1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved System Security Center will not start

Discussion in 'Malware and Virus Removal Archive' started by larsonjean, 2014/03/05.

  1. 2014/03/07
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Yes I was able to start the Security Center Again and Microsoft Security Essentials is running.

    I ran the quick scan in OTL and here are the results:

    OTL.TXT:
    OTL logfile created on: 3/7/2014 8:59:18 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jean\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 60.31% Memory free
    6.19 Gb Paging File | 5.17 Gb Available in Paging File | 83.42% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 455.59 Gb Total Space | 323.07 Gb Free Space | 70.91% Space Free | Partition Type: NTFS
    Drive D: | 10.17 Gb Total Space | 4.76 Gb Free Space | 46.80% Space Free | Partition Type: NTFS

    Computer Name: JEAN-PC | User Name: Jean | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2014/03/07 20:57:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jean\Desktop\OTL.exe
    PRC - [2014/02/24 15:14:34 | 000,841,096 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe
    PRC - [2014/01/02 19:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jean\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2013/11/18 05:09:34 | 000,757,024 | ---- | M] (Glarysoft Ltd) -- C:\Program Files\Glarysoft\Glary Utilities 4\Integrator.exe
    PRC - [2013/10/31 13:47:38 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
    PRC - [2013/10/23 15:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
    PRC - [2013/10/23 14:55:28 | 000,948,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
    PRC - [2010/02/10 08:19:09 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files\Common Files\aol\1334930562\ee\aolsoftware.exe
    PRC - [2009/06/11 09:17:38 | 003,618,104 | ---- | M] (brother) -- C:\Program Files\Brownie\BrStsWnd.exe
    PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/07/06 13:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\WINDOWS\RtHDVCpl.exe


    ========== Modules (No Company Name) ==========

    MOD - [2014/01/02 19:45:04 | 003,558,400 | ---- | M] () -- C:\Users\Jean\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
    MOD - [2013/11/18 04:54:06 | 000,080,160 | ---- | M] () -- C:\Program Files\Glarysoft\Glary Utilities 4\zlib1.dll
    MOD - [2013/10/18 18:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Jean\AppData\Roaming\Dropbox\bin\libcef.dll
    MOD - [2013/09/14 01:51:02 | 000,087,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Internet Services\zlib1.dll
    MOD - [2013/09/14 01:50:36 | 001,242,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Internet Services\libxml2.dll


    ========== Services (SafeList) ==========

    SRV - [2014/02/24 15:14:34 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2013/12/21 01:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2013/12/05 14:36:33 | 000,119,408 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2013/10/23 15:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV - [2013/10/23 15:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV - [2013/10/01 07:14:40 | 005,087,584 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
    SRV - [2013/02/25 23:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
    SRV - [2013/01/18 07:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2011/04/01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [Disabled | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
    SRV - [2011/03/28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
    SRV - [2010/02/24 16:42:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
    SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2006/10/23 07:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Disabled | Stopped] -- C:\Program Files\Common Files\aol\acs\AOLacsd.exe -- (AOL ACS)


    ========== Driver Services (SafeList) ==========

    DRV - [2013/09/27 09:53:06 | 000,104,768 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV - [2013/07/25 15:53:46 | 000,018,944 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\netaapl.sys -- (Netaapl)
    DRV - [2013/02/25 23:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
    DRV - [2012/03/21 19:48:18 | 000,047,264 | ---- | M] (Tether) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\qrkis.sys -- (qrkis)
    DRV - [2011/09/16 14:10:50 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
    DRV - [2009/12/30 10:21:18 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\revoflt.sys -- (Revoflt)
    DRV - [2009/04/11 00:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\WSDScan.sys -- (WSDScan)
    DRV - [2009/03/18 15:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\hamachi.sys -- (hamachi)
    DRV - [2008/05/06 15:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\wdcsam.sys -- (WDC_SAM)
    DRV - [2008/01/20 21:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
    DRV - [2007/09/18 01:17:36 | 000,098,816 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Rtlh86.sys -- (RTL8169)
    DRV - [2007/08/09 18:12:32 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nvrd32.sys -- (nvrd32)
    DRV - [2007/08/09 18:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nvstor32.sys -- (nvstor32)
    DRV - [2006/11/29 17:24:57 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\wanatw4.sys -- (wanatw)
    DRV - [2006/11/02 02:30:56 | 002,589,184 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NETw2v32.sys -- (NETw2v32)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\..\SearchScopes\{c1d89ae7-449d-4929-b24b-fded04adbe06}: "URL" = http://isearch.glarysoft.com/?q={searchTerms}&src=iesearch


