Hello _temp_, thanks for the help. Of course I understand about the wait....all volunteer basis for a free valuable service and a long wait happens often.
Sooo....everything is exactly as above: same virus messages, same problems with explorer.exe not starting on startup. The only major change that I've made is to update from Vista SP1 to SP2. Here are the OTL logs:
OTL logfile created on: 10/30/2009 12:25:20 PM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18828)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.04% Memory free
4.00 Gb Paging File | 2.88 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.21 Gb Total Space | 20.19 Gb Free Space | 20.35% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.23 Gb Free Space | 62.26% Space Free | Partition Type: NTFS
Drive E: | 679.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RYAN
Current User Name: Ryan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2009/10/30 12:23:11 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
PRC - [2009/10/27 23:09:54 | 01,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2009/10/27 23:09:54 | 00,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2009/10/27 23:09:54 | 00,502,040 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2009/10/27 23:09:53 | 02,010,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2009/10/27 23:09:52 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/10/18 18:38:39 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/10/09 11:24:55 | 00,919,024 | ---- | M] (Google Inc.) -- C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2009/09/29 01:28:23 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/08/26 20:41:45 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
PRC - [2009/08/24 14:22:36 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe
PRC - [2009/08/24 14:22:36 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Users\Ryan\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PRC - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/06/01 13:51:52 | 01,468,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2009/06/01 13:51:52 | 00,448,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
PRC - [2009/05/27 18:00:32 | 00,211,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe
PRC - [2009/05/21 10:55:32 | 00,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/17 03:35:18 | 00,408,424 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
PRC - [2009/04/10 23:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/04/10 23:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009/04/10 23:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/25 11:44:34 | 00,031,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008/10/25 08:18:50 | 00,098,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/01/19 00:33:40 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2008/01/19 00:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008/01/19 00:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008/01/19 00:33:15 | 00,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mobsync.exe
PRC - [2007/09/07 21:33:34 | 01,635,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2007/09/07 21:33:32 | 02,532,736 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2007/09/06 02:55:38 | 02,177,464 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2007/08/06 02:08:40 | 00,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2007/08/06 02:08:06 | 00,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/06/27 03:17:02 | 00,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
PRC - [2007/06/27 03:17:00 | 00,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\System32\STacSV.exe
PRC - [2007/05/31 08:21:28 | 00,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdc.exe
PRC - [2007/05/10 23:57:30 | 00,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\HidFind.exe
PRC - [2007/05/10 23:57:26 | 00,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/05/10 23:57:24 | 00,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/05/10 23:57:24 | 00,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apntex.exe
PRC - [2007/04/28 22:24:30 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe
PRC - [2007/04/27 07:34:18 | 01,123,872 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/04/16 15:10:26 | 00,184,320 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2007/03/21 12:33:44 | 01,548,288 | ---- | M] (Dell Inc.) -- C:\Windows\System32\WLTRAY.EXE
PRC - [2007/03/21 12:33:44 | 00,024,064 | ---- | M] () -- C:\Windows\System32\WLTRYSVC.EXE
PRC - [2007/03/21 12:33:42 | 01,724,416 | ---- | M] (Dell Inc.) -- C:\Windows\System32\bcmwltry.exe
PRC - [2006/11/03 17:02:14 | 00,050,688 | ---- | M] (Avanquest Software ) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/01/05 10:57:00 | 00,114,688 | ---- | M] (SanDisk) -- C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe
PRC - [2004/08/05 11:13:48 | 00,229,438 | ---- | M] (Thermo Electron Corporation) -- C:\Program Files\OMNIC\ThermoBenchService.exe
========== Win32 Services (SafeList) ========== SRV - [2009/10/27 23:09:52 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd [Auto | Running])
SRV - [2009/09/24 18:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll -- (FontCache [On_Demand | Stopped])
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/07/05 18:02:52 | 00,658,432 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/05/27 18:00:32 | 00,211,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running])
SRV - [2009/04/10 23:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2009/03/29 21:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/02/18 11:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/02/18 11:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2009/02/18 11:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2008/10/25 11:44:08 | 00,065,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2008/08/13 18:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter [Auto | Running])
SRV - [2008/01/19 00:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Stopped])
SRV - [2008/01/19 00:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])
SRV - [2008/01/19 00:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2007/10/11 08:49:46 | 00,076,016 | ---- | M] () -- C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe -- (DellAMBrokerService [On_Demand | Stopped])
SRV - [2007/09/07 21:35:04 | 00,234,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC [On_Demand | Stopped])
SRV - [2007/09/07 21:33:32 | 02,532,736 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService [Auto | Running])
SRV - [2007/09/06 02:55:38 | 02,177,464 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
SRV - [2007/08/11 19:05:27 | 03,093,872 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2007/08/06 02:08:06 | 00,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr [Auto | Running])
SRV - [2007/08/06 02:08:06 | 00,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr [Auto | Running])
SRV - [2007/06/27 03:17:00 | 00,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\System32\STacSV.exe -- (STacSV [Auto | Running])
SRV - [2007/05/31 08:21:24 | 00,379,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm [Auto | Running])
SRV - [2007/05/31 08:21:18 | 00,183,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr [Auto | Running])
SRV - [2007/04/28 22:24:30 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe -- (XAudioService [Auto | Running])
SRV - [2007/03/21 12:33:44 | 00,024,064 | ---- | M] () -- C:\Windows\System32\WLTRYSVC.EXE -- (wltrysvc [Auto | Running])
SRV - [2006/11/02 05:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 05:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2004/08/05 11:13:48 | 00,229,438 | ---- | M] (Thermo Electron Corporation) -- C:\Program Files\OMNIC\ThermoBenchService.exe -- (TMSRVC [Auto | Running])
========== Driver Services (SafeList) ========== DRV - [2009/10/27 23:09:54 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009/10/27 23:09:54 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
DRV - [2009/10/17 19:21:31 | 00,034,816 | ---- | M] () -- C:\Windows\System32\drivers\tatertot.scr.sys -- (tatertot.scr [On_Demand | Stopped])
DRV - [2009/10/17 17:40:45 | 00,034,816 | ---- | M] () -- C:\Windows\System32\drivers\tatertot.sys -- (tatertot [On_Demand | Stopped])
DRV - [2009/09/15 11:42:48 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Stopped])
DRV - [2009/09/15 11:42:46 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV [System | Running])
DRV - [2009/09/15 11:42:44 | 00,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL [System | Running])
DRV - [2009/08/28 19:42:52 | 00,040,448 | ---- | M] (Apple, Inc.) -- C:\Windows\System32\Drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
DRV - [2009/08/26 01:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
