1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

IE and Mozilla not working - dl.exe problem?

Discussion in 'Virus & Other Malware Removal' started by CindyJB, Jan 12, 2015.

Thread Status:
Not open for further replies.
Advertisement
  1. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    My computer starting accessing the internet very slowly and now won't work at all. It is on a router and the other computer works fine so I can access the internet from the other computer but not the one I really need. Somehow I have messed up Mozilla and now it is saying a profile is missing. I can get IE to open but it generally won't open a website. It says connection problem, I run diagnose, it says winsock problem do you want to fix, I say yes and reboot - it doesn't fix it. I also get a message that says:

    dl.exe
    The NTVDM CUP has encountered an illegal instruction
    CS:0000 IP:0e23 OP:ff ff ff ff ff 00

    I have run SuperAnti Spyware and it didn't find anything.

    Can anyone help?

    By the way, I have no problem getting email.
     
  2. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Tech Support Guy System Info Utility version 1.0.0.2

    OS Version: Microsoft Windows XP Home Edition, Service Pack 2, 32 bit

    Processor: Intel(R) Pentium(R) D CPU 3.00GHz, x86 Family 15 Model 6 Stepping 2

    Process Count: 2

    Ram: 2046 Mb

    Graphics Card: RADEON X300 SE 128MB HyperMemory, 128 Mb

    Hard Drives: C: Total - 149275 MB, Free - 22606 MB;

    Motherboard: Dell Inc., OYC523

    Antivirus: None
     
  3. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Welcome. :)

    Please download Farbar Recovery Scan Tool and save it to your desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Make sure that under Optional Scans, there is a checkmark on Addition.txt and Shortcut.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The tool will also produce another two logs (Addition.txt and Shortcut.txt). Please attach these to your reply.
     
  4. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Ok, I went ahead and downloaded all the programs I could find that seem to have been recommended on these forums. I didn't check the ShortCut one but I can go back and do that. Here is what I have so far:

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2015 02
    Ran by CINDY (administrator) on DARRYL on 12-01-2015 23:06:34
    Running from F:\
    Loaded Profiles: CINDY & QBDataServiceUser22 (Available profiles: DEVON & CINDY & QBDataServiceUser19 & QBDataServiceUser22)
    Platform: Microsoft Windows XP Home Edition Service Pack 2 (X86) OS Language: English (United States)
    Internet Explorer Version 8 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
    (brother Industries Ltd) C:\WINDOWS\system32\BRSVC01A.EXE
    (brother Industries Ltd) C:\WINDOWS\system32\BRSS01A.EXE
    (SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
    (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\realplay.exe
    (Sonic Solutions) C:\WINDOWS\system32\dla\tfswctrl.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
    (Hewlett-Packard Company) C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe
    () C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    () C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
    (Intuit Inc.) C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE
    (HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
    (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    (Seagate Technology LLC) C:\Program Files\Maxtor\Sync\SyncServices.exe
    (United Parcel Service, Inc.) C:\UPS\WSTD\WSTDMessaging.exe
    (Memeo) C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
    (Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    (United Parcel Service, Inc.) C:\UPS\WSTD\WSTDMessaging.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    (Microsoft Corporation) C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    (Intuit) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    (Intuit Inc.) C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
    (Memeo) C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
    (HP) C:\WINDOWS\system32\HPZipm12.exe
    (Intuit, Inc.) C:\PROGRA~1\Intuit\QUC2E1~1\QBDBMgrN.exe
    (McAfee, Inc.) C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    () C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
    (McAfee, Inc.) C:\Program Files\McAfee\MSC\mcuihost.exe


    ==================== Registry (Whitelisted) ==================

    Addition:
    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-01-2015 02
    Ran by CINDY at 2015-01-12 23:10:19
    Running from F:\
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)