    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_page_URL = http://www.gateway.com/g/startpage.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=FX541S
    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=FX541S
    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_page_URL = http://www.gateway.com/g/startpage.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=FX541S
    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Consumer&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=FX541S
    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..\SearchScopes,DefaultScope = {F1C49C3C-4BAF-4026-AA60-2E13CC387749}
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?FORM=UP21DF&PC=UP21&dt=053013&q={searchTerms}&src=IE-SearchBox
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..\SearchScopes\{c1d89ae7-449d-4929-b24b-fded04adbe06}: "URL" = http://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..\SearchScopes\{F1C49C3C-4BAF-4026-AA60-2E13CC387749}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GWYF_enUS471
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..\SearchScopes\8DBA89FFD777403E8B5679C8B8ED3041: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-528091951-17181806-3350549182-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..extensions.enabledAddons: %7B0113D088-8ED1-468C-B225-585A9C53B5E3%7D:1.0
    FF - prefs.js..extensions.enabledAddons: %7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:9.5.3
    FF - prefs.js..extensions.enabledAddons: %7B7093ee04-f2e4-4637-a667-0f730797b3a0%7D:10.20.1.508
    FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jean\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jean\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/01/25 16:27:20 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/10/12 11:46:14 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2013/03/17 19:45:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jean\AppData\Roaming\Mozilla\Extensions
    [2014/03/06 20:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\02xdd2fr.default-1373117438142\extensions
    [2013/12/19 21:26:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
    [2013/12/19 21:26:07 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    File not found (No name found) -- C:\USERS\JEAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\02XDD2FR.DEFAULT-1373117438142\EXTENSIONS\{0113D088-8ED1-468C-B225-585A9C53B5E3}
    File not found (No name found) -- C:\USERS\JEAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\02XDD2FR.DEFAULT-1373117438142\EXTENSIONS\{7093EE04-F2E4-4637-A667-0F730797B3A0}
    File not found (No name found) -- C:\USERS\JEAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\02XDD2FR.DEFAULT-1373117438142\EXTENSIONS\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8}

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:eek:riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:eek:mniboxStartMarginParameter}ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
    CHR - homepage: http://www.google.com/
    CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - Extension: Google Drive = C:\Users\Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
    CHR - Extension: YouTube = C:\Users\Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
    CHR - Extension: Google Search = C:\Users\Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
    CHR - Extension: Google Wallet = C:\Users\Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
    CHR - Extension: Gmail = C:\Users\Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

    O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\System32\BAE.dll (Gateway Inc.)
    O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [Brdefprn] C:\Program Files\Brother\BRHL2140\Brdefprn.exe ()
    O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
    O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1334930562\ee\aolsoftware.exe (AOL Inc.)
    O4 - HKLM..\Run: [MapsGalaxy EPM Support] "C:\PROGRA~1\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S File not found
    O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
    O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
    O4 - HKU\S-1-5-21-528091951-17181806-3350549182-1000..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
    O4 - HKU\S-1-5-21-528091951-17181806-3350549182-1000..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
    O4 - HKU\S-1-5-21-528091951-17181806-3350549182-1000..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
    O4 - HKU\S-1-5-21-528091951-17181806-3350549182-1000..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE (Dale Nurden)
    O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
    O4 - Startup: C:\Users\Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jean\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O15 - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0271D2AC-1FFD-4C96-A066-B06379D17507}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{575FEBB4-1BC0-4E1A-ABFD-91934B099DA3}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8B21746E-DFB3-49C0-989C-BE3769660D3B}: DhcpNameServer = 172.20.10.1
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O34 - HKLM BootExecute: (刭癁몊권��П瘽→瓈˪Ĩ)
    O34 - HKLM BootExecute: ()
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    ========== Files/Folders - Created Within 30 Days ==========

    [2014/03/07 20:57:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Jean\Desktop\OTL.exe
    [2014/03/07 09:44:21 | 000,000,000 | ---D | C] -- C:\Users\Jean\Desktop\old txts
    [2014/03/06 23:52:28 | 000,982,016 | ---- | C] (Farbar) -- C:\Users\Jean\Desktop\MiniToolBox.exe
    [2014/03/06 23:50:18 | 000,409,600 | ---- | C] (Farbar) -- C:\Users\Jean\Desktop\FSS.exe
    [2014/03/06 20:41:52 | 000,000,000 | ---D | C] -- C:\FRST
    [2014/03/06 20:29:16 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
    [2014/03/06 20:13:49 | 000,000,000 | ---D | C] -- C:\AdwCleaner
    [2014/03/06 20:13:42 | 001,145,344 | ---- | C] (Farbar) -- C:\Users\Jean\Desktop\FRST.exe
    [2014/03/06 20:13:37 | 001,037,734 | ---- | C] (Thisisu) -- C:\Users\Jean\Desktop\JRT.exe
    [2014/03/06 20:06:24 | 000,000,000 | ---D | C] -- C:\Users\Jean\Desktop\Lance trip 3 4 14
    [2014/03/06 12:14:07 | 000,000,000 | ---D | C] -- C:\Users\Jean\Desktop\FIRST Lance trip 3 4 14
    [2014/03/05 21:54:51 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Jean\Desktop\dds.com
    [2014/03/03 10:49:05 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\Ahead
    [2014/02/25 12:40:31 | 000,000,000 | ---D | C] -- C:\Windows\en
    [2014/02/25 12:40:00 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
    [2014/02/25 12:39:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
    [2014/02/25 12:38:44 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2014/02/25 12:38:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2014/02/25 12:37:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2014/02/25 12:37:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
    [2014/02/25 12:07:44 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\Windows Live
    [2014/02/25 12:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2014/02/19 22:22:00 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\Apple
    [2014/02/18 09:33:08 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\Apple Computer
    [2014/02/16 20:38:24 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\AOL
    [2014/02/16 20:37:07 | 000,000,000 | ---D | C] -- C:\Users\Jean\AppData\Local\Adobe
    [2014/02/16 16:40:09 | 000,000,000 | ---D | C] -- C:\Windows\Migration

