Tom,
When I booted up this time, I was able to get into regular mode (did not have to use safe mode). Not sure if that is a sign of progess or just dumb luck.
Since I have been unable to do so in safe mode, I uninstalled AVG and Spybot so that they would not interfere with these scans. I hope that was OK.
Here are the logs from the recent scans: Combofix, mbam, ESETscan and OTL.
ComboFix 10-06-30.03 - oreganb 07/03/2010 12:00:57.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.592 [GMT -5:00]
Running from: c:\documents and settings\oreganb\Desktop\schrauber.exe
Command switches used :: c:\documents and settings\oreganb\Desktop\CFScript.txt
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-06-03 to 2010-07-03 )))))))))))))))))))))))))))))))
.
2010-07-01 17:42 . 2010-07-01 17:42 -------- d-----w- C:\HelpAsst_backup
2010-06-17 22:32 . 2010-06-17 22:32 284915 ----a-w- c:\program files\gmer.zip
2010-06-17 22:29 . 2010-06-17 22:29 525824 ----a-w- c:\program files\dds.scr
2010-06-17 22:28 . 2010-06-17 22:28 50477 ----a-w- c:\program files\Defogger.exe
2010-06-17 22:04 . 2010-06-17 22:04 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-06-17 21:59 . 2010-06-17 22:02 97364760 ----a-w- c:\program files\Ad-AwareInstaller.exe
2010-06-17 21:34 . 2010-06-17 21:34 -------- d-----w- c:\documents and settings\oreganb\Application Data\AVP 2009
2010-06-17 21:33 . 2010-06-17 21:33 2803352 ----a-w- c:\program files\adware-pro-v04.exe
2010-06-15 22:56 . 2010-06-15 22:56 734728 ----a-w- c:\documents and settings\oreganb\Application Data\Real\RealPlayer\setup\AU_setup14.exe
2010-06-15 22:56 . 2010-06-15 22:56 734728 ----a-w- c:\documents and settings\oreganb\Application Data\Real\RealPlayer\Temp\~Upg0\playinst_aupackage.exe
2010-06-15 20:12 . 2010-03-09 21:47 38784 ----a-w- c:\documents and settings\oreganb\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-12 16:51 . 2010-06-12 16:51 -------- d-----w- c:\windows\system32\MpEngineStore
2010-06-11 04:38 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-03 16:57 . 2009-08-07 20:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-03 16:57 . 2009-08-07 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-03 16:53 . 2008-10-31 12:50 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-06-17 12:08 . 2009-05-18 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-06-17 12:08 . 2009-05-18 17:44 -------- d-----w- c:\program files\Yahoo!
2010-06-17 12:08 . 2008-11-11 21:19 -------- d-----w- c:\program files\DivX
2010-06-12 16:51 . 2004-08-04 10:00 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2010-06-11 08:28 . 2008-11-14 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-06 19:49 . 2009-12-18 22:31 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-12 15:53 . 2009-12-05 21:38 -------- d-----w- c:\program files\Google
2010-05-06 10:41 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 10:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 10:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-19 22:57 . 2010-04-19 22:57 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-04-19 22:57 . 2010-04-19 22:57 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-04-19 22:57 . 2010-04-19 22:57 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-04-19 22:57 . 2010-04-19 22:57 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-04-19 22:57 . 2010-04-19 22:57 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-04-19 22:57 . 2010-04-19 22:57 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-04-19 22:57 . 2010-04-19 22:57 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-04-19 22:57 . 2010-04-19 22:57 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-04-19 22:57 . 2010-04-19 22:57 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-04-19 22:55 . 2003-03-19 02:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-04-19 22:55 . 2003-02-21 10:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-14 12:16 . 2010-03-22 11:58 439816 ----a-w- c:\documents and settings\oreganb\Application Data\Real\Update\setup3.10\setup.exe
2010-04-12 21:46 . 2010-04-12 21:46 55088 ----a-w- c:\program files\MFInstall.exe
2010-03-29 13:12 . 2010-03-29 13:12 84425240 ----a-w- c:\program files\w_turbotax_1040_dlx_2009.12.0100.exe
2010-01-14 17:14 . 2010-01-14 17:14 16409960 ----a-w- c:\program files\spybotsd162.exe
2009-10-26 12:35 . 2009-10-26 12:35 460032 ----a-w- c:\program files\CPimpExp77.exe
2009-10-26 12:25 . 2009-10-26 12:25 6637816 ----a-w- c:\program files\CyberPatrol77.exe
2009-09-22 12:17 . 2009-09-22 12:17 1875071 ----a-w- c:\program files\RAR-Password-Recovery-Magic.exe
2009-08-12 18:41 . 2009-08-12 18:40 848712 ----a-w- c:\program files\avg_free_stb_all_8_32_cnet.exe
2009-04-15 23:29 . 2009-04-15 23:28 111096176 ----a-w- c:\program files\w_turbotax_1040_dlx_2008.14.0003.exe