DRV - [2009/08/26 01:00:00 | 00,102,448 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2009/08/25 01:00:00 | 01,323,568 | ---- | M] (Symantec Corporation) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20091029.005\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
DRV - [2009/08/25 01:00:00 | 00,084,912 | ---- | M] (Symantec Corporation) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20091029.005\NAVENG.SYS -- (NAVENG [On_Demand | Running])
DRV - [2009/07/05 16:47:51 | 00,721,904 | ---- | M] () -- C:\Windows\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009/06/01 13:51:54 | 00,030,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRIVERS\point32k.sys -- (Point32 [On_Demand | Running])
DRV - [2009/05/27 16:04:00 | 09,850,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\DRIVERS\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
DRV - [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2009/05/09 01:14:20 | 00,014,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRIVERS\NuidFltr.sys -- (NuidFltr [On_Demand | Running])
DRV - [2009/04/10 21:42:54 | 00,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2008/07/30 17:42:12 | 00,023,888 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\COH_Mon.sys -- (COH_Mon [On_Demand | Stopped])
DRV - [2007/12/19 11:35:22 | 00,136,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
DRV - [2007/12/14 00:09:35 | 00,020,152 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2007/12/14 00:09:35 | 00,019,128 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2007/12/14 00:09:35 | 00,017,592 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2007/08/23 17:29:10 | 00,005,376 | --S- | M] (Gteko Ltd.) -- C:\Windows\System32\DRIVERS\datunidr.sys -- (datunidr [Auto | Running])
DRV - [2007/08/14 16:54:00 | 00,277,040 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SRTSPL.SYS -- (SRTSPL [On_Demand | Stopped])
DRV - [2007/08/14 16:54:00 | 00,250,416 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SRTSP.SYS -- (SRTSP [System | Running])
DRV - [2007/08/14 16:54:00 | 00,025,136 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SRTSPX.SYS -- (SRTSPX [System | Running])
DRV - [2007/07/31 01:17:26 | 00,418,864 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [System | Running])
DRV - [2007/06/27 03:17:04 | 00,326,656 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA [On_Demand | Running])
DRV - [2007/05/11 00:00:48 | 00,179,712 | ---- | M] (Broadcom Corporation) -- C:\Windows\System32\DRIVERS\b57nd60x.sys -- (b57nd60x [On_Demand | Stopped])
DRV - [2007/05/10 23:57:22 | 00,157,184 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Windows\System32\DRIVERS\Apfiltr.sys -- (ApfiltrService [On_Demand | Running])
DRV - [2007/04/28 23:43:22 | 00,277,784 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastor.sys -- (iaStor [Boot | Running])
DRV - [2007/04/28 23:34:36 | 00,037,376 | ---- | M] (REDC) -- C:\Windows\System32\DRIVERS\rixdptsk.sys -- (rismxdp [Auto | Running])
DRV - [2007/04/28 23:34:34 | 00,043,520 | ---- | M] (REDC) -- C:\Windows\System32\DRIVERS\rimsptsk.sys -- (rimsptsk [Auto | Running])
DRV - [2007/04/28 23:34:34 | 00,032,256 | ---- | M] (REDC) -- C:\Windows\System32\DRIVERS\rimmptsk.sys -- (rimmptsk [Auto | Running])
DRV - [2007/04/28 22:24:30 | 00,008,192 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.sys -- (XAudio [Auto | Running])
DRV - [2007/04/28 22:24:28 | 00,986,624 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\HSX_DPV.sys -- (HSF_DPV [On_Demand | Running])
DRV - [2007/04/28 22:24:28 | 00,659,968 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\HSX_CNXT.sys -- (winachsf [On_Demand | Running])
DRV - [2007/04/28 22:24:28 | 00,206,848 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\HSXHWAZL.sys -- (HSXHWAZL [On_Demand | Running])
DRV - [2007/04/28 22:24:28 | 00,012,672 | ---- | M] (Conexant) -- C:\Windows\System32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
DRV - [2007/03/21 12:33:46 | 00,534,016 | ---- | M] (Broadcom Corporation) -- C:\Windows\System32\DRIVERS\bcmwl6.sys -- (BCM43XX [On_Demand | Running])
DRV - [2007/01/09 15:46:26 | 00,191,544 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running])
DRV - [2007/01/09 15:46:26 | 00,027,576 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running])
DRV - [2006/11/06 18:37:16 | 00,078,128 | ---- | M] (Broadcom Corporation.) -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio [On_Demand | Running])
DRV - [2006/11/06 16:13:52 | 00,016,560 | ---- | M] (Broadcom Corporation.) -- C:\Windows\System32\DRIVERS\btwrchid.sys -- (btwrchid [On_Demand | Running])
DRV - [2006/11/06 16:13:50 | 00,080,176 | ---- | M] (Broadcom Corporation.) -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt [On_Demand | Running])
DRV - [2006/11/02 02:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 02:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 02:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2006/11/02 02:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2006/11/02 02:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 02:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Boot | Running])
DRV - [2006/11/02 02:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 02:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2006/11/02 02:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])
DRV - [2006/11/02 02:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2006/11/02 02:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2006/11/02 02:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 02:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2006/11/02 02:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 02:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2006/11/02 02:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2006/11/02 02:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Disabled | Stopped])
DRV - [2006/11/02 02:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 02:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2006/11/02 02:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2006/11/02 02:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 02:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2006/11/02 02:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2006/11/02 02:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2006/11/02 02:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 02:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 02:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 02:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 02:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 02:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 02:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 02:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2006/11/02 01:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 01:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 01:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 01:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 01:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 01:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 00:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 00:36:43 | 02,028,032 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\DRIVERS\atikmdag.sys -- (R300 [On_Demand | Stopped])
DRV - [2006/11/02 00:30:55 | 00,200,704 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\e1e6032.sys -- (e1express [On_Demand | Stopped])
DRV - [2006/11/02 00:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2006/11/01 23:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2006/10/05 15:07:28 | 00,004,736 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys -- (PTproct [On_Demand | Stopped])
DRV - [2003/07/16 20:37:44 | 00,016,509 | ---- | M] (Palm, Inc.) -- C:\Windows\System32\drivers\PalmUSBD.sys -- (PalmUSBD [On_Demand | Stopped])
========== Modules (SafeList) ========== MOD - [2009/10/30 12:23:11 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
MOD - [2009/10/27 23:09:54 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
MOD - [2009/04/10 23:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/dell?hl=en&cl...amp;ibd=3071214IE - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/dell?hl=en&cl...amp;ibd=3071214IE - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001\S-1-5-21-3041016070-1017456950-1424249797-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/11 20:52:16 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/29 01:28:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/18 18:56:19 | 00,000,000 | ---D | M]
[2009/06/13 13:17:56 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Extensions
[2009/06/13 13:17:56 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/25 18:13:49 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Firefox\Profiles\oib1us2g.default\extensions