    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    5500 (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    5500_Help (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    5500Tour (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    5500Trb (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    ACT! 2000 (HKLM\...\ACT! 2000) (Version: - )
    ACT! 2000 (HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\ACT! 2000) (Version: - )
    ACT! 2000 (HKU\S-1-5-21-408940103-543640705-2808721970-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\ACT! 2000) (Version: - )
    Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
    Adobe Photoshop Elements (HKLM\...\Adobe Photoshop Elements 1.0) (Version: 1.0 - Adobe Systems, Inc.)
    Adobe Photoshop Elements 5.0 (HKLM\...\Adobe Photoshop Elements 5) (Version: 5.0 - Adobe Systems Inc.)
    Adobe Reader XI (11.0.08) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
    Adobe SVG Viewer (HKLM\...\Adobe SVG Viewer) (Version: 1.0 - Adobe Systems, Inc.)
    Adobe® Photoshop® Album Starter Edition 3.2 (HKLM\...\Adobe® Photoshop® Album Starter Edition 3.2) (Version: 3.2.0 - http://www.adobe.com)
    Advanced Analyzer (HKLM\...\{AF397F20-24BB-11D7-AC6F-0050DA09345C}) (Version: - )
    AiO_Scan (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    AiOSoftware (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    AlignmentUtility (Version: 17.00.0000 - UPS) Hidden
    Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ATI Control Panel (HKLM\...\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}) (Version: 6.14.10.5160 - )
    ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.162-050803a2-025672C-Dell - )
    BL2003 Registration (HKLM\...\BL2003 Registration) (Version: - )
    Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
    BufferChm (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    CCC (Version: 17.00.0000 - United Parcel Service, Inc.) Hidden
    Copy (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    CreativeProjects (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    CreativeProjectsTemplates (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    Critical Update for Windows Media Player 11 (KB959772) (HKLM\...\KB959772_WM11) (Version: - Microsoft Corporation)
    CueTour (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    DAZzle (HKLM\...\DAZzle) (Version: - )
    Dell Digital Jukebox Driver (HKLM\...\Dell Digital Jukebox Driver) (Version: - )
    Dell Driver Reset Tool (HKLM\...\{5905F42D-3F5F-4916-ADA6-94A3646AEE76}) (Version: 1.02.0000 - Dell Inc.)
    Dell Support Center (Support Software) (HKLM\...\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.2.09085 - Dell)
    DellSupport (HKLM\...\{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}) (Version: 6.0.3062 - Dell)
    Destinations (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    Digital Content Portal (HKLM\...\{B702CCCE-3176-4DBF-B932-D1B8F402F330}) (Version: 1.00.0000 - Dell)
    Director (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    DocProc (Version: 4.0.0.0 - Hewlett-Packard) Hidden
    DocumentViewer (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    DYMO Printable Postage (HKLM\...\Printable Postage.exe) (Version: 2.6 - Endicia Internet Postage)
    EPSON CardMonitor (HKLM\...\{109D28C7-FB38-483A-9C91-001CB59E2699}) (Version: - )
    EPSON PhotoStarter3.0 (HKLM\...\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}) (Version: - )