    ========== Files - Modified Within 30 Days ==========

    [2014/03/07 20:58:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2014/03/07 20:57:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jean\Desktop\OTL.exe
    [2014/03/07 20:54:06 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2014/03/07 20:54:06 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2014/03/07 20:40:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2014/03/07 20:10:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-528091951-17181806-3350549182-1000UA.job
    [2014/03/07 19:38:11 | 000,000,334 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize 4.job
    [2014/03/07 19:37:28 | 000,000,263 | ---- | M] () -- C:\Windows\Brownie.ini
    [2014/03/07 19:37:18 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2014/03/07 19:36:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2014/03/07 09:53:11 | 000,692,352 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2014/03/07 09:53:11 | 000,138,298 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2014/03/06 23:48:02 | 000,982,016 | ---- | M] (Farbar) -- C:\Users\Jean\Desktop\MiniToolBox.exe
    [2014/03/06 23:47:20 | 000,409,600 | ---- | M] (Farbar) -- C:\Users\Jean\Desktop\FSS.exe
    [2014/03/06 20:11:08 | 001,145,344 | ---- | M] (Farbar) -- C:\Users\Jean\Desktop\FRST.exe
    [2014/03/06 20:08:50 | 001,037,734 | ---- | M] (Thisisu) -- C:\Users\Jean\Desktop\JRT.exe
    [2014/03/06 20:08:30 | 001,244,192 | ---- | M] () -- C:\Users\Jean\Desktop\adwcleaner.exe
    [2014/03/05 21:52:26 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Jean\Desktop\dds.com
    [2014/03/04 16:21:26 | 000,012,946 | ---- | M] () -- C:\Users\Jean\AppData\Roaming\Microsoft Excel 97-2003.CAL
    [2014/03/04 09:17:38 | 008,397,824 | ---- | M] () -- C:\Users\Jean\Desktop\Outlook backup.pst
    [2014/03/01 21:23:36 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-528091951-17181806-3350549182-1000Core.job
    [2014/02/25 20:54:08 | 000,481,656 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2014/02/21 22:14:27 | 000,002,048 | ---- | M] () -- C:\Users\Jean\Desktop\Google Chrome.lnk
    [2014/02/19 15:17:26 | 000,000,118 | ---- | M] () -- C:\Users\Public\Documents\SAH_Install.ini
    [2014/02/16 20:41:31 | 000,000,815 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
    [2014/02/15 15:18:56 | 000,000,426 | ---- | M] () -- C:\Windows\BRWMARK.INI

    ========== Files Created - No Company Name ==========

    [2014/03/06 20:13:24 | 001,244,192 | ---- | C] () -- C:\Users\Jean\Desktop\adwcleaner.exe
    [2014/03/05 15:12:15 | 000,000,961 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
    [2014/03/04 16:21:26 | 000,012,946 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\Microsoft Excel 97-2003.CAL
    [2014/03/04 09:17:20 | 008,397,824 | ---- | C] () -- C:\Users\Jean\Desktop\Outlook backup.pst
    [2014/03/03 11:16:42 | 000,002,595 | ---- | C] () -- C:\Users\Jean\Desktop\Microsoft Office PowerPoint 2007.lnk
    [2014/03/03 11:16:42 | 000,001,763 | ---- | C] () -- C:\Users\Jean\Desktop\Ipswitch WS_FTP 12.lnk
    [2014/03/03 11:16:42 | 000,001,708 | ---- | C] () -- C:\Users\Jean\Desktop\Hoyle Card Games.lnk
    [2014/03/03 11:16:42 | 000,000,949 | ---- | C] () -- C:\Users\Jean\Desktop\Microsoft Office Outlook.lnk
    [2014/02/25 12:39:53 | 000,001,169 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
    [2014/02/25 12:39:41 | 000,001,238 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
    [2014/02/25 12:39:26 | 000,001,048 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
    [2014/02/25 12:39:17 | 000,002,036 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
    [2014/02/19 15:17:23 | 000,000,118 | ---- | C] () -- C:\Users\Public\Documents\SAH_Install.ini
    [2013/12/20 22:34:01 | 000,000,030 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\WB.CFG
    [2012/12/25 09:33:00 | 000,000,446 | ---- | C] () -- C:\Windows\SIERRA.INI
    [2012/12/04 11:24:07 | 000,012,967 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\Tab Separated Values (Windows).CAL
    [2012/07/31 19:58:01 | 000,000,090 | ---- | C] () -- C:\Windows\System32\ftm31.dat
    [2012/07/19 18:22:18 | 000,000,240 | ---- | C] () -- C:\Users\Jean\AppData\Local\RAExpertHistory.xml
    [2012/04/20 08:53:18 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
    [2012/04/13 13:37:18 | 000,024,206 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\UserTile.png
    [2012/04/01 20:49:29 | 000,000,416 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\wklnhst.dat
    [2012/03/12 09:44:03 | 000,000,191 | ---- | C] () -- C:\Windows\PowerReg.dat
    [2012/02/25 12:33:30 | 000,061,678 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\PFP120JPR.{PB
    [2012/02/25 12:33:30 | 000,012,358 | ---- | C] () -- C:\Users\Jean\AppData\Roaming\PFP120JCM.{PB
    [2012/02/25 12:29:01 | 000,000,680 | ---- | C] () -- C:\Users\Jean\AppData\Local\d3d9caps.dat
    [2012/02/19 20:14:37 | 000,001,024 | ---- | C] () -- C:\Users\Jean\.rnd
    [2012/02/17 11:58:54 | 000,720,402 | ---- | C] () -- C:\ProgramData\LuUninstall.LiveUpdate
    [2012/02/17 11:55:03 | 000,041,984 | ---- | C] () -- C:\Users\Jean\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    ========== ZeroAccess Check ==========