[2009/08/14 06:56:45 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Firefox\Profiles\oib1us2g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/15 01:48:29 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Firefox\Profiles\oib1us2g.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/07 18:12:45 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Firefox\Profiles\oib1us2g.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/07/02 17:13:23 | 00,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\mozilla\Firefox\Profiles\oib1us2g.default\extensions\elemhidehelper@adblockplus.org
[2009/10/18 18:39:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/25 23:38:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/08 17:24:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/10/18 18:39:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/06/13 13:17:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\inspector@mozilla.org
[2009/06/13 13:17:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla.org
[2009/09/25 23:38:04 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/25 23:38:04 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/13 17:16:26 | 01,044,480 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\libdivx.dll
[2007/04/10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2009/10/18 18:38:42 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/07/13 17:15:48 | 01,650,992 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009/07/13 17:15:58 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2007/12/19 05:57:38 | 00,310,272 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
[2009/09/25 23:38:05 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/10/02 22:13:10 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/09/29 01:28:48 | 00,140,864 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/09/09 22:04:05 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/09 22:04:05 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/09 22:04:06 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/09 22:04:06 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/09 22:04:06 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/09 22:04:06 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/09 22:04:06 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/09/29 01:28:55 | 00,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2009/09/29 01:28:45 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/07/13 17:16:26 | 00,200,704 | ---- | M] (The OpenSSL Project,
http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
[2009/06/13 13:17:45 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/13 13:17:45 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/13 13:17:45 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/13 13:17:45 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/13 13:17:45 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/13 13:17:45 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\System32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001..\Run: [Google Update] C:\Users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Gita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O4 - Startup: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/Facebo...toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 130.212.10.163 130.212.10.238
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-8439818098-2080355288-076337672-6009\dllrun32.exe) - C:\RECYCLER\S-1-5-21-8439818098-2080355288-076337672-6009\dllrun32.exe File not found
O20 - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001 Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-3041016070-1017456950-1424249797-1001 Winlogon: Shell - ("C:\Users\Ryan\fbbv.exe") - C:\Users\Ryan\fbbv.exe File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/10/28 14:55:20 | 00,000,246 | ---- | M] () - F:\autorun.inf -- [ FAT ]
O33 - MountPoints2\{6f9b534c-b285-11de-aee3-001dd9e71551}\Shell\AutoRun\command - "" = I:\tmp.folder\restore.exe -- File not found
O33 - MountPoints2\{6f9b534c-b285-11de-aee3-001dd9e71551}\Shell\ExploRE\CoMmaNd - "" = I:\tmp.folder\restore.exe -- File not found
O33 - MountPoints2\{6f9b534c-b285-11de-aee3-001dd9e71551}\Shell\OPeN\commAnd - "" = I:\tmp.folder\restore.exe -- File not found
O33 - MountPoints2\{82e4def8-92cf-11de-83a8-001c23fb81ca}\Shell\AutoRun\command - "" = F:\_cache.tmp\gam3.exe -- File not found
O33 - MountPoints2\{82e4def8-92cf-11de-83a8-001c23fb81ca}\Shell\eXpLorE\cOMMand - "" = F:\_cache.tmp\gam3.exe -- File not found
O33 - MountPoints2\{82e4def8-92cf-11de-83a8-001c23fb81ca}\Shell\oPen\CoMMAnd - "" = F:\_cache.tmp\gam3.exe -- File not found
O33 - MountPoints2\{c3eeff6b-69be-11de-8058-001dd9e71551}\Shell - "" = AutoRun
O33 - MountPoints2\{c3eeff6b-69be-11de-8058-001dd9e71551}\Shell\AutoRun\command - "" = G:\Setup.exe -- File not found
O33 - MountPoints2\{f9e4932b-5551-11de-9071-001dd9e71551}\Shell\AutoRun\command - "" = folder.tmp/tmp.exe
O33 - MountPoints2\{f9e4932b-5551-11de-9071-001dd9e71551}\Shell\explore\command - "" = folder.tmp/tmp.exe
O33 - MountPoints2\{f9e4932b-5551-11de-9071-001dd9e71551}\Shell\open\command - "" = folder.tmp/tmp.exe
O33 - MountPoints2\H\Shell\AutoRun\command - "" = folder.tmp/tmp.exe
O33 - MountPoints2\H\Shell\explore\command - "" = folder.tmp/tmp.exe
O33 - MountPoints2\H\Shell\open\command - "" = folder.tmp/tmp.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ========== [2009/10/27 23:09:51 | 00,000,000 | ---D | C] -- C:\ProgramData\avg9
[2009/10/04 22:46:45 | 00,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2009/10/27 22:45:15 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2009/10/12 16:35:45 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2009/10/29 11:50:00 | 00,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\dvdcss
[2009/10/18 18:57:09 | 00,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\OpenOffice.org
[2009/10/27 22:45:47 | 00,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\Skype
[2009/10/27 22:50:16 | 00,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\skypePM
[2009/10/12 16:33:57 | 00,000,000 | ---D | C] -- C:\Users\Ryan\AppData\Roaming\SUPERAntiSpyware.com
[2009/10/27 22:45:26 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009/10/12 16:25:48 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/10/18 18:44:11 | 00,000,000 | ---D | C] -- C:\Program Files\JRE
[2009/10/27 23:11:26 | 00,000,000 | ---D | C] -- C:\Program Files\Logitech
[2009/10/18 18:42:04 | 00,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2009/10/19 17:55:37 | 00,000,000 | ---D | C] -- C:\Program Files\Runtime Software
[2009/10/27 22:45:24 | 00,000,000 | R--D | C] -- C:\Program Files\Skype
[2009/10/12 16:33:57 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/10/28 22:22:40 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2009/10/30 12:23:10 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2009/10/28 22:14:53 | 00,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
[2009/10/28 22:14:52 | 03,023,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2009/10/28 22:14:52 | 01,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2009/10/28 22:13:53 | 00,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2009/10/28 22:13:53 | 00,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winspool.drv
[2009/10/28 22:13:52 | 00,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgkrnl.sys
[2009/10/28 22:13:52 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2009/10/28 22:13:50 | 00,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2009/10/28 22:13:50 | 00,829,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2009/10/28 22:13:50 | 00,828,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2009/10/28 22:13:50 | 00,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2009/10/28 22:13:50 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2009/10/28 22:13:50 | 00,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2009/10/28 22:13:50 | 00,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2009/10/28 22:13:50 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2009/10/28 22:13:50 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2009/10/28 22:13:49 | 01,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2009/10/28 22:13:49 | 01,064,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2009/10/28 22:13:49 | 00,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2009/10/28 22:13:49 | 00,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll
[2009/10/28 22:13:49 | 00,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2009/10/28 22:13:49 | 00,486,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2009/10/28 22:13:49 | 00,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2009/10/28 22:13:49 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2009/10/28 22:13:49 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2009/10/28 22:13:48 | 01,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2009/10/28 22:13:48 | 00,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2009/10/28 22:13:48 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2009/10/28 22:13:48 | 00,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2009/10/28 22:13:48 | 00,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2009/10/28 22:12:44 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