    EPSON Print CD (HKLM\...\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}) (Version: - )
    EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - )
    Fax (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    FormsComponent (Version: 17.00.0000 - UPS) Hidden
    FOSS (Version: 17.00.0000 - UPS) Hidden
    getPlus(R)_ocx (HKLM\...\getPlus(R)_ocx) (Version: - )
    Google Earth (HKLM\...\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}) (Version: 4.3.7284.3916 - Google)
    High Definition Audio Driver Package - KB835221 (HKLM\...\KB835221WXP) (Version: 20040219.000000 - Microsoft Corporation)
    Hotfix 2055 for SQL Server 2000 ENU (KB960082) (HKLM\...\KB960082(ENU)) (Version: 1 - Microsoft Corporation)
    HP Image Zone 4.2 (HKLM\...\HP Photo & Imaging) (Version: 4.2 - HP)
    HP LaserJet 400 M401 (HKLM\...\{8989F6D9-550C-4178-A8CB-75B82A06621F}) (Version: - Hewlett-Packard)
    HP PSC & OfficeJet 4.2 (HKLM\...\{A1062847-0846-427A-92A1-BB8251A91E91}) (Version: - HP)
    HP Share-to-Web (HKLM\...\{748F4870-8350-11D3-B0BF-080009FB4A19}) (Version: - )
    HP Software Update (HKLM\...\{457791C5-D702-4143-A7B2-2744BE9573F2}) (Version: 2.0.39.20040212 - Hewlett-Packard)
    hpbDSService (Version: 002.002.07399 - Hewlett-Packard) Hidden
    hpbM401DSService (Version: 001.001.05874 - Hewlett-Packard) Hidden
    HPLaserJet400-M401_HelpLearnCenter_SI (HKLM\...\{4989DD05-86FB-4CA2-96C5-923DFAD89DA3}) (Version: 1.01.0000 - Hewlett-Packard)
    HPLJUTCore (Version: 3.00.0003 - HP) Hidden
    HPLJUTM401 (Version: 3.00.0003 - HP) Hidden
    hppLaserJetService (Version: 009.022.00816 - Hewlett-Packard) Hidden
    hppM401LaserJetService (HKLM\...\{B1F80E92-B702-4E7A-91A1-D7987F9C83EC}) (Version: 001.015.00029 - Hewlett-Packard)
    hpStatusAlerts (Version: 030.027.1140 - Hewlett Packard) Hidden
    hpStatusAlertsM401 (Version: 030.025.01810 - Hewlett-Packard) Hidden
    HPSystemDiagnostics (Version: 1.5.0.0 - Your Company Name) Hidden
    ICCHelp (HKLM\...\{A5763105-D1D5-4862-A3FE-EC058F9AA73E}) (Version: 17.00.0000 - UPS)
    InstantShare (Version: 4.0.0.40 - Hewlett-Packard) Hidden
    Intel Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - )
    Intel(R) PRO Network Connections Drivers (HKLM\...\PROSet) (Version: - )
    Intel(R) PROSet for Wired Connections (HKLM\...\{4CEA6811-DFAD-4892-828D-49941FE3B779}) (Version: 9.30.0000 - Dell)
    iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
    Java 7 Update 9 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.90 - Oracle)
    Java(TM) 6 Update 24 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
    Learn2 Player (Uninstall Only) (HKLM\...\StreetPlugin) (Version: - )
    Lernout & Hauspie TruVoice American English TTS Engine (HKLM\...\tv_enua) (Version: - )
    Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
    Maxtor Manager (HKLM\...\InstallShield_{B8281D46-D846-4BB9-BC84-F1115A7BF820}) (Version: 4.01.0227 - Seagate Technology)
    Maxtor Manager (Version: 4.01.0227 - Seagate Technology) Hidden
    McAfee SecurityCenter (HKLM\...\MSC) (Version: 10.0.580 - McAfee, Inc.)
    MCU (Version: 1.00.0000 - Dell) Hidden
    Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
    Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
    Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
    Microsoft Expression Web 2 (HKLM\...\XWeb) (Version: 12.0.4518.1084 - Microsoft Corporation)
    Microsoft Office 2007 Primary Interop Assemblies (HKLM\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office FrontPage 2003 (HKLM\...\{91170409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