    [2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    " " = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    " " = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    " " = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 01:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    ========== LOP Check ==========

    [2014/03/07 19:38:25 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Dropbox
    [2013/12/20 21:39:11 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\DVDVideoSoft
    [2012/02/20 15:36:23 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\EPSON
    [2012/03/21 21:08:45 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Firetrust
    [2013/11/20 11:44:09 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\GlarySoft
    [2014/03/06 22:07:41 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\IrfanView
    [2012/03/27 19:17:24 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\JGsoft
    [2012/07/19 21:10:25 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Leadertech
    [2012/03/21 21:15:42 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\MailWasherPro
    [2013/10/01 18:24:57 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\ooVoo Details
    [2012/04/01 08:48:02 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\OpenOffice.org
    [2014/02/01 14:03:07 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\PDF reDirect
    [2012/02/17 11:42:59 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\SampleView
    [2012/02/19 20:20:55 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Simple Star
    [2013/08/29 13:07:11 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\TeamViewer
    [2012/04/01 20:49:30 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Template
    [2012/11/24 10:25:45 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Tether
    [2012/02/17 16:14:24 | 000,000,000 | ---D | M] -- C:\Users\Jean\AppData\Roaming\Thunderbird

    ========== Purity Check ==========



    < End of report >
     
  2. 2014/03/07
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Here is the second txt document:

    OTL Extras logfile created on: 3/7/2014 8:59:18 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jean\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 60.31% Memory free
    6.19 Gb Paging File | 5.17 Gb Available in Paging File | 83.42% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 455.59 Gb Total Space | 323.07 Gb Free Space | 70.91% Space Free | Partition Type: NTFS
    Drive D: | 10.17 Gb Total Space | 4.76 Gb Free Space | 46.80% Space Free | Partition Type: NTFS