[2009/10/28 22:12:43 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdbusenum.dll
[2009/10/28 22:12:43 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BthMtpContextHandler.dll
[2009/10/28 22:12:33 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceConnectApi.dll
[2009/10/28 22:12:28 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdConns.dll
[2009/10/28 22:12:27 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdMtpUS.dll
[2009/10/28 22:12:27 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WpdUsb.sys
[2009/10/28 22:12:26 | 02,537,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpdshext.dll
[2009/10/28 22:12:26 | 00,546,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2009/10/28 22:12:26 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2009/10/28 22:12:26 | 00,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2009/10/28 22:12:26 | 00,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdMtp.dll
[2009/10/28 22:12:26 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
[2009/10/28 22:12:26 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
[2009/10/28 22:12:26 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/10/28 22:12:26 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShServiceObj.dll
[2009/10/28 22:09:29 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
[2009/10/28 22:09:27 | 00,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2009/10/28 22:09:27 | 00,234,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
[2009/10/28 07:57:46 | 10,627,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll
[2009/10/28 07:57:42 | 00,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unregmp2.exe
[2009/10/28 07:57:39 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2009/10/27 23:10:29 | 00,000,000 | -H-D | C] -- C:\$AVG
[2009/10/26 21:53:14 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Desktop\AP Kinetics
[2009/10/20 21:48:34 | 00,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2009/10/20 21:48:34 | 00,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2009/10/20 21:48:24 | 00,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2009/10/18 20:05:15 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Desktop\cucdcr
[2009/10/18 18:39:45 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2009/10/18 18:39:45 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2009/10/18 18:39:45 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2009/10/18 18:27:42 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Desktop\OpenOffice.org 3.1 (en-US) Installation Files
[2009/10/18 18:00:01 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Desktop\groupreport
[2009/10/15 11:06:23 | 05,940,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/10/15 11:06:22 | 11,069,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/10/15 11:06:21 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/10/15 11:06:21 | 01,208,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/10/15 11:06:21 | 00,916,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/10/15 11:06:21 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/10/15 11:06:20 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/10/15 11:06:20 | 00,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/10/15 11:06:20 | 00,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/10/15 11:06:20 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/10/15 11:06:20 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/10/15 11:06:19 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/10/15 11:06:19 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/10/15 11:06:19 | 00,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/10/15 11:06:19 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/10/15 11:06:19 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/10/15 11:06:19 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/10/15 11:06:19 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/10/15 11:06:19 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/10/15 11:06:19 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/10/15 11:05:33 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/10/15 11:05:22 | 03,600,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2009/10/15 11:05:21 | 03,548,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009/10/15 11:03:43 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll
[2009/10/15 11:03:40 | 00,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys
[2009/10/15 11:03:37 | 00,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2009/10/12 16:27:59 | 00,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2009/10/12 16:27:46 | 00,333,192 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2009/10/12 16:27:45 | 00,028,424 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2009/10/12 16:26:10 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg
[2009/10/05 10:01:11 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Documents\Fall 09 - Chem 422
[2009/10/05 09:40:48 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Documents\Fall 09 - BIOL 328
[2009/10/04 22:47:03 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Documents\Simply Super Software
[2009/10/04 12:41:48 | 00,000,000 | ---D | C] -- C:\Users\Ryan\Documents\SUP
[2009/10/03 20:08:02 | 00,195,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
========== Files - Modified Within 30 Days ========== [2009/10/30 12:30:19 | 00,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D98DA5A6-DD2C-43C3-B24F-11905611C603}.job
[2009/10/30 12:23:11 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2009/10/30 11:53:57 | 03,393,528 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/30 11:53:57 | 01,144,820 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/30 11:53:57 | 01,100,152 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/30 11:04:02 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/30 11:04:02 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/30 09:07:24 | 00,088,672 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009/10/30 09:04:37 | 00,088,672 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009/10/30 09:04:18 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/30 09:03:59 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/30 09:03:36 | 21,455,83104 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/30 07:33:32 | 00,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2009/10/30 07:32:23 | 02,795,520 | -H-- | M] () -- C:\Users\Ryan\AppData\Local\IconCache.db
[2009/10/30 04:05:22 | 00,000,162 | -H-- | M] () -- C:\Users\Ryan\Desktop\~$8_review_exam_2.doc
[2009/10/30 04:05:06 | 00,084,992 | ---- | M] () -- C:\Users\Ryan\Desktop\328_review_exam_2.doc
[2009/10/29 12:52:13 | 00,050,176 | ---- | M] () -- C:\Users\Ryan\Desktop\Foreign Outreach Centralized Info.xls
[2009/10/29 10:31:30 | 44,366,342 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2009/10/29 10:30:59 | 00,064,405 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg
[2009/10/28 22:53:55 | 00,021,504 | -H-- | M] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/28 22:22:02 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009/10/28 22:21:10 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/10/28 22:01:59 | 00,040,960 | ---- | M] () -- C:\Users\Ryan\Documents\Brain Worksheet.doc
[2009/10/28 22:01:27 | 00,029,452 | ---- | M] () -- C:\Users\Ryan\Documents\Brain Worksheet.docx
[2009/10/27 23:09:56 | 00,001,649 | ---- | M] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2009/10/27 23:09:54 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2009/10/27 23:09:54 | 00,113,461 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2009/10/27 23:09:54 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2009/10/27 23:09:54 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2009/10/27 22:50:17 | 00,000,048 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2009/10/26 18:50:05 | 00,053,248 | ---- | M] () -- C:\Users\Ryan\Desktop\Foreign Contacts (1).doc
[2009/10/26 18:42:30 | 00,072,192 | ---- | M] () -- C:\Users\Ryan\Desktop\SUP ROLES! new.doc
[2009/10/26 16:39:51 | 00,795,746 | ---- | M] () -- C:\Users\Ryan\Desktop\woms_713_f08_f6.pdf
[2009/10/23 16:32:35 | 00,093,515 | ---- | M] () -- C:\Users\Ryan\Desktop\09.docx
[2009/10/23 13:21:59 | 00,056,320 | ---- | M] () -- C:\Users\Ryan\Desktop\March 18th Talking Points.doc
[2009/10/23 13:21:45 | 00,063,488 | ---- | M] () -- C:\Users\Ryan\Desktop\Actual Proposal 318.doc
[2009/10/23 00:34:42 | 00,000,000 | ---- | M] () -- C:\Windows\System32\null
[2009/10/22 12:19:30 | 00,039,424 | ---- | M] () -- C:\Users\Ryan\Desktop\SFSU General Assembly October 21, 2009.doc
[2009/10/22 01:21:13 | 00,346,924 | ---- | M] () -- C:\Users\Ryan\Desktop\Call of Cthulhu Savegame.zip