    Microsoft Office Professional 2007 (HKLM\...\PROR) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Plus! Digital Media Edition Installer (HKLM\...\{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}) (Version: 1.1.0.3514 - Microsoft Corporation)
    Microsoft Plus! Photo Story 2 LE (HKLM\...\{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}) (Version: 1.1.0.3463 - Microsoft Corporation)
    Microsoft SAPI 5.1- DO NOT REMOVE (HKLM\...\{DF0BEF15-A82E-40C5-A051-DE0B7F009895}) (Version: 5.1.0.0 - ReadPlease Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
    Microsoft Speech Recognition Engine 4.0 (English) (HKLM\...\MSCSR) (Version: - )
    Microsoft SQL Server Desktop Engine (UPSWSDBSERVER) (HKLM\...\{E09B48B5-E141-427A-AB0C-D3605127224A}) (Version: 8.00.2039 - Microsoft Corporation)
    Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual Studio 2005 Tools for Office Runtime (HKLM\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation)
    Microsoft WSE 2.0 SP3 (HKLM\...\{6F396FFB-CC3A-4335-BC0B-2AEF38F4492C}) (Version: 2.0.5050.0 - Microsoft Corporation)
    Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
    Mozilla Firefox 34.0.5 (x86 en-US) (HKLM\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
    MSIChecker (Version: 9.00.0000 - UPS) Hidden
    MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
    MSXML 6 Service Pack 2 (KB973686) (HKLM\...\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)
    Musicmatch for Windows Media Player (HKLM\...\{E93E5EF6-D361-481E-849D-F16EF5C78EBC}) (Version: 0.00.000 - )
    MyWordTool (HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\MyWordTool) (Version: 1 - http://www.mywordtool.com)
    MyWordTool (HKU\S-1-5-21-408940103-543640705-2808721970-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MyWordTool) (Version: 1 - http://www.mywordtool.com)
    NA1Messenger (Version: 17.00.0000 - Your Company Name) Hidden
    NRF (Version: 17.00.0000 - UPS) Hidden
    Octoshape add-in for Adobe Flash Player (HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Octoshape add-in for Adobe Flash Player) (Version: - )
    Octoshape add-in for Adobe Flash Player (HKU\S-1-5-21-408940103-543640705-2808721970-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Octoshape add-in for Adobe Flash Player) (Version: - )
    OpenOffice.org 2.2 (HKLM\...\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}) (Version: 2.2.9134 - OpenOffice.org)
    Overland (Version: 2.1.5 - Hewlett-Packard) Hidden
    PhotoGallery (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    PhotoParade Player (HKLM\...\PhotoParade.exe) (Version: - )
    PhotoShow Deluxe 3 (HKLM\...\PhotoShow Deluxe 3) (Version: 3.0 - Simple Star, Inc.)
    PolicyManager (Version: 17.00.0000 - UPS) Hidden
    PowerDVD 5.5 (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - )
    PrintScreen (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    ProductContext (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
    QuestDns 1.0 build 199 powered by FIRST SEARCHBAR (HKLM\...\QuestDns) (Version: - )
    QuickBooks (Version: 19.0.4008.703 - Intuit Inc.) Hidden
    QuickBooks (Version: 22.0.4005.2206 - Intuit Inc.) Hidden
    QuickBooks Customer Manager Version 1 (HKLM\...\{53A0BE5E-F813-43BD-AEDF-8A0036724648}) (Version: 1.00.000 - )
    QuickBooks Pro 2006 (HKLM\...\{69B02159-7622-4DBB-B9EE-F933039830AD}) (Version: - )
    QuickBooks Pro 2009 (HKLM\...\{9A2F0810-3622-4E86-9072-973FBE1679C5}) (Version: 19.0.4008.703 - Intuit Inc.)
    QuickBooks Pro 2012 (HKLM\...\{22057D8D-7CC8-46FF-AD8C-9BD24F9014F3}) (Version: 22.0.4005.2206 - Intuit Inc.)
    QuickBooks Simple Start Special Edition (HKLM\...\{14374619-0900-4056-BA06-C87C900AF9E6}) (Version: - )
    QuickProjects (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    QuickTime (HKLM\...\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}) (Version: 7.62.14.0 - Apple Inc.)
    Readme (Version: 43.0.217.000 - Hewlett-Packard) Hidden
    RealPlayer Basic (HKLM\...\RealPlayer 6.0) (Version: - )
    Reconciler (Version: 17.00.0000 - UPS) Hidden
    ReportServer (Version: 17.00.0000 - Your Company Name) Hidden
    RezEasy 7.5 Mobile (Std) (HKLM\...\RezEasy 7.5 Mobile (Std)) (Version: - )
    RezEasy Standard 7.5 (HKLM\...\RezEasy Standard 7.5) (Version: - )
    Scan (Version: 4.1.0.0 - Hewlett-Packard) Hidden
    Seagate Dashboard (HKLM\...\{C3A11907-930D-41AC-A135-CC3B12F92011}) (Version: 1.0.0.809 - Memeo Inc.)
    Shipstream Manager (HKLM\...\shipstream) (Version: - )
    SkinsHP1 (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    Sonic DLA (HKLM\...\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}) (Version: 4.95 - Sonic Solutions)
    Sonic MyDVD LE (HKLM\...\{21657574-BD54-48A2-9450-EB03B2C7FC29}) (Version: 6.1.1 - Sonic Solutions)
    Sonic RecordNow Audio (HKLM\...\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}) (Version: 2.0.0 - Sonic Solutions)
    Sonic RecordNow Copy (HKLM\...\{B12665F4-4E93-4AB4-B7FC-37053B524629}) (Version: 2.0.0 - Sonic Solutions)
    Sonic RecordNow Data (HKLM\...\{075473F5-846A-448B-BCB3-104AA1760205}) (Version: 2.0.0 - Sonic Solutions)
    Sonic Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Sonic Solutions)
    Sony DVD Architect Studio 3.0 (HKLM\...\{2EAEB09D-767A-431A-88B2-071C1A0D6214}) (Version: 3.0.51 - Sony)
    Sony Vegas Movie Studio Platinum 6.0 (HKLM\...\{70D1ADA7-4B91-490A-8683-720475CE37E3}) (Version: 6.0.43 - Sony)
    Sothink DHTMLMenu (HKLM\...\{24D1FCDD-FE3F-43D4-96D6-EDA0A8F633E7}_is1) (Version: - SourceTec Software Co., LTD)
    SpiceMASTER 2.5 TFX for Vegas (HKLM\...\SpiceMASTER 2.5 TFX for Vegas) (Version: 2.5 - Pixelan Software)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1128 - SUPERAntiSpyware.com)
    SupportSoft Assisted Service (HKLM\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
    SupportUtility (Version: 17.00.0000 - Your Company Name) Hidden
    System (Version: 17.00.0000 - UPS) Hidden
    Tax Forms Helper 2011 10.0 (HKLM\...\Tax Forms Helper 2011_is1) (Version: - )
    TrayApp (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    UnifiedPrinting (Version: 17.00.0000 - UPS) Hidden
    Unload (Version: 4.0.0 - Hewlett-Packard) Hidden
    Update for 2007 Microsoft Office System (KB2284654) (HKLM\...\{90120000-0045-0000-0000-0000000FF1CE}_XWeb_{FB166E7C-8AA6-48C8-B726-1F25BEE7825A}) (Version: - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0045-0000-0000-0000000FF1CE}_XWeb_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0014-0000-0000-0000000FF1CE}_PROR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    UPS WorldShip (HKLM\...\UPS WorldShip) (Version: 17.0 - UPS)
    UPSDB (Version: 17.00.0000 - UPS) Hidden
    UPSICC (Version: 17.00.0000 - UPS) Hidden
    UPSlinkHTTP (Version: 17.00.0000 - UPS) Hidden
    UPSVC2008MM (Version: 1.00.0000 - UPS) Hidden
    UPSVCMM (Version: 11.00.0000 - UPS) Hidden
    UPSVCMM (Version: 12.00.0000 - UPS) Hidden
    VLC media player 1.0.1 (HKLM\...\VLC media player) (Version: 1.0.1 - VideoLAN Team)
    WebCyberCoach 3.2 Dell (HKLM\...