafczyevo.job
[2011/04/11 20:08:20 | 000,000,288 | ---- | M] () -- C:\WINDOWS\Tasks\CopyNetworkBackupsToArchive.job
[2011/04/08 22:31:13 | 000,000,374 | ---- | M] () -- C:\WINDOWS\Tasks\CopyTomsBackupToServer.job
[2011/04/03 05:01:41 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\First Sunday Image of C.job
[2011/04/03 04:37:43 | 000,000,250 | ---- | M] () -- C:\WINDOWS\Tasks\FirstSundayCopyImagesOfC.job
[2011/04/05 15:23:42 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\rb-Full.job
[2011/04/11 00:16:27 | 000,000,270 | ---- | M] () -- C:\WINDOWS\Tasks\rb-Incr_Daily.job
[2011/04/09 00:16:36 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\rb-Incr_Sat.job
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 4/11/2011 8:34:57 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 16.43 Gb Free Space | 56.09% Space Free | Partition Type: NTFS
Drive D: | 119.75 Gb Total Space | 10.49 Gb Free Space | 8.76% Space Free | Partition Type: NTFS
Computer Name: RICK | User Name: Rick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-1606980848-1454471165-682003330-1003\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host -- (McAfee, Inc.)
"C:\WINDOWS\TEMP\frvn\setup.exe" = C:\WINDOWS\TEMP\frvn\setup.exe:*:Enabled:setup
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2515BF88-E42E-4AFA-A8E7-DF272762589B}" = Microsoft Office Live Meeting 2007
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 23
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE9327CE-B854-462B-92EB-56E829E50EE3}" = Default
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{F0674B40-D8C3-11D3-8C61-00104B1F6CF0}" = Remote Backup 2007
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FCC3BD6A-F118-475D-8748-7EE08EA0AF56}" = HDView for Internet Explorer
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"ATT-PRT22" = ATT-PRT22
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 3.0.0.352
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Google Updater" = Google Updater
"GPL Ghostscript 8.60" = GPL Ghostscript 8.60
"GPL Ghostscript Fonts" = GPL Ghostscript Fonts
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.16)" = Mozilla Firefox (3.0.16)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"SelectRebatesUninstall" = ShopAtHome.com Toolbar
"Service2000 Database Server" = Service2000 Database Server
"Service2000 Network Client" = Service2000 Network Client
"whitesmoketoolbar" = WhiteSmoke Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YInstHelper" = Yahoo! Install Manager
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1606980848-1454471165-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.452
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/11/2011 5:05:48 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:05:48 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:12:09 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:17:30 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:19:10 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:27:18 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 6:29:59 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 7:21:26 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 7:26:51 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
Error - 4/11/2011 7:30:37 PM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application AcV5o0Aq.exe, version 1.0.0.0, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x0000985e.
[ System Events ]
Error - 4/11/2011 11:01:56 AM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 11:01:56 AM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 11:01:56 AM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 11:41:00 AM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 12:00:27 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 12:00:34 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 12:00:37 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 12:00:43 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 12:01:03 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
Error - 4/11/2011 2:42:02 PM | Computer Name = RICK | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
as /. The error: "%2" Happened while starting this command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-Embedding
< End of report >