[2009/10/20 22:00:52 | 00,398,392 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/10/20 20:57:57 | 00,010,104 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS Results Abstract.docx
[2009/10/20 20:39:40 | 00,021,504 | ---- | M] () -- C:\Users\Ryan\Desktop\tables for method.doc
[2009/10/20 20:38:46 | 00,181,384 | ---- | M] () -- C:\Users\Ryan\Desktop\es802544n.pdf
[2009/10/20 08:55:41 | 00,129,024 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS.doc
[2009/10/20 08:55:22 | 00,024,677 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS.docx
[2009/10/19 23:00:38 | 00,053,248 | ---- | M] () -- C:\Users\Ryan\Desktop\Foreign Contacts.doc
[2009/10/19 22:52:29 | 02,617,480 | ---- | M] () -- C:\Users\Ryan\Desktop\1-01 The Birds and the Bees - Thinking about Sex and Gender.mp3
[2009/10/19 22:32:23 | 00,062,976 | ---- | M] () -- C:\Users\Ryan\Desktop\Minutes101509.doc
[2009/10/19 18:13:22 | 00,331,264 | ---- | M] () -- C:\Users\Ryan\Desktop\dds.scr
[2009/10/19 18:00:35 | 00,106,424 | ---- | M] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT
[2009/10/19 17:56:32 | 00,041,420 | ---- | M] () -- C:\Users\Ryan\Desktop\dixml.chm
[2009/10/19 17:55:47 | 00,000,914 | ---- | M] () -- C:\Users\Public\Desktop\DriveImage XML.lnk
[2009/10/19 10:10:30 | 01,044,464 | ---- | M] () -- C:\Users\Ryan\Desktop\How to write journal articles F09 iLearn.pptm
[2009/10/19 10:10:24 | 00,049,152 | ---- | M] () -- C:\Users\Ryan\Desktop\CHEM 422 LAB REPORTS.doc
[2009/10/18 20:06:16 | 00,047,104 | ---- | M] () -- C:\Users\Ryan\Desktop\grad_spreadsheet.doc
[2009/10/18 20:04:52 | 00,011,697 | ---- | M] () -- C:\Users\Ryan\Desktop\cucdcr.rar
[2009/10/18 18:38:35 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2009/10/18 18:38:35 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2009/10/18 18:38:35 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2009/10/18 18:38:34 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2009/10/18 18:33:05 | 00,001,800 | ---- | M] () -- C:\Users\Ryan\Desktop\Monitoring.RDP
[2009/10/18 17:59:18 | 00,049,483 | ---- | M] () -- C:\Users\Ryan\Desktop\groupreport.rar
[2009/10/18 17:26:47 | 12,524,032 | ---- | M] () -- C:\Users\Ryan\Desktop\Persistent Fall whole 10.17.09.doc
[2009/10/17 20:51:11 | 00,002,039 | ---- | M] () -- C:\Users\Ryan\Desktop\Google Chrome.lnk
[2009/10/17 19:21:31 | 00,034,816 | ---- | M] () -- C:\Windows\System32\drivers\tatertot.scr.sys
[2009/10/17 17:40:45 | 00,034,816 | ---- | M] () -- C:\Windows\System32\drivers\tatertot.sys
[2009/10/12 16:26:19 | 00,492,629 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/10/12 16:26:18 | 06,061,540 | ---- | M] () -- C:\Windows\System32\drivers\Avg\avi7.avg
[2009/10/08 16:12:09 | 00,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2009/10/08 14:08:01 | 00,555,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2009/10/08 14:08:01 | 00,234,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
[2009/10/08 14:07:59 | 00,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
[2009/10/07 08:04:49 | 00,019,827 | ---- | M] () -- C:\Users\Ryan\Documents\Sentence Completion Responses.docx
[2009/10/05 07:12:47 | 00,027,136 | ---- | M] () -- C:\Users\Ryan\Documents\March 18th day of Action.doc
[2009/10/04 21:13:59 | 00,016,193 | ---- | M] () -- C:\Users\Ryan\Documents\Instructions for Sentence Completion Programs.docx
[2009/10/04 12:38:45 | 00,000,374 | ---- | M] () -- C:\Users\Ryan\Desktop\Documents.lnk
[2009/10/02 11:01:57 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/10/01 10:53:41 | 00,099,825 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 343 SDS-Page Lab Report1.docx
[2009/10/01 10:29:14 | 00,195,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2009/09/30 20:25:16 | 00,022,253 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 343 Gel Separation Data.xlsx
[2009/09/30 18:08:10 | 00,003,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\en-US\wpdmtpdr.dll.mui
[2009/09/30 18:02:17 | 02,537,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpdshext.dll
[2009/09/30 18:02:05 | 00,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
[2009/09/30 18:02:04 | 00,334,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2009/09/30 18:02:02 | 00,087,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WPDShServiceObj.dll
[2009/09/30 18:02:00 | 00,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\BthMtpContextHandler.dll
[2009/09/30 18:01:59 | 00,546,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2009/09/30 18:01:59 | 00,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
[2009/09/30 18:01:56 | 00,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2009/09/30 18:01:56 | 00,196,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
[2009/09/30 18:01:56 | 00,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/09/30 18:01:56 | 00,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceConnectApi.dll
[2009/09/30 18:01:54 | 00,839,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\WpdMtpDr.dll
[2009/09/30 18:01:54 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpdbusenum.dll
[2009/09/30 18:01:54 | 00,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\WpdUsb.sys
[2009/09/30 18:01:52 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\WpdFs.dll
[2009/09/30 18:01:50 | 00,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WpdMtp.dll
[2009/09/30 18:01:49 | 00,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WpdMtpUS.dll
[2009/09/30 18:01:49 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WpdConns.dll
[2009/09/30 15:01:44 | 00,091,640 | ---- | M] () -- C:\Users\Ryan\Documents\CHEM 343 Gel Separation Coomassie Figures.docx
========== Files - No Company Name ==========[2009/10/30 04:05:22 | 00,000,162 | -H-- | C] () -- C:\Users\Ryan\Desktop\~$8_review_exam_2.doc
[2009/10/30 04:05:05 | 00,084,992 | ---- | C] () -- C:\Users\Ryan\Desktop\328_review_exam_2.doc
[2009/10/29 12:25:56 | 00,050,176 | ---- | C] () -- C:\Users\Ryan\Desktop\Foreign Outreach Centralized Info.xls
[2009/10/28 22:22:02 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009/10/28 22:21:10 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/10/28 22:01:35 | 00,040,960 | ---- | C] () -- C:\Users\Ryan\Documents\Brain Worksheet.doc
[2009/10/28 22:01:26 | 00,029,452 | ---- | C] () -- C:\Users\Ryan\Documents\Brain Worksheet.docx
[2009/10/27 23:09:56 | 00,001,649 | ---- | C] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2009/10/27 23:09:54 | 00,113,461 | ---- | C] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2009/10/27 22:50:17 | 00,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/10/26 18:50:05 | 00,053,248 | ---- | C] () -- C:\Users\Ryan\Desktop\Foreign Contacts (1).doc
[2009/10/26 18:42:30 | 00,072,192 | ---- | C] () -- C:\Users\Ryan\Desktop\SUP ROLES! new.doc
[2009/10/26 16:39:41 | 00,795,746 | ---- | C] () -- C:\Users\Ryan\Desktop\woms_713_f08_f6.pdf
[2009/10/23 16:32:35 | 00,093,515 | ---- | C] () -- C:\Users\Ryan\Desktop\09.docx
[2009/10/23 13:21:59 | 00,056,320 | ---- | C] () -- C:\Users\Ryan\Desktop\March 18th Talking Points.doc
[2009/10/23 13:21:45 | 00,063,488 | ---- | C] () -- C:\Users\Ryan\Desktop\Actual Proposal 318.doc
[2009/10/22 12:19:30 | 00,039,424 | ---- | C] () -- C:\Users\Ryan\Desktop\SFSU General Assembly October 21, 2009.doc
[2009/10/22 01:21:11 | 00,346,924 | ---- | C] () -- C:\Users\Ryan\Desktop\Call of Cthulhu Savegame.zip
[2009/10/20 20:49:52 | 00,010,104 | ---- | C] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS Results Abstract.docx
[2009/10/20 20:39:39 | 00,021,504 | ---- | C] () -- C:\Users\Ryan\Desktop\tables for method.doc
[2009/10/20 20:38:45 | 00,181,384 | ---- | C] () -- C:\Users\Ryan\Desktop\es802544n.pdf
[2009/10/20 08:55:35 | 00,129,024 | ---- | C] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS.doc
[2009/10/19 23:00:38 | 00,053,248 | ---- | C] () -- C:\Users\Ryan\Desktop\Foreign Contacts.doc
[2009/10/19 22:51:44 | 02,617,480 | ---- | C] () -- C:\Users\Ryan\Desktop\1-01 The Birds and the Bees - Thinking about Sex and Gender.mp3
[2009/10/19 22:32:23 | 00,062,976 | ---- | C] () -- C:\Users\Ryan\Desktop\Minutes101509.doc
[2009/10/19 18:13:22 | 00,331,264 | ---- | C] () -- C:\Users\Ryan\Desktop\dds.scr
[2009/10/19 18:00:35 | 00,106,424 | ---- | C] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT
[2009/10/19 17:56:32 | 00,041,420 | ---- | C] () -- C:\Users\Ryan\Desktop\dixml.chm
[2009/10/19 17:55:47 | 00,000,914 | ---- | C] () -- C:\Users\Public\Desktop\DriveImage XML.lnk
[2009/10/19 10:20:29 | 00,024,677 | ---- | C] () -- C:\Users\Ryan\Documents\CHEM 422 FAAS.docx
[2009/10/19 10:10:29 | 01,044,464 | ---- | C] () -- C:\Users\Ryan\Desktop\How to write journal articles F09 iLearn.pptm
[2009/10/19 10:10:24 | 00,049,152 | ---- | C] () -- C:\Users\Ryan\Desktop\CHEM 422 LAB REPORTS.doc
[2009/10/18 20:06:14 | 00,047,104 | ---- | C] () -- C:\Users\Ryan\Desktop\grad_spreadsheet.doc
[2009/10/18 20:04:52 | 00,011,697 | ---- | C] () -- C:\Users\Ryan\Desktop\cucdcr.rar