2009-02-18 19:56 . 2009-02-18 19:56 19405937 ----a-w- c:\program files\Treo755p_1_07_SPNT_desktopupdater.zip
2009-02-17 23:16 . 2009-02-17 23:16 73233320 ----a-w- c:\program files\PalmDesktopWin62.exe
2009-01-20 00:56 . 2009-01-20 00:55 3841337 ----a-w- c:\program files\tvpsetup.exe
2008-11-16 15:50 . 2008-11-16 15:50 67167528 ----a-w- c:\program files\iTunes801Setup.exe
2008-10-30 17:51 . 2008-10-30 17:49 16074512 ----a-w- c:\program files\5600_enu_win2k_xp.exe
2008-10-29 19:36 . 2008-10-29 19:28 35124856 ----a-w- c:\program files\AdbeRdr90_en_US.exe
2009-09-18 12:27 . 2008-10-28 18:15 1004 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-07-01_20.08.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-03 16:54 . 2010-07-03 16:54 16384 c:\windows\temp\Perflib_Perfdata_5f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6CBDD622-ED9D-4D27-ADE4-5D26B7EAE3C1}"= "c:\documents and settings\All Users\Application Data\UploadingCom\Uploading.com Toolbar\tbcore3.dll" [2009-03-12 2614272]
[HKEY_CLASSES_ROOT\clsid\{6cbdd622-ed9d-4d27-ade4-5d26b7eae3c1}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6CBDD622-ED9D-4D27-ADE4-5D26B7EAE3C1}"= "c:\documents and settings\All Users\Application Data\UploadingCom\Uploading.com Toolbar\tbcore3.dll" [2009-03-12 2614272]
[HKEY_CLASSES_ROOT\clsid\{6cbdd622-ed9d-4d27-ade4-5d26b7eae3c1}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00808.TBSB00808]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2005-12-01 77892]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Realtime Monitor"="c:\program files\CA\eTrust\InoculateIT\realmon.exe" [2001-07-20 374584]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2008-06-24 99328]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2006-01-13 188416]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-06-01 1501064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-19 202256]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CyberPatrolNew]
2008-12-19 19:10 1975552 ------w- c:\program files\CyberPatrol LLC\CyberPatrol\CPHQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-10-02 00:57 289576 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-12-05 21:38 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [11/13/2009 6:31 AM 92008]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [6/24/2008 3:12 PM 23552]
S1 mgrslizo;mgrslizo;\??\c:\windows\system32\drivers\mgrslizo.sys --> c:\windows\system32\drivers\mgrslizo.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2010 10:52 AM 136176]
S2 LogWatch;Event Log Watch;c:\windows\LogWatNT.exe [6/7/2000 4:15 PM 50176]
S3 CyberPatrol UpdateService;CyberPatrol UpdateService;c:\program files\CyberPatrol LLC\CyberPatrol\UpdateService.exe [10/26/2009 7:26 AM 144704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 15:51]
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 15:51]
2009-10-19 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\program files\Microsoft IntelliType Pro\itype.exe [2009-06-01 18:43]
2010-07-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
2010-07-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
2010-07-03 c:\windows\Tasks\User_Feed_Synchronization-{B4935876-E585-43E8-9303-E2B5FBB753CF}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://us.mc544.mail.yahoo.com/mc/welcome?.gx=0&.tm=1246396038&.rand=1e3u69c5gico0
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
LSP: c:\windows\system32\cplsp.dll
Trusted Zone: ancestry.com\www
Trusted Zone: intuit.com\ttlc
Trusted Zone: jpclerkofcourt.us\ssl
Trusted Zone: westlaw.com
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue.com/Customer/x86/RescueDownloader.cab
DPF: {73779860-6F88-4D8C-9DAB-30583B9BAAC3} - hxxps://ssl.jpclerkofcourt.us/JeffNetService/ImageServer/iView2/FileProInet2.CAB
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-03 12:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1080)
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(988)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-03 12:14:58
ComboFix-quarantined-files.txt 2010-07-03 17:14
ComboFix2.txt 2010-07-01 20:11
ComboFix3.txt 2010-06-28 15:57
Pre-Run: 42,967,482,368 bytes free
Post-Run: 42,949,410,816 bytes free
- - End Of File - - D75BB4D866766A34E9EBF544D1278221
----------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4271
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/3/2010 12:29:35 PM
mbam-log-2010-07-03 (12-29-35).txt
Scan type: Quick scan
Objects scanned: 132111
Time elapsed: 7 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\adware-pro-v04.exe (Rogue.AdwarePro) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\AdwarePro.lnk (Rogue.AdwarePro) -> Quarantined and deleted successfully.