    Computer Name: JEAN-PC | User Name: Jean | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1 ",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "UacDisableNotify" = 0
    "InternetSettingsDisableNotify" = 0
    "AutoUpdateDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0C481F92-A5B2-42CD-8A76-B3B0B5B7B7D3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{43E6742D-59FF-445A-8A3C-684C21EB6CD1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{4CE9E9E0-E9BE-4FEA-B673-7D10DF5B87DF}" = rport=138 | protocol=17 | dir=out | app=system |
    "{5985C8AE-8689-4EE7-8395-FF9D505E718E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{5E8D817D-0A16-47B5-AB43-A216FBCBED6D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{64C504D0-73E3-4970-A329-4600B56FEBA2}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
    "{7C242051-E96F-4CE8-9D9D-1E6A7E5922D5}" = lport=139 | protocol=6 | dir=in | app=system |
    "{84E357C3-A728-4452-8544-73D39FEEDC82}" = lport=137 | protocol=17 | dir=in | app=system |
    "{854B18F7-27F1-4B46-8A84-5049E6D153F3}" = lport=138 | protocol=17 | dir=in | app=system |
    "{8918A381-79E5-4E77-B166-E3359F4B0C41}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{9A1EFFBE-4251-43E8-AE8A-F82C3946A868}" = rport=445 | protocol=6 | dir=out | app=system |
    "{9A834C79-6FB6-498D-AFC2-737F5039C083}" = rport=137 | protocol=17 | dir=out | app=system |
    "{9C750238-81E9-44FD-B345-79E3FDC250CD}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{A84A8304-E9A5-4802-9800-CB79132CA89D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{AF1EE1A2-D000-4FA3-B4CC-3F7DF70C49DD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{B61B1683-71E3-4103-9549-392AAB052F11}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{BAEB996B-30CB-4691-8613-14C8EE9D8D6E}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{C3A56A27-5085-4AB8-8EE1-1BED92D91CF7}" = rport=139 | protocol=6 | dir=out | app=system |
    "{D38FE75B-C2D8-4214-A395-DA68CA20CFBE}" = lport=445 | protocol=6 | dir=in | app=system |
    "{D4176A4B-CA1D-4F27-9C4C-9619A7F7BED6}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{D5E1DED8-932A-4EFE-B3A9-1E8DA41D3A23}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{E3A81E43-A4DE-497D-AE19-C3AFABEA296D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{001AC188-E5CF-4A27-97C6-A0763E9D2C43}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
    "{017187AE-A58C-4472-BDA0-96C4A5707C76}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
    "{0350220D-995C-4F9B-A1C1-C862ABBFEEDB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{05F3CFC4-C884-4990-89EB-5A9A836FA334}" = protocol=17 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
    "{093FB0CD-1BC7-4835-BABD-3C04EE0F3112}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{0B69FE29-BBA6-4D1C-8FFC-37BE0B52DAC3}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
    "{0CC55C08-502B-4158-A1B3-A5B945C40024}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{0D5B7C85-ED21-4DD8-A38E-D814422A1438}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{1DDC2CB3-23A3-4FA7-8E26-20EAC8AE76C1}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe |
    "{1F263EE2-9DD0-43DF-BADD-AE763ECFAAC2}" = protocol=6 | dir=in | app=c:\program files\common files\aol\system information\sinf.exe |
    "{2CCB00E7-2392-4A11-AB03-E9A776B14B7B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{3042F2F6-B59F-4ADF-A870-3F0C556EEB49}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{313E7744-3C54-42DB-A93B-53EAB6B5F30A}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe |
    "{3345CEC0-5C3C-4522-8FCC-DE33F878F112}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{3A2B9972-C14B-49E2-9632-50956C9BFE6B}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
    "{3B504B66-EEA2-48C6-B941-7CF52F6BD023}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{3C6B841E-BF81-4505-98FF-35AF27889AE7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{3ED4429B-59F8-486E-A90D-6A7C18CC4B3D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\1334930562\ee\aolsoftware.exe |
    "{428C7C5B-7518-4150-A246-0C3E0B49E015}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe |
    "{444AEE3C-F0C5-41E8-B90F-7C2E3F0DC9F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{46A52A11-CDC9-4C9C-B2A2-ECCCCE2DAEE0}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{47C77055-3AF2-40CA-8090-469BD0D801B7}" = protocol=6 | dir=in | app=c:\program files\aol 9.5\waol.exe |
    "{51005A75-D42F-462D-8DDF-076AE93A2658}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{52509026-01AC-43E1-9655-5433811F1E6B}" = protocol=17 | dir=in | app=c:\program files\aol 9.5\waol.exe |
    "{61578EA3-FD8D-4C70-A91F-FCC98126D288}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
    "{63058FB5-CE93-49EE-920B-AB57D3AC4595}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{66D9F188-5D32-4B22-BE66-373BFD94B3C6}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
    "{7E50D2E5-FA70-4620-B1A0-D563128B41E4}" = protocol=17 | dir=in | app=c:\program files\common files\aol\acs\aoldial.exe |
    "{81224FFB-2BC6-4A26-AEA0-38CBAEEFCD9E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{86BAB2ED-2378-476D-94F7-DB3A8327BAA9}" = dir=in | app=c:\program files\itunes\itunes.exe |
    "{89F969AA-40A7-464D-A648-F65B5CA619B4}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
    "{9078E63C-704E-4E91-8A28-C9FF5F0CC752}" = protocol=6 | dir=in | app=c:\users\jean\appdata\roaming\dropbox\bin\dropbox.exe |
    "{ADFC96A8-E36F-477C-AB6B-4CB84800B52B}" = protocol=17 | dir=in | app=c:\users\jean\appdata\roaming\dropbox\bin\dropbox.exe |
    "{AE05C1B7-B4EB-4431-A1E2-DEEF0D5FF7B8}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
    "{AF5CC5F5-1126-429F-853B-37183B239A27}" = protocol=6 | dir=in | app=c:\program files\common files\aol\1334930562\ee\aolsoftware.exe |
    "{B27AC467-22AD-4BF1-B542-B94155DD2E25}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{B72D13D1-2991-4A9C-AFE0-1CF679C28A3C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{BC7037B2-7B10-473E-9BD8-18871298AE4B}" = protocol=6 | dir=out | app=system |
    "{C32EB3C2-647D-4E0C-A2E9-018EACD12155}" = protocol=6 | dir=in | app=c:\program files\common files\aol\acs\aolacsd.exe |
    "{DD56A2AE-5EF7-45F0-90FE-6E6AE555ED06}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe |
    "{DFCD41BB-463B-4ACC-9D07-DA7EC809DAB0}" = protocol=17 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
    "{E74D1C69-F746-4C04-8B67-9FF10D97BAF1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{EB65FE4C-053B-4EE0-BADF-E0E0894805B9}" = protocol=6 | dir=in | app=c:\program files\common files\aol\topspeed\3.0\aoltpsd3.exe |
    "{ECF44776-0B60-4493-BBC6-B915667F4A53}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{F94BF27C-742B-4E5C-9454-9291BE03B5AD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{FC2C0066-8017-4E4C-B8C5-ED8AAB4E61B2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "TCP Query User{9087F102-B4AE-4F67-BDE3-3F3078416AA5}C:\program files\tams11\games\hand and foot\handandfoot.exe" = protocol=6 | dir=in | app=c:\program files\tams11\games\hand and foot\handandfoot.exe |
    "TCP Query User{CCA7B867-DDED-454E-9B0B-DE6FB20DA864}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "UDP Query User{3A7CDCF2-4B5F-45EF-B1A8-E1BDD2B6A437}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "UDP Query User{EED12008-858E-49C2-8DE5-648979358D4D}C:\program files\tams11\games\hand and foot\handandfoot.exe" = protocol=17 | dir=in | app=c:\program files\tams11\games\hand and foot\handandfoot.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0CD47142-BA4F-46B0-AA92-2675864928B8}" = Microsoft Security Client
    "{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
    "{10E3A6DD-84D8-4D8A-BB11-5E5314BCA7FD}" = Apple Mobile Device Support
    "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series" = Canon MG5200 series MP Drivers
    "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
    "{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
    "{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{254BEB3E-1085-4D66-9CDC-0152C0DC2E93}" = EPSON TWAIN 5
    "{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
    "{26A24AE4-039D-4CA4-87B4-2F83216039FF}" = Java(TM) 6 Update 39
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
    "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
    "{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
    "{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
    "{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
    "{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
    "{5E33D30D-D896-4D92-B033-5F45819B2937}" = Strongvault Online Backup
    "{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
    "{616445AF-BBCF-41C1-A4D6-8CFF171C182D}" = iTunes
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{6657DA03-A39B-472C-8458-6292E128A3D9}" = MailWasherPro
    "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.0.5
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
    "{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
    "{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
    "{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
    "{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
    "{93691D57-668D-4940-814E-4D7E16F7459B}" = Brother HL-2140
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A2264E8F-1649-11E3-8BED-B8AC6F98CCE3}" = Google Earth
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}" = Apple Application Support
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06)
    "{AD88355B-A4E0-4DA1-BAC3-EA4FEA930691}" = Ipswitch WS_FTP 12
    "{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
    "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
    "{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B4DD23DF-FA02-4BA0-8087-9FFB5C081033}" = Nero 8
    "{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
    "{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
    "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E30DECE7-42AF-489D-ABB4-BAD765347272}" = Omar Sharif Bridge
    "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
    "{E7084B89-69E0-46B3-A118-8F99D06988CD}" = Microsoft SQL Server VSS Writer
    "{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}" = Google Drive
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Adobe Photoshop 5.0.2" = Adobe Photoshop 5.0.2
    "AOL Emergency Connect Utility 1.0" = Uninstall AOL Emergency Connect Utility 1.0
    "AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
    "ArcSoft PhotoImpression 3.0" = ArcSoft PhotoImpression 3.0
    "Belarc Advisor" = Belarc Advisor 8.2
    "CCleaner" = CCleaner
    "CleanUp!" = CleanUp!
    "Copy Utility" = Copy Utility
    "EPSON Photo Print" = EPSON Photo Print
    "EPSON Smart Panel" = EPSON Smart Panel
    "Free YouTube Download_is1" = Free YouTube Download version 3.2.11.812
    "Glary Utilities 4" = Glary Utilities 4.0
    "HandAndFoot_is1" = Hand And Foot 1.0.3.1
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "Hoyle Card Games 4" = Hoyle Card Games 4
    "Hoyle Card Games 5" = Hoyle Card Games 5
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
    "Microsoft Security Client" = Microsoft Security Essentials
    "Microsoft SQL Server 2005" = Microsoft SQL Server 2005
    "Mozilla Firefox 26.0 (x86 en-US)" = Mozilla Firefox 26.0 (x86 en-US)
    "Mozilla Thunderbird 24.3.0 (x86 en-US)" = Mozilla Thunderbird 24.3.0 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "NVIDIA Drivers" = NVIDIA Drivers
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "PDF reDirect" = PDF reDirect (remove only)
    "Revo Uninstaller" = Revo Uninstaller 1.95
    "SMALLBUSINESSR" = Microsoft Office Small Business 2007
    "TClockEx_is1" = TClockEx
    "TeamViewer 8" = TeamViewer 8
    "WinLiveSuite" = Windows Live Essentials