[2009/10/18 17:59:18 | 00,049,483 | ---- | C] () -- C:\Users\Ryan\Desktop\groupreport.rar
[2009/10/18 17:26:18 | 12,524,032 | ---- | C] () -- C:\Users\Ryan\Desktop\Persistent Fall whole 10.17.09.doc
[2009/10/17 19:36:14 | 21,455,83104 | -HS- | C] () -- C:\hiberfil.sys
[2009/10/17 17:40:45 | 00,034,816 | ---- | C] () -- C:\Windows\System32\drivers\tatertot.sys
[2009/10/17 17:38:15 | 00,034,816 | ---- | C] () -- C:\Windows\System32\drivers\tatertot.scr.sys
[2009/10/12 16:26:20 | 44,366,342 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2009/10/12 16:26:19 | 00,064,405 | ---- | C] () -- C:\Windows\System32\drivers\Avg\microavi.avg
[2009/10/12 16:26:18 | 00,492,629 | ---- | C] () -- C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/10/12 16:26:10 | 06,061,540 | ---- | C] () -- C:\Windows\System32\drivers\Avg\avi7.avg
[2009/10/05 07:12:46 | 00,027,136 | ---- | C] () -- C:\Users\Ryan\Documents\March 18th day of Action.doc
[2009/10/04 12:38:45 | 00,000,374 | ---- | C] () -- C:\Users\Ryan\Desktop\Documents.lnk
[2009/09/30 15:07:53 | 00,099,825 | ---- | C] () -- C:\Users\Ryan\Documents\CHEM 343 SDS-Page Lab Report1.docx
[2009/09/29 12:08:42 | 02,795,520 | -H-- | C] () -- C:\Users\Ryan\AppData\Local\IconCache.db
[2009/09/25 22:43:11 | 00,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/09/25 22:43:11 | 00,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/09/23 07:38:12 | 00,000,680 | ---- | C] () -- C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2009/09/21 16:48:02 | 00,000,024 | ---- | C] () -- C:\Windows\tb60.ini
[2009/09/21 16:48:02 | 00,000,024 | ---- | C] () -- C:\Windows\tb50.ini
[2009/09/21 16:29:53 | 00,000,321 | ---- | C] () -- C:\Windows\winhlp32.ini
[2009/09/21 16:29:53 | 00,000,321 | ---- | C] () -- C:\Windows\winhelp.ini
[2009/09/21 16:24:45 | 00,000,551 | ---- | C] () -- C:\Windows\omnic32.ini
[2009/09/21 16:21:23 | 00,001,278 | ---- | C] () -- C:\Windows\OMUPDATE.INI
[2009/09/20 16:02:37 | 00,000,113 | ---- | C] () -- C:\Windows\photoimpression.ini
[2009/09/20 16:02:37 | 00,000,029 | ---- | C] () -- C:\Windows\videoimp.ini
[2009/09/20 16:01:36 | 00,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2009/09/17 03:03:40 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/07 19:51:34 | 00,178,430 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2009/08/07 04:32:55 | 00,088,672 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/08/07 04:32:55 | 00,088,672 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/29 16:17:26 | 00,021,504 | -H-- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/06 19:57:50 | 00,037,841 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\Comma Separated Values (Windows).ADR
[2009/07/05 16:47:50 | 00,721,904 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/07/05 10:18:50 | 00,000,150 | ---- | C] () -- C:\Windows\Lexstat.ini
[2009/06/20 19:47:18 | 00,048,104 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.001
[2009/06/20 19:47:10 | 00,048,104 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.dat
[2009/06/08 19:28:58 | 00,102,248 | -H-- | C] () -- C:\Users\Ryan\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/10/07 09:13:30 | 00,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008/08/13 14:59:06 | 00,229,376 | ---- | C] () -- C:\Windows\System32\ISP2000.dll
[2007/12/14 00:09:56 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007/12/13 16:30:00 | 00,065,536 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2006/11/03 16:25:56 | 00,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/11/02 05:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 05:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 03:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 00:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2004/11/03 11:45:04 | 00,000,488 | ---- | C] () -- C:\Windows\turbo32.ini
[2001/11/14 11:56:00 | 01,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[2001/02/01 04:00:00 | 00,000,189 | ---- | C] () -- C:\Windows\NicBib.ini
========== Alternate Data Streams ========== @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:62E2D794
< End of report >
OTL Extras logfile created on: 10/30/2009 12:25:20 PM - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18828)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.04% Memory free
4.00 Gb Paging File | 2.88 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.21 Gb Total Space | 20.19 Gb Free Space | 20.35% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.23 Gb Free Space | 62.26% Space Free | Partition Type: NTFS
Drive E: | 679.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RYAN
Current User Name: Ryan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\TESTOUT\Cmi\Navigator.exe" = C:\Program Files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator -- (TestOut Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\TESTOUT\Cmi\Navigator.exe" = C:\Program Files\TESTOUT\Cmi\Navigator.exe:*:Disabled:TestOut Navigator -- (TestOut Corporation)
========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{148BA972-2DDF-4D72-ADDF-435C28508E48}" = lport=10421 | protocol=17 | dir=in | name=singleclick discovery protocol |
"{314DAE50-BA36-4027-A582-1805D9DD9D7F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{387D8631-BEA3-4F8C-829E-7936A7A0A26E}" = lport=138 | protocol=17 | dir=in | name=netbios datagram service |
"{58C4AFF6-16B3-4CFC-AF7A-C54DD1E964DF}" = lport=10426 | protocol=17 | dir=in | name=singleclick icc |
"{70E60FCB-8642-4461-857F-399E5301340A}" = lport=445 | protocol=6 | dir=in | name=microsoft directory services |
"{770DCEC2-4076-4B48-BA67-B4FBF7E81900}" = lport=139 | protocol=6 | dir=in | name=netbios file/printer sharing |
"{7F3DD851-626F-4D39-87BF-61D148154250}" = lport=137 | protocol=17 | dir=in | name=netbios name service |
"{8492E727-5D35-4808-BEB0-545C6873A631}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A03634E0-B4DE-459A-98A1-D6BD252E1187}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A5500216-857A-4EFF-B71D-52B1B03EF297}" = lport=2869 | protocol=6 | dir=in | app=system |
"{ABEA0B03-DE01-4B19-804D-CB4074D0EB54}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{B9983B15-EE86-48C0-A91E-9FE7B3DD2498}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CADBD647-F124-4C78-B29E-10DA5219F10B}" = rport=10243 | protocol=6 | dir=out | app=system |
"{CBB259AC-4583-4CDE-91D3-1EB6C6F740AC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DF60D87F-9196-41D3-B0D0-A3C92C4C5974}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E8365472-F855-4842-93C1-2B7521D7E523}" = lport=48149 | protocol=6 | dir=in | name=utorrent port |
"{EA8484DB-5BDC-4DBE-83AA-B790F85BB36F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01298CBC-EA57-4366-9AF1-ACE8948E29FE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{019C0E97-4C70-40F4-8E69-0ECBD5F3B55F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{032BC3DD-BE3E-4D5A-8EE8-5BA14F117AB0}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{0B186DFB-6D3D-4416-9204-9E1E1CFD05AA}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{0B2A7B94-9DB4-4558-BAAC-DDC01A159E9A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0B6F612F-FC1E-42AE-88C6-E17A920A07D7}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{0FDB7942-FD19-419B-83BF-E8F076057828}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1052C06D-A56E-426A-912E-8E32036EF456}" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{12240CF1-3E0B-45FD-9322-B0B8DAA2AE84}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{143F3091-E239-4B82-87B6-6A459044C36D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1AB051A1-6871-47E4-BE1F-437F74F8068F}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{1E072C54-30A5-4D8A-9824-77608A9602D3}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbcpswx.exe |
"{1FE02C14-1B12-4187-9A5E-308DF70439DB}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{2B982C57-2120-48BC-9EB3-F9B1A28FCE07}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{31BFB531-396B-4596-8782-2ABDD2839C0C}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\symcorpui.exe |
"{362189AB-1FF2-403D-888B-08FEE802286E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3C63C2B8-26C3-4E3A-9132-5BF52B394D8F}" = protocol=17 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{3D8858F1-4AB9-40F8-BC84-13E91B6109E1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3E9CB313-3C18-461B-BBD5-314BD8F7364A}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{3F178A4F-CB96-45A8-9BB8-7D2A8B3C324B}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{40FC9ED1-6097-4601-843C-296F4B82CBD3}" = dir=in | app=rosettastoneversion3.exe |
"{4AD830AD-BDE9-4F17-878F-647A3B366FB6}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{4EBB7FC7-D158-466D-97F6-AF60719141B7}" = protocol=6 | dir=out | app=support inrosettastoneltdservices.exe |
"{5214BBD0-EFC9-4889-97BB-660AFC2BE380}" = protocol=6 | dir=out | app=system |