----------------------------------------------------------------------------------------------
C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Local Settings\Temp\1A.tmp a variant of Win32/Mebroot.DZ trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files\Adware Pro\EngineAP.dll.vir a variant of Win32/Adware.AntiMalwarePro.AA application cleaned by deleting - quarantined
C:\System Volume Information\_restore{80128F55-C654-44D9-A5BD-F3F34E858B9C}\RP524\A0100669.dll a variant of Win32/Adware.AntiMalwarePro.AA application cleaned by deleting - quarantined
----------------------------------------------------------------------------------------------
OTL logfile created on: 7/3/2010 2:35:38 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\oreganb\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 434.00 Mb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 40.73 Gb Free Space | 54.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 362.85 Gb Total Space | 128.59 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Computer Name: BILLY
Current User Name: oreganb
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/07/03 14:34:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\oreganb\Desktop\OTL.exe
PRC - [2010/04/19 17:55:44 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/02/24 22:09:42 | 000,173,576 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealUpgrade\realupgrade.exe
PRC - [2009/11/13 06:31:14 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/09/29 09:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/06/01 13:43:46 | 001,501,064 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\itype.exe
PRC - [2008/12/19 14:10:40 | 001,045,760 | ---- | M] (CyberPatrol LLC.) -- C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
PRC - [2008/12/09 05:12:30 | 000,234,856 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\HOMERunner.exe
PRC - [2008/06/24 15:12:09 | 000,099,328 | ---- | M] () -- C:\Program Files\OpenVPN\bin\openvpn-gui.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/02/21 12:28:36 | 000,643,072 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2007/02/21 12:19:58 | 000,819,200 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2007/02/21 12:19:40 | 000,294,912 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2007/02/21 12:17:42 | 000,970,752 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2007/02/21 12:16:48 | 000,983,040 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2007/02/21 12:13:26 | 000,487,424 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2007/02/21 12:10:00 | 000,327,680 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2006/01/13 02:14:58 | 000,188,416 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2005/10/07 15:13:38 | 000,176,128 | R--- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2005/08/11 17:30:30 | 000,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/07/27 17:41:08 | 000,045,056 | R--- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2004/06/29 00:56:12 | 000,045,056 | R--- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\hidfind.exe
PRC - [2003/06/25 11:24:48 | 000,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
PRC - [2001/07/19 20:21:20 | 000,374,584 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\eTrust\InoculateIT\Realmon.exe
PRC - [2001/07/19 20:20:30 | 000,218,936 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
PRC - [2001/07/19 20:20:16 | 000,186,168 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
PRC - [2001/07/19 20:20:14 | 000,137,016 | ---- | M] (Computer Associates International, Inc.) -- C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
PRC - [2000/06/07 16:15:24 | 000,050,176 | ---- | M] () -- C:\WINDOWS\LogWatNT.exe
========== Modules (SafeList) ========== MOD - [2010/07/03 14:34:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\oreganb\Desktop\OTL.exe
MOD - [2008/04/14 06:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (YahooAUService)
SRV - File not found [Auto | Stopped] -- -- (hpdj)
SRV - [2009/12/17 17:36:24 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2009/11/13 06:31:14 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/09/29 09:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2008/07/31 14:50:50 | 000,144,704 | ---- | M] (CyberPatrol LLC) [On_Demand | Stopped] -- C:\Program Files\CyberPatrol LLC\CyberPatrol\UpdateService.exe -- (CyberPatrol UpdateService)
SRV - [2008/06/24 15:12:09 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2007/02/21 12:28:36 | 000,643,072 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2007/02/21 12:19:40 | 000,294,912 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®
SRV - [2007/02/21 12:16:48 | 000,983,040 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2007/02/21 12:10:00 | 000,327,680 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2001/07/19 20:20:30 | 000,218,936 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe -- (InoTask)
SRV - [2001/07/19 20:20:16 | 000,186,168 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\eTrust\InoculateIT\InoRT.exe -- (InoRT)
SRV - [2001/07/19 20:20:14 | 000,137,016 | ---- | M] (Computer Associates International, Inc.) [Auto | Running] -- C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe -- (InoRPC)
SRV - [2000/06/07 16:15:24 | 000,050,176 | ---- | M] () [Auto | Running] -- C:\WINDOWS\LogWatNT.exe -- (LogWatch)
========== Driver Services (SafeList) ========== DRV - [2010/06/12 11:51:15 | 000,052,480 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\i8042prt.sys -- (i8042prt)
DRV - [2009/12/14 17:00:44 | 000,016,694 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2009/05/09 01:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2008/06/24 15:12:09 | 000,023,552 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0801.sys -- (tap0801)
DRV - [2007/02/21 12:16:12 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007/02/08 14:51:16 | 002,209,408 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2005/09/28 21:57:18 | 000,113,847 | R--- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2005/03/10 17:56:06 | 000,273,168 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2004/05/26 16:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2001/06/15 19:01:36 | 000,105,312 | ---- | M] (Computer Associates International, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\ino_fltr.sys -- (INO_FLTR)
DRV - [2001/05/18 14:36:28 | 000,020,688 | ---- | M] (Computer Associates International, Inc.) [File_System | Boot | Running] -- C:\WINDOWS\system32\Drivers\ino_flpy.sys -- (INO_FLPY)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://us.mc544.mail.yahoo.com/mc/welcome?...d=1e3u69c5gico0IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/19 17:57:32 | 000,000,000 | ---D | M]
[2009/09/23 15:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\Mozilla\Extensions
[2009/03/17 08:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\Mozilla\Extensions\home2@tomtom.com
[2009/09/23 15:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\Mozilla\Extensions\mozswing@mozswing.org
O1 HOSTS File: ([2010/06/28 10:44:16 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No CLSID value found.