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Dropbox" = Dropbox
    "Google Chrome" = Google Chrome
    "Google Earth Free Download Packages" = Google Earth Free Download Packages
    "IrfanView Free Download Packages" = IrfanView Free Download Packages
    "Pilot Desktop" = Palm Desktop

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 3/7/2014 9:18:47 PM | Computer Name = Jean-PC | Source = VSS | ID = 12292
    Description =

    Error - 3/7/2014 9:18:47 PM | Computer Name = Jean-PC | Source = VSS | ID = 40
    Description =

    Error - 3/7/2014 9:18:47 PM | Computer Name = Jean-PC | Source = VSS | ID = 12292
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 40
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 12292
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 40
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 12292
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 40
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = VSS | ID = 12292
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = System Restore | ID = 8193
    Description =

    Error - 3/7/2014 9:18:59 PM | Computer Name = Jean-PC | Source = System Restore | ID = 8210
    Description =

    [ OSession Events ]
    Error - 1/8/2014 11:25:40 AM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 336
    seconds with 120 seconds of active time. This session ended with a crash.

    Error - 1/8/2014 11:28:27 AM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 158
    seconds with 120 seconds of active time. This session ended with a crash.

    Error - 1/11/2014 12:51:46 PM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 223
    seconds with 180 seconds of active time. This session ended with a crash.