"{5331075D-BDB1-47C2-AE69-B524A181237B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{550454BA-7150-4D21-8C67-1CC012CBA99E}" = protocol=6 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{5561C310-A276-4BB3-A923-EA056CAFA464}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{592862C5-7189-4DAD-89FF-F6C30F9C7F5A}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbcpswx.exe |
"{60F15486-01D5-498E-AE3F-5F3C8EF38551}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{61721DF5-C251-496D-9FAA-A983B4DA9620}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{64474037-D863-4B4C-9DF4-70EF6528AD36}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{67DC12D2-D684-4FD6-A247-D0C2B9BE515F}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
"{7B9401AE-F4BB-4BD3-84D9-EF2FBF7A7291}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D6FD8B7-0256-452B-A681-031BB5572D8B}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"{82D93344-0E4A-4278-BF37-D8A1B383E546}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
"{8E8806F6-BBFD-458F-AF29-11C7024782BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{91F69431-6796-4B5F-88EC-7D157BBB3233}" = dir=in | app=support inrosettastoneltdservices.exe |
"{98C3CC5C-3A3A-460B-AB4A-766634F6EB5F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A252D4A5-D003-4A94-92EE-9A5A33F099C2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A8087F8C-E0D0-452C-BD91-51320F5EFA49}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\symcorpui.exe |
"{AACA087B-2F7C-465C-86D3-6BA22CEEF869}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
"{AB03217B-64A8-4D6B-93CC-1FD0417C21E5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BB8BE7EF-CA77-4F2C-86BD-1185CD18ADA8}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C299098D-92F4-489D-90C5-F58D4B8E50DF}" = protocol=6 | dir=out | app=rosettastoneversion3.exe |
"{CE00EF78-F00E-4743-824D-9F58BE08AC65}" = protocol=6 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{D2E86DCA-A72A-460E-810E-342E80FD3636}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D4BC6622-0570-490E-8BEF-B881655ADCB4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{DF831481-D6A3-45B7-88CF-F6F793F88C17}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E5E91DAC-D373-4DC4-BF73-27462C4C3B83}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EF50A0B8-FD8C-4CE0-9BE3-A31473CDD460}" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{F42400D3-B77E-46F0-BF40-7CEC46E0CC62}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FC5CA402-DB30-4A96-BF17-8C20D99725C5}" = protocol=17 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{FD0D93D7-21DB-44E4-A4C4-098F4B610ACF}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
"TCP Query User{4082E8D0-711A-4334-83AB-EC8350A2FA93}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B6C2E2EA-62A3-441E-9F4E-8A337E236D4B}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{CECCBBD5-F7A6-4D13-ADEF-0470DA5838D4}C:\program files\palm\hotsync.exe" = protocol=6 | dir=in | app=c:\program files\palm\hotsync.exe |
"TCP Query User{DEA7C9FF-09C8-4ADE-A18A-B901CF43127C}C:\program files\microsoft office\office12\onenote.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"TCP Query User{F72C1EED-B534-4808-9599-1722D3DB1B8D}C:\program files\palm\hotsync.exe" = protocol=6 | dir=in | app=c:\program files\palm\hotsync.exe |
"TCP Query User{F7767D36-99F2-4E44-A9FA-F34847DCB683}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{391AFB21-AE59-4603-8A6E-E39FBEE8CFAC}C:\program files\palm\hotsync.exe" = protocol=17 | dir=in | app=c:\program files\palm\hotsync.exe |
"UDP Query User{6AC8A0B3-4F6A-490E-988C-DDC1223FBC5B}C:\program files\palm\hotsync.exe" = protocol=17 | dir=in | app=c:\program files\palm\hotsync.exe |
"UDP Query User{738EAE6A-E4A9-495F-875C-6BB019E7D4AB}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{94F3AEAE-AFD7-4EC7-B0D1-313263B8CB50}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{CB4B7B6A-D44B-45DF-B14D-58695555D3EB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{EAF697AF-B1E9-4483-BED0-84E5E9D6B78F}C:\program files\microsoft office\office12\onenote.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = QualxServ Service Agreement
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = RemoteCapture 2.7.5
"{1481269D-8548-4439-85EC-097CFF86BC05}" = Smart Accessory Tutorials
"{16D919E6-F019-4E15-BFBE-4A85EF19DA57}" = Oblivion - Spell Tomes
"{178B7DE9-44F7-440B-B4B7-DCA56EF91652}" = Nicolet 4700 Spectrometer Help
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 16
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{2F2E3D62-8B8C-448F-8900-451325E50948}" = Oblivion - Wizard's Tower
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java SE Runtime Environment 6
"{33F327F6-254A-4C5B-8009-B94CE2655E22}" = TQ Analyst v6 EZ Edition
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4FFC7852-787A-4CA8-888A-ED517D905AEA}" = OMNIC Peak Resolve
"{520F4B09-3A51-47A2-82B0-9FF1DC2D20FA}" = Oblivion - Vile Lair
"{5735FB0C-6DFA-4240-BA3F-26BE4B3B3A86}" = OMNIC
"{584D8056-03EE-4C4A-AB55-2A5967956881}" = 4700 and 6700 User Guide
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5EFE22A3-7794-11D4-862B-00A0C967A936}" = OMNIC Applications Bibliography
"{601C6E14-DF1E-4113-A8C8-F9DB90CB0D88}" = SanDisk TransferMate
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6CD22C16-63B6-48F7-83CF-AABABD69868E}" = Macros Basic
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7210BCFE-ED8D-4261-8537-81B5A4BDFA2A}" = Rosetta Stone V3
"{75ADD2E4-0EA7-4F52-9A97-7D389F6AB28C}" = Spectrometer Safety Guide
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{863F58EF-467F-4BCC-A40B-D2304630DEA1}" = CambridgeSoft Activation Client
"{870842F7-18BB-479D-A7B1-FE17E81AFF1A}" = Palm Desktop
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B6B6280-44CE-4AE1-AA88-335C3DB68489}" = Nicolet Spectrometer
"{8E325B7E-5F85-4F61-9C89-49DCCA0B6167}" = Preparing Your Site Guide
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{9F769788-E01B-40EC-B745-FE81321582AB}" = OMNIC User Guide
"{A0A20753-92DF-4631-82B4-9CACE2FCED6A}" = Oblivion - The Fighter's Stronghold
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software 6.0.1.3100
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.7
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD36ED92-805E-4A05-8298-B6D71491C5ED}" = Experiment Files
"{BF8B4E28-E576-43D8-A757-F9F6E8995FEE}" = OMNIC Tutorials
"{C3FD43D6-55FD-11D5-81CB-0050DA73CC14}" = OMNIC Internationalization
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE624CC6-DED1-4257-A9ED-77EAC3700E9F}" = OMNIC Utilities
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E4406ED3-B04C-44F1-ABB4-08775B74934F}" = Call Of Cthulhu DCoTE
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{EC425CFC-EE78-4A91-AA25-3BFA65B75364}" = Oblivion - Orrery
"{EF295F5C-7B57-47AA-8889-6B3E8E214E89}" = Oblivion - Mehrunes Razor
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE
"{F20AE04A-3FDC-4A14-A90B-85DEE2812030}" = Sam & Max Season 1
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{F9265BBA-BA3D-4784-A805-FDB24E9966F2}" = Interpretation Guide
"{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}" = Symantec Endpoint Protection
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"{FFFFFD17-B460-41EB-93F1-C48ABAD63828}" = Oblivion - Thieves Den
"201 Games- Trivia Quiz" = 201 Games- Trivia Quiz
"3D Frog Frenzy" = 3D Frog Frenzy
"3D Pinball Express" = 3D Pinball Express
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"Board Games" = Board Games
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Card Games for Windows" = Card Games for Windows
"CDisplay_is1" = CDisplay 1.8
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.64
"ImgBurn" = ImgBurn
"InstallShield_{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}" = Canon Utilities RemoteCapture 2.7
"KaleidaGraph 4.1 Demo" = KaleidaGraph 4.1 Demo
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NVIDIA Drivers" = NVIDIA Drivers
"PeerGuardian_is1" = PeerGuardian 2.0
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Slots 100" = Slots 100
"SystemRequirementsLab" = System Requirements Lab
"TestOut Product Navigator (SA)" = TestOut Navigator (Stand-Alone Version)
"Top 20 Solid Gold" = Top 20 Solid Gold
"Top 30 Games 4 Kids" = Top 30 Games 4 Kids
"Top 50 Blazing Games" = Top 50 Blazing Games
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.2.0
"Unofficial Official Mods Patch_is1" = Unofficial Official Mods Patch v15
"Unofficial Shivering Isles Patch_is1" = Unofficial Shivering Isles Patch v1.4.0
"Val-Q" = Val-Q
"VLC media player" = VLC media player 1.0.2
"WinAce Archiver" = WinAce Archiver
"Xvid_is1" = Xvid 1.2.2 final uninstall
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-3041016070-1017456950-1424249797-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 10/30/2009 3:30:11 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Trojan Horse in File: c:\users\ryan\appdata\local\temp\dwh3013.tmp
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.