O2 - BHO: (TBSB00808 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Documents and Settings\All Users\Application Data\UploadingCom\Uploading.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Uploading.com Toolbar) - {6CBDD622-ED9D-4D27-ADE4-5D26B7EAE3C1} - C:\Documents and Settings\All Users\Application Data\UploadingCom\Uploading.com Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Uploading.com Toolbar) - {6CBDD622-ED9D-4D27-ADE4-5D26B7EAE3C1} - C:\Documents and Settings\All Users\Application Data\UploadingCom\Uploading.com Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [itype] c:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe ()
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [Realtime Monitor] C:\Program Files\CA\eTrust\InoculateIT\realmon.exe (Computer Associates International, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\HOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\WINDOWS\System32\cplsp.dll (CyberPatrol LLC.)
O15 - HKCU\..Trusted Domains: ancestry.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: jpclerkofcourt.us ([ssl] https in Trusted sites)
O15 - HKCU\..Trusted Domains: westlaw.com ([]https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623}
http://www.alternatiff.com/install-ie/alttiff.cab (AlternaTIFF ActiveX)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/0/A...01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D}
https://secure.logmeinrescue.com/Customer/x...eDownloader.cab (LogMeIn Rescue Applet Downloader)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC}
https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73779860-6F88-4D8C-9DAB-30583B9BAAC3}
https://ssl.jpclerkofcourt.us/JeffNetServic...ileProInet2.CAB (FileProInet2.ImageView)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.22.3.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = lawfirm.local
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/28 13:13:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/10/28 13:12:40 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55182706186649600)
========== Files/Folders - Created Within 90 Days ========== [2010/07/03 14:34:30 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\oreganb\Desktop\OTL.exe
[2010/07/03 12:37:21 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/07/03 12:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\Malwarebytes
[2010/07/03 12:20:28 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/03 12:20:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/03 12:20:26 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/03 12:20:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/03 12:19:17 | 006,153,376 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\oreganb\Desktop\mbam-setup-1.46.exe
[2010/07/01 15:11:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/07/01 12:42:13 | 000,000,000 | ---D | C] -- C:\HelpAsst_backup
[2010/06/28 10:18:51 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/06/28 10:10:58 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/06/28 10:10:58 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/06/28 10:10:58 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/06/28 10:10:58 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/06/28 10:10:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/06/28 09:54:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/06/17 17:04:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/17 16:59:53 | 097,364,760 | ---- | C] (Lavasoft ) -- C:\Program Files\Ad-AwareInstaller.exe
[2010/06/17 16:34:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\AVP 2009
[2010/06/17 07:08:02 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\oreganb\Recent
[2010/06/16 15:36:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010/06/12 11:51:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2010/05/26 15:46:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\My Documents\De La Salle
[2010/05/26 15:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\My Documents\Health
[2010/05/26 15:00:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\My Documents\TEC
[2010/05/25 15:09:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/05/17 10:15:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\My Documents\Geneaology
[2010/05/12 10:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/05/12 10:52:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Local Settings\Application Data\Temp
[2010/05/12 10:52:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/28 08:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/04/27 12:49:20 | 000,000,000 | ---D | C] -- C:\Program Files\TomTom International B.V
[2010/04/24 16:20:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\W Photo Studio
[2010/04/24 16:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Walgreens
[2010/04/24 16:19:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\Walgreens
[2010/04/24 16:19:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2010/04/24 16:19:35 | 000,000,000 | ---D | C] -- C:\Program Files\Walgreens
[2010/04/24 16:16:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\W Photo Studio Viewer
[2010/04/19 17:56:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2010/04/19 17:55:47 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2010/04/13 08:59:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/04/13 08:58:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oreganb\Application Data\Office Genuine Advantage
[2010/04/12 16:39:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-TW
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-HK
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\tr-TR
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-SE
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nl-NL
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\nb-NO
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ko-KR
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\it-IT
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\he-IL
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fr-FR
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\fi-FI
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\es-ES
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\el-GR
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\da-DK
[2010/04/12 16:29:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ar-SA
[2010/04/12 09:51:32 | 000,189,976 | ---- | C] (MyFamily.com, Inc.) -- C:\WINDOWS\System32\mfimgvwr.ocx
[2010/04/12 09:51:17 | 000,000,000 | ---D | C] -- C:\Program Files\MFInstall
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\oreganb\My Documents\*.tmp files -> C:\Documents and Settings\oreganb\My Documents\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/07/03 14:35:39 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
[2010/07/03 14:35:38 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
[2010/07/03 14:34:33 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\oreganb\Desktop\OTL.exe
[2010/07/03 14:03:06 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/03 12:31:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/03 12:31:44 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/03 12:31:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/03 12:31:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/03 12:30:34 | 013,631,488 | ---- | M] () -- C:\Documents and Settings\oreganb\NTUSER.DAT
[2010/07/03 12:30:34 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\oreganb\ntuser.ini
[2010/07/03 12:30:27 | 003,778,094 | -H-- | M] () -- C:\Documents and Settings\oreganb\Local Settings\Application Data\IconCache.db
[2010/07/03 12:20:31 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/03 12:19:35 | 006,153,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\oreganb\Desktop\mbam-setup-1.46.exe
[2010/07/03 12:11:38 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/07/03 11:45:11 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B4935876-E585-43E8-9303-E2B5FBB753CF}.job
[2010/07/01 14:56:15 | 003,725,156 | R--- | M] () -- C:\Documents and Settings\oreganb\Desktop\schrauber.exe
[2010/07/01 12:42:09 | 000,490,232 | ---- | M] () -- C:\Documents and Settings\oreganb\Desktop\HelpAsst_mebroot_fix.exe
[2010/07/01 12:37:10 | 000,147,244 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Passwords.pdf
[2010/06/28 10:44:16 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/28 10:18:57 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/06/17 17:32:22 | 000,284,915 | ---- | M] () -- C:\Program Files\gmer.zip
[2010/06/17 17:29:16 | 000,525,824 | ---- | M] () -- C:\Program Files\dds.scr
[2010/06/17 17:28:34 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\oreganb\defogger_reenable
[2010/06/17 17:28:07 | 000,050,477 | ---- | M] () -- C:\Program Files\Defogger.exe
[2010/06/17 17:02:25 | 097,364,760 | ---- | M] (Lavasoft ) -- C:\Program Files\Ad-AwareInstaller.exe
[2010/06/16 15:39:29 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/16 15:39:29 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/06/15 18:05:40 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2008.lnk
[2010/06/15 11:17:12 | 000,331,380 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\RosterLicensees.zip
[2010/06/15 11:14:50 | 000,075,072 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\RosterCorps.zip
[2010/06/14 14:19:23 | 000,006,729 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\SANDESTIN 2010Saturday.wpd
[2010/06/14 13:11:00 | 000,002,429 | ---- | M] () -- C:\Documents and Settings\oreganb\Desktop\WordPerfect X3.lnk
[2010/06/14 08:22:38 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\oreganb\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/06/12 17:03:52 | 000,013,469 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Passwords.docx
[2010/06/12 11:51:15 | 000,052,480 | ---- | M] () -- C:\WINDOWS\System32\drivers\i8042prt.sys
[2010/06/11 03:48:16 | 000,321,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 03:21:38 | 000,000,224 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2010/06/11 03:12:07 | 000,494,710 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/11 03:12:07 | 000,436,438 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/11 03:12:07 | 000,069,168 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/09 10:37:35 | 000,062,641 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\SGO FLorida License.pdf
[2010/06/09 10:36:16 | 000,028,429 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Plaint atty possible depo dates for pl 6-9-10.doc
[2010/06/09 10:33:29 | 000,039,091 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\20100609095054080.pdf
[2010/06/09 10:29:50 | 000,062,656 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\WDO FLorida License.pdf
[2010/06/08 22:25:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/08 15:19:19 | 000,013,074 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\PETITION FOR RETURN OF MOV PROP.wpd
[2010/06/08 15:17:53 | 000,011,933 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Billy Winters ltr re set up meeting 6-7-10.wpd
[2010/06/08 15:06:55 | 000,005,692 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Aisola ltr re disc issues & settl offer 6-7-10.wpd
[2010/06/08 15:06:40 | 000,008,711 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Client Miller update 6-7-10.wpd
[2010/06/08 15:05:05 | 000,012,080 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Billy Winters ltr re set up meeting 6-8-10.wpd
[2010/06/08 14:23:20 | 000,011,282 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Katz re mediation and suppl report 6-8-10.wpd
[2010/06/08 14:18:17 | 000,011,575 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Katz re mediation and suppl report 6-7-10.wpd
[2010/06/08 13:57:05 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\oreganb\Desktop\Microsoft Office Outlook 2003.lnk
[2010/06/02 10:48:34 | 000,392,608 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\95915151482003_hl000061.sid
[2010/05/31 09:50:05 | 000,012,820 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Rent Reimbursments.xlsx
[2010/05/28 16:39:47 | 000,002,245 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Toll Tag Info.wpd
[2010/05/25 16:53:00 | 000,180,736 | ---- | M] () -- C:\Documents and Settings\oreganb\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/21 09:08:18 | 003,933,666 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\io-ebook.pdf
[2010/05/07 17:08:56 | 000,021,696 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Confirmation Talk.docx
[2010/05/07 14:38:36 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Confirmation%20Retreat[1].doc
[2010/05/03 09:37:21 | 000,333,322 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\ABBY.jpg
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/27 13:25:53 | 000,185,907 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Ospitalità San Gregorio.pdf
[2010/04/27 13:25:44 | 000,011,468 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Translation - S. Gregorio.pdf
[2010/04/26 18:48:35 | 001,329,880 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Rome.pdf
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010/04/25 23:35:28 | 000,002,761 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\EXTRAORDINARY FUNDS.wpd
[2010/04/19 17:57:33 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2010/04/19 17:55:50 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010/04/19 17:17:13 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Media Player.lnk
[2010/04/19 15:01:00 | 000,014,168 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\April 2010 Family Budget.docx
[2010/04/19 14:59:18 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/14 13:55:30 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/04/12 16:46:39 | 000,055,088 | ---- | M] () -- C:\Program Files\MFInstall.exe
[2010/04/06 10:56:04 | 000,014,632 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Genealogy email.docx
[2010/04/06 10:50:55 | 000,047,355 | ---- | M] () -- C:\Documents and Settings\oreganb\My Documents\Genealogy email.pdf
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\oreganb\My Documents\*.tmp files -> C:\Documents and Settings\oreganb\My Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/07/03 12:20:31 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/01 12:40:14 | 000,490,232 | ---- | C] () -- C:\Documents and Settings\oreganb\Desktop\HelpAsst_mebroot_fix.exe
[2010/07/01 12:37:10 | 000,147,244 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Passwords.pdf
[2010/06/28 10:18:57 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/06/28 10:18:54 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/06/28 10:10:58 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/06/28 10:10:58 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/06/28 10:10:58 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/06/28 10:10:58 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/28 10:10:58 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/28 09:53:58 | 003,725,156 | R--- | C] () -- C:\Documents and Settings\oreganb\Desktop\schrauber.exe
[2010/06/17 17:32:21 | 000,284,915 | ---- | C] () -- C:\Program Files\gmer.zip
[2010/06/17 17:29:12 | 000,525,824 | ---- | C] () -- C:\Program Files\dds.scr
[2010/06/17 17:28:34 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\oreganb\defogger_reenable
[2010/06/17 17:28:04 | 000,050,477 | ---- | C] () -- C:\Program Files\Defogger.exe
[2010/06/15 11:17:11 | 000,331,380 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\RosterLicensees.zip
[2010/06/15 11:14:49 | 000,075,072 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\RosterCorps.zip
[2010/06/14 13:23:21 | 000,006,729 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\SANDESTIN 2010Saturday.wpd
[2010/06/11 03:21:38 | 000,000,224 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/06/09 10:37:34 | 000,062,641 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\SGO FLorida License.pdf
[2010/06/09 10:36:13 | 000,028,429 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Plaint atty possible depo dates for pl 6-9-10.doc
[2010/06/09 10:33:27 | 000,039,091 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\20100609095054080.pdf
[2010/06/09 10:29:48 | 000,062,656 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\WDO FLorida License.pdf
[2010/06/08 16:33:50 | 000,000,282 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
[2010/06/08 15:19:18 | 000,013,074 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\PETITION FOR RETURN OF MOV PROP.wpd
[2010/06/08 15:06:54 | 000,005,692 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Aisola ltr re disc issues & settl offer 6-7-10.wpd
[2010/06/08 15:06:38 | 000,008,711 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Client Miller update 6-7-10.wpd
[2010/06/08 15:05:05 | 000,012,080 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Billy Winters ltr re set up meeting 6-8-10.wpd
[2010/06/08 15:03:07 | 000,011,933 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Billy Winters ltr re set up meeting 6-7-10.wpd
[2010/06/08 14:23:20 | 000,011,282 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Katz re mediation and suppl report 6-8-10.wpd
[2010/06/08 14:18:13 | 000,011,575 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Pl Atty Katz re mediation and suppl report 6-7-10.wpd
[2010/06/02 10:48:33 | 000,392,608 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\95915151482003_hl000061.sid
[2010/05/28 16:39:19 | 000,002,245 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Toll Tag Info.wpd
[2010/05/21 09:08:18 | 003,933,666 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\io-ebook.pdf
[2010/05/12 10:52:15 | 000,000,888 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/12 10:52:14 | 000,000,884 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/07 14:38:36 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Confirmation%20Retreat[1].doc
[2010/05/07 14:34:03 | 000,021,696 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Confirmation Talk.docx
[2010/05/03 09:38:39 | 000,333,322 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\ABBY.jpg
[2010/04/27 13:25:53 | 000,185,907 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Ospitalità San Gregorio.pdf
[2010/04/27 13:25:42 | 000,011,468 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Translation - S. Gregorio.pdf
[2010/04/26 18:48:35 | 001,329,880 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Rome.pdf
[2010/04/25 23:35:28 | 000,002,761 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\EXTRAORDINARY FUNDS.wpd
[2010/04/19 17:57:42 | 000,000,290 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3468976516-4285789688-3672828899-1218.job
[2010/04/19 17:57:33 | 000,000,929 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk
[2010/04/19 17:17:13 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Media Player.lnk
[2010/04/19 15:00:59 | 000,014,168 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\April 2010 Family Budget.docx
[2010/04/12 16:46:39 | 000,055,088 | ---- | C] () -- C:\Program Files\MFInstall.exe
[2010/04/12 16:39:42 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/06 10:50:54 | 000,047,355 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Genealogy email.pdf
[2010/04/06 10:14:54 | 000,014,632 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Genealogy email.docx
[2010/04/05 14:54:42 | 000,012,820 | ---- | C] () -- C:\Documents and Settings\oreganb\My Documents\Rent Reimbursments.xlsx
[2009/12/14 16:54:51 | 000,000,094 | ---- | C] () -- C:\WINDOWS\family.ini
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/04/19 09:57:17 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2009/01/07 21:37:14 | 000,000,037 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2009/01/02 00:47:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/11/14 09:57:47 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2008/10/30 12:37:29 | 000,011,738 | ---- | C] () -- C:\WINDOWS\hpdj5600.ini
[2008/10/28 15:20:10 | 000,000,075 | ---- | C] () -- C:\WINDOWS\ricdb.ini
[2008/10/28 15:20:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\RPCS.ini
[2008/10/28 13:47:53 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2008/10/28 13:45:46 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/10/28 13:15:54 | 000,001,004 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2004/08/04 05:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 05:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 05:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 05:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 05:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 05:00:00 | 000,052,480 | ---- | C] () -- C:\WINDOWS\System32\drivers\i8042prt.sys
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ========== [2009/05/22 15:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avery
[2008/10/28 13:13:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Borland
[2009/10/26 07:26:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberPatrol
[2009/12/14 17:04:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2010/03/29 19:07:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RootsMagic
[2009/03/17 08:59:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2009/04/22 15:06:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UploadingCom
[2010/04/24 16:19:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Walgreens
[2008/12/18 14:44:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2008/11/16 10:10:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2010/06/17 17:04:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/17 16:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\AVP 2009
[2008/12/01 18:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/12/03 10:26:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\CyberPatrol Client
[2009/12/14 16:54:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\HotSync
[2009/09/24 13:59:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\LimeWire
[2010/03/29 19:07:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\RootsMagic
[2009/03/17 08:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\TomTom
[2010/04/24 16:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\W Photo Studio
[2010/04/24 16:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\W Photo Studio Viewer
[2010/04/24 16:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oreganb\Application Data\Walgreens
[2010/07/03 11:45:11 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B4935876-E585-43E8-9303-E2B5FBB753CF}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 06:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 05:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >[2007/07/12 16:35:02 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\WINDOWS\dell\iastor\iastor.sys
< MD5 for: NETLOGON.DLL >[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 06:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATA.SYS >[2006/10/18 17:31:38 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A -- C:\WINDOWS\dell\nvraid\nvata.sys
< MD5 for: NVATABUS.SYS >[2006/10/18 16:31:38 | 000,105,472 | ---- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A -- C:\WINDOWS\dell\nvraid\NvAtaBus.sys
< MD5 for: SCECLI.DLL >[2004/08/04 05:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SYMMPI.SYS >[2007/02/09 22:06:00 | 000,100,096 | ---- | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E -- C:\WINDOWS\dell\symmpi\symmpi.sys
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2008/10/28 06:59:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008/10/28 06:59:58 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008/10/28 06:59:58 | 000,892,928 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemdrive%\*.sys /90 /md5 >[2010/07/03 12:31:18 | 1598,029,824 | -HS- | M] ()
Unable to obtain MD5 -- C:\pagefile.sys
< End of report >
----------------------------------------------------------------------------------------------
OTL Extras logfile created on: 7/3/2010 2:35:38 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\oreganb\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 434.00 Mb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 40.73 Gb Free Space | 54.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 362.85 Gb Total Space | 128.59 Gb Free Space | 35.44% Space Free | Partition Type: NTFS
Computer Name: BILLY
Current User Name: oreganb
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"80:TCP" = 80:TCP:*:Enabled:Services
"443:TCP" = 443:TCP:*:Enabled:Services
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"7161:TCP" = 7161:TCP:*:Enabled:Services
"7160:TCP" = 7160:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"65533:TCP" = 65533:TCP:*:Enabled:Services
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- File not found
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\WINDOWS\LMI5B.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI5B.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\Documents and Settings\oreganb\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\oreganb\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player -- File not found
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)
"C:\Program Files\RootsMagic 4\RootsMagic.exe" = C:\Program Files\RootsMagic 4\RootsMagic.exe:*:Enabled:RootsMagic Genealogy Software -- (RootsMagic, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{049D96D7-E082-4FB5-BF64-CD3460E6877C}_is1" = RootsMagic 4.0.8.0
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0DE6646A-AFD0-44AC-A493-5A8A7ABB858F}" = CyberPatrol (Remove Only)
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 11
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{392D84D0-EAA2-012B-ADD8-000000000000}" = TurboTax 2009 wlaiper
"{3BEF9769-BA52-18F7-1D02-2362F6A27E38}" = Adobe Media Player
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{52242A19-B603-4A86-9101-8B6E0442C16C}" = Palm
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5D50644B-310A-4C1B-B2DD-B8E781ADC430}" = WordPerfect Mail
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8D7574B1-49D7-41E6-9C2E-6B49A8619E64}" = BCL easyPDF Printer Driver 5.1
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{90E00409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Outlook 2003
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CBF3C503-946E-45EA-B347-EACC41781989}" = W Photo Studio
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB5518BE-F40F-407A-B451-012625D4497B}" = hp deskjet 5600
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FB36174F-6AA4-4532-B011-F86FD597D471}" = TurboTax 2008 wlaiper
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Adobe AIR" = Adobe AIR
"CCleaner" = CCleaner (remove only)
"CDisplay_is1" = CDisplay 1.8
"com.adobe.amp.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CutePDF Writer Installation" = CutePDF Writer 2.7
"ESET Online Scanner" = ESET Online Scanner v3
"eTrust InoculateIT" = eTrust InoculateIT
"ffdshow" = ffdshow (remove only)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenVPN" = OpenVPN 2.0.5-gui-1.0.3
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 12.0" = RealPlayer
"TomTom HOME" = TomTom HOME 2.7.3.1894
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Uploading.com Toolbars" = Uploading.com Toolbars
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 6/17/2010 7:52:26 AM | Computer Name = BILLY | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 6/17/2010 7:54:28 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 7:55:27 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 8:09:15 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 8:09:16 AM | Computer Name = BILLY | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 6/17/2010 5:38:10 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 5:42:44 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 5:44:19 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 6:08:39 PM | Computer Name = BILLY | Source = MsiInstaller | ID = 1008
Description = The installation of c:\42a3799161d02db7e4ca5e\vc_red.msi is not permitted
due to an error in software restriction policy processing. The object cannot be
trusted.
Error - 6/28/2010 11:20:21 AM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
[ Application Events ]
Error - 6/17/2010 7:52:26 AM | Computer Name = BILLY | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 6/17/2010 7:54:28 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 7:55:27 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 8:09:15 AM | Computer Name = BILLY | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 6/17/2010 8:09:16 AM | Computer Name = BILLY | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 6/17/2010 5:38:10 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 5:42:44 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 5:44:19 PM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application adware_pro.exe, version 1.0.0.1, faulting module
engineap.dll, version 0.0.0.0, fault address 0x00070210.
Error - 6/17/2010 6:08:39 PM | Computer Name = BILLY | Source = MsiInstaller | ID = 1008
Description = The installation of c:\42a3799161d02db7e4ca5e\vc_red.msi is not permitted
due to an error in software restriction policy processing. The object cannot be
trusted.
Error - 6/28/2010 11:20:21 AM | Computer Name = BILLY | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
[ System Events ]
Error - 7/3/2010 12:41:33 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The hpdj service failed to start due to the following error: %%2
Error - 7/3/2010 12:41:33 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The Yahoo! Updater service failed to start due to the following error:
%%3
Error - 7/3/2010 12:56:06 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7023
Description = The Client Service for NetWare service terminated with the following
error: %%2
Error - 7/3/2010 12:56:06 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The hpdj service failed to start due to the following error: %%2
Error - 7/3/2010 12:56:06 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The Yahoo! Updater service failed to start due to the following error:
%%3
Error - 7/3/2010 1:00:39 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7034
Description = The Event Log Watch service terminated unexpectedly. It has done
this 1 time(s).
Error - 7/3/2010 1:32:53 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7023
Description = The Client Service for NetWare service terminated with the following
error: %%2
Error - 7/3/2010 1:32:53 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The hpdj service failed to start due to the following error: %%2
Error - 7/3/2010 1:32:53 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7000
Description = The Yahoo! Updater service failed to start due to the following error:
%%3
Error - 7/3/2010 1:32:53 PM | Computer Name = BILLY | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde
< End of report >