    Error - 1/16/2014 9:45:55 AM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 1/16/2014 10:22:51 AM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6680.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 1/22/2014 2:24:35 PM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 158
    seconds with 120 seconds of active time. This session ended with a crash.

    Error - 1/29/2014 12:21:29 PM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 69
    seconds with 60 seconds of active time. This session ended with a crash.

    Error - 2/15/2014 4:13:25 PM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1311
    seconds with 600 seconds of active time. This session ended with a crash.

    Error - 2/16/2014 11:02:46 AM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6680.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 2/26/2014 5:26:40 PM | Computer Name = Jean-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 235
    seconds with 180 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 3/7/2014 10:28:46 AM | Computer Name = Jean-PC | Source = DCOM | ID = 10005
    Description =

    Error - 3/7/2014 10:28:46 AM | Computer Name = Jean-PC | Source = Service Control Manager | ID = 7001
    Description =

    Error - 3/7/2014 10:30:19 AM | Computer Name = Jean-PC | Source = Service Control Manager | ID = 7001
    Description =

    Error - 3/7/2014 10:38:13 AM | Computer Name = Jean-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 1.167.1000.0 Update Source: %%859 Update Stage:
    %%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

    Current
    Engine Version: Previous Engine Version: 1.1.10302.0 Error code: 0x80070422 Error
    description: The service cannot be started, either because it is disabled or because
    it has no enabled devices associated with it.

    Error - 3/7/2014 10:43:45 AM | Computer Name = Jean-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 3/7/2014 10:53:35 AM | Computer Name = Jean-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 1.167.1000.0 Update Source: %%859 Update Stage:
    %%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

    Current
    Engine Version: Previous Engine Version: 1.1.10302.0 Error code: 0x80070422 Error
    description: The service cannot be started, either because it is disabled or because
    it has no enabled devices associated with it.

    Error - 3/7/2014 4:49:36 PM | Computer Name = Jean-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 3/7/2014 4:59:28 PM | Computer Name = Jean-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 1.167.1000.0 Update Source: %%859 Update Stage:
    %%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

    Current
    Engine Version: Previous Engine Version: 1.1.10302.0 Error code: 0x80070422 Error
    description: The service cannot be started, either because it is disabled or because
    it has no enabled devices associated with it.

    Error - 3/7/2014 8:37:15 PM | Computer Name = Jean-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 3/7/2014 8:47:04 PM | Computer Name = Jean-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 1.167.1000.0 Update Source: %%859 Update Stage:
    %%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

    Current
    Engine Version: Previous Engine Version: 1.1.10302.0 Error code: 0x80070422 Error
    description: The service cannot be started, either because it is disabled or because
    it has no enabled devices associated with it.


    < End of report >


    How is it looking??

    Jean
     

  3. to hide this advert.

  4. 2014/03/08
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    I am awaiting your advice whenever you have time.
    I do want you to know I have no sound, and do not have either printer listed. Also I tried to update Windows for Microsoft Office and it said it encountered an error. I guess I am not out of the woods yet but at least I can get on the internet.

    Thank you.

    Jean
     
  5. 2014/03/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Some of those may be a subject to a different forum so let's finish cleaning process first.

    [​IMG] Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following
    Code:
    :OTL
    O4 - HKLM..\Run: [MapsGalaxy EPM Support]  "C:\PROGRA~1\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S File not found
    O15 - HKU\S-1-5-21-528091951-17181806-3350549182-1000\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    
    
    :Services
    
    :Reg
    
    :Files
    C:\FRST
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
    
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Click on "Run ESET Online Scanner" button.
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  6. 2014/03/08
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Ok, I just finished running the ESET Online Scanner. It took about 5 hours but there were no viruses found.

    Following is the text from OTL:

    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MapsGalaxy EPM Support deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-528091951-17181806-3350549182-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\aol.com\objects\ deleted successfully.
    Starting removal of ActiveX control {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    C:\FRST\Quarantine folder moved successfully.
    C:\FRST\Logs folder moved successfully.
    C:\FRST\Hives\Users\00000002 folder moved successfully.
    C:\FRST\Hives\Users\00000001 folder moved successfully.
    C:\FRST\Hives\Users folder moved successfully.
    C:\FRST\Hives folder moved successfully.
    C:\FRST folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Jean
    ->Temp folder emptied: 11098622 bytes
    ->Temporary Internet Files folder emptied: 24308071 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 1264902 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 1140 bytes

    User: LogMeInRemoteUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 39142 bytes
    RecycleBin emptied: 340246 bytes

    Total Files Cleaned = 35.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Jean
    ->Java cache emptied: 0 bytes

    User: LogMeInRemoteUser

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Jean
    ->Flash cache emptied: 0 bytes

    User: LogMeInRemoteUser

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 03082014_152206

    Files\Folders moved on Reboot...

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...

    SECURITY TEXT:

    Results of screen317's Security Check version 0.99.80
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 9
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Microsoft Security Essentials
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.75.0.1300
    CCleaner
    EasyCleaner
    Java(TM) 6 Update 22
    Java(TM) 6 Update 39
    Java(TM) 6 Update 4
    Java version out of Date!
    Adobe Flash Player 11.9.900.170 Flash Player out of Date!
    Adobe Reader XI
    Mozilla Firefox (26.0)
    Mozilla Thunderbird (24.3.0)
    Google Chrome 32.0.1700.107
    Google Chrome 33.0.1750.117
    ````````Process Check: objlist.exe by Laurent````````
    Microsoft Security Essentials MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 1 %
    ````````````````````End of Log``````````````````````
     
  7. 2014/03/08
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    TEXT FROM FSS:

    Farbar Service Scanner Version: 25-02-2014
    Ran by Jean (administrator) on 08-03-2014 at 15:40:28
    Running from "C:\Users\Jean\Desktop "
    Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============
    SDRSVC Service is not running. Checking service configuration:
    The start type of SDRSVC service is set to Disabled. The default start type is 3.
    The ImagePath of SDRSVC service is OK.
    The ServiceDll of SDRSVC service is OK.
    Checking LEGACY_SDRSVC: ATTENTION!=====> Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.


    System Restore Disabled Policy:
    ========================


    Security Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is OK.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware "=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\system32\nsisvc.dll => MD5 is legit
    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
    C:\Windows\system32\Drivers\afd.sys => MD5 is legit
    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
    C:\Windows\system32\Drivers\tcpip.sys
    [2013-08-13 14:38] - [2013-07-04 22:20] - 0914880 ____A (Microsoft Corporation) 6D0D344F643E28B31262AC2682109A3C

    C:\Windows\system32\dnsrslvr.dll => MD5 is legit
    C:\Windows\system32\mpssvc.dll => MD5 is legit
    C:\Windows\system32\bfe.dll => MD5 is legit
    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\system32\SDRSVC.dll => MD5 is legit
    C:\Windows\system32\vssvc.exe => MD5 is legit
    C:\Windows\system32\wscsvc.dll => MD5 is legit
    C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\system32\wuaueng.dll => MD5 is legit
    C:\Windows\system32\qmgr.dll => MD5 is legit
    C:\Windows\system32\es.dll => MD5 is legit
    C:\Windows\system32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\system32\ipnathlp.dll => MD5 is legit
    C:\Windows\system32\iphlpsvc.dll => MD5 is legit
    C:\Windows\system32\svchost.exe => MD5 is legit
    C:\Windows\system32\rpcss.dll => MD5 is legit


    **** End of log ****

    I also ran the TFC and last the scanner.

    What do you think about this computer now.

    Thanks again for all your help.

    Jean
     
  8. 2014/03/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Update Adobe Flash Player: http://get.adobe.com/flashplayer/
    Make sure you UN-check Yes, install McAfee Security Scan Plus

    NOTE 1: Beginning with Adobe Flash Version 11.3, the universal installer includes the 32-bit and 64-bit versions of the Flash Player.
    NOTE 2: While installing make sure you UN-check any extra garbage which wants to install alongside.

    [​IMG] 1. Update your Java version here: http://www.java.com/en/download/manual.jsp
    Alternate download: http://www.filehippo.com/search?q=java

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

    Note 3: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista and 7 users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    ===============================

    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

    12. Please, let me know, how your computer is doing.
     
  9. 2014/03/08
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    I did run the Adobe Flash Player with no problem.
    I tried to run the Java version and I get the following message:

    "The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance. "


    How do I get the Windows Installer Service?

    Jean
     
  10. 2014/03/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run JavaRa first and then try to install new Java again.
     
  11. 2014/03/08
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    I did run the JavaRa first and I am still getting the message when I try to install Java:
    "The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance. "

    I even went to this site: http://tinyurl.com/pzap5kl
    to try to repair the Windows Installer but the first option did not work.

    Any ideas?

    Good Night for now. It is so late I have to go to bed.

    P.S. It also said "8.On the Desktop, right-click Msirepair.reg, and then click Run as administrator." It didn't give me the option to Run As Administrator, just Merge. It did add it to the registry but I still can't install Java.

    Help, I'm stuck.

    Jean
     
  12. 2014/03/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  13. 2014/03/09
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Broni, that did the trick (Total Install). I was able to install Java when all the others were gone.

    I will continue with your instructions for cleaning up the programs this evening. I have to go see my husband who is in the VA nursing home and then go to a Birthday Party. I will get back to you as soon as I finish doing the things you advised.

    Thanks again. I wish I had your brain.

    Jean
     
  14. 2014/03/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     
  15. 2014/03/09
    larsonjean

    larsonjean Well-Known Member Thread Starter

    Joined:
    2002/06/03
    Messages:
    766
    Likes Received:
    2
    Hi Broni,
    Thanks for all the help. I did run the rest of the programs you suggested and I think I am in good shape except for No Printers or Sound. I will work on that later. The computer is running very well.

    I did like that Total Uninstall. I suppose I can use that for other programs I want to install also.

    Thanks for closing out this problem. I'll be more careful in the future.

    I only can afford a little donation but believe me you are worth a million times more.

    Jean
     
  16. 2014/03/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thank you :)

    Please pursue printer/sound issue in Windows forum.
    It may be just a matter of reinstalling drivers.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.