Error - 10/30/2009 3:30:12 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH3013.tmp
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: Risk was partially removed.
Error - 10/30/2009 3:30:22 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH537B.tmp
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was left unchanged.
Error - 10/30/2009 3:30:24 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Trojan Horse in File: c:\users\ryan\appdata\local\temp\dwh537b.tmp
by: Auto-Protect scan. Action: Reboot Required. Action Description: The file
was quarantined successfully.
Error - 10/30/2009 3:30:25 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH537B.tmp
by: Auto-Protect scan. Action: Reboot Required. Action Description: Risk was
partially removed.
Error - 10/30/2009 3:31:33 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH537B.tmp
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was left unchanged.
Error - 10/30/2009 3:31:37 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH537B.tmp
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.
Error - 10/30/2009 3:33:06 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH5F6C.tmp
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was left unchanged.
Error - 10/30/2009 3:33:08 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Trojan Horse in File: c:\users\ryan\appdata\local\temp\dwh5f6c.tmp
by: Auto-Protect scan. Action: Reboot Required. Action Description: The file
was quarantined successfully.
Error - 10/30/2009 3:33:09 PM | Computer Name = Ryan | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Trojan Horse in File: C:\Users\Ryan\AppData\Local\Temp\DWH5F6C.tmp
by: Auto-Protect scan. Action: Reboot Required. Action Description: Risk was
partially removed.
[ Broadcom Wireless LAN Events ]
Error - 5/2/2008 7:51:12 PM | Computer Name = Rebecca-PC | Source = WLAN-Tray | ID = 0
Description = 16:51:11, Fri, May 02, 08 Error - Unable to gain access to user store
Error - 5/7/2008 10:37:02 PM | Computer Name = Rebecca-PC | Source = WLAN-Tray | ID = 0
Description = 19:37:02, Wed, May 07, 08 Error - Unable to gain access to user store
Error - 8/13/2008 5:25:18 PM | Computer Name = Rebecca-PC | Source = WLAN-Tray | ID = 0
Description = 14:25:18, Wed, Aug 13, 08 Error - Unable to gain access to user store
Error - 9/25/2008 9:30:35 PM | Computer Name = Rebecca-PC | Source = WLAN-Tray | ID = 0
Description = 18:30:35, Thu, Sep 25, 08 Error - Unable to gain access to user store
Error - 7/16/2009 2:52:38 AM | Computer Name = Ryan | Source = WLAN-Tray | ID = 0
Description = 23:52:38, Wed, Jul 15, 09 Error - Unable to gain access to user store
Error - 7/16/2009 7:10:44 AM | Computer Name = Ryan | Source = WLAN-Tray | ID = 0
Description = 04:10:44, Thu, Jul 16, 09 Error - Unable to gain access to user store
Error - 8/8/2009 10:06:54 AM | Computer Name = Ryan | Source = WLAN-Tray | ID = 0
Description = 07:06:52, Sat, Aug 08, 09 Error - Unable to gain access to user store
Error - 8/26/2009 6:06:54 AM | Computer Name = Ryan | Source = WLAN-Tray | ID = 0
Description = 03:06:54, Wed, Aug 26, 09 Error - Unable to gain access to user store
Error - 8/31/2009 1:38:47 PM | Computer Name = Ryan | Source = WLAN-Tray | ID = 0
Description = 10:38:44, Mon, Aug 31, 09 Error - Unable to gain access to user store
[ OSession Events ]
Error - 9/10/2009 4:46:35 AM | Computer Name = Ryan | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6504.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 12146
seconds with 2280 seconds of active time. This session ended with a crash.
Error - 9/28/2009 12:07:56 AM | Computer Name = Ryan | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6504.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 6418
seconds with 3060 seconds of active time. This session ended with a crash.
Error - 10/19/2009 12:36:45 PM | Computer Name = Ryan | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6504.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 577
seconds with 540 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 10/27/2009 4:02:29 PM | Computer Name = Ryan | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.5 for the Network Card with network
address 001E4C3B621C has been denied by the DHCP server 130.212.10.130 (The DHCP
Server sent a DHCPNACK message).
Error - 10/27/2009 5:13:49 PM | Computer Name = Ryan | Source = Dhcp | ID = 1002
Description = The IP address lease 130.212.177.112 for the Network Card with network
address 001E4C3B621C has been denied by the DHCP server 130.212.10.130 (The DHCP
Server sent a DHCPNACK message).
Error - 10/28/2009 1:21:49 AM | Computer Name = Ryan | Source = BROWSER | ID = 8032
Description =
Error - 10/28/2009 11:02:31 AM | Computer Name = Ryan | Source = BROWSER | ID = 8032
Description =
Error - 10/28/2009 12:15:08 PM | Computer Name = Ryan | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.
Error - 10/28/2009 12:17:08 PM | Computer Name = Ryan | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.
Error - 10/29/2009 1:22:58 AM | Computer Name = Ryan | Source = DCOM | ID = 10010
Description =
Error - 10/29/2009 4:26:56 AM | Computer Name = Ryan | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
will not be used. The driver has been unloaded.
Error - 10/29/2009 1:47:25 PM | Computer Name = Ryan | Source = BROWSER | ID = 8032
Description =
Error - 10/30/2009 12:04:17 PM | Computer Name = Ryan | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.7 for the Network Card with network
address 001E4C3B621C has been denied by the DHCP server 130.212.10.20 (The DHCP
Server sent a DHCPNACK message).
< End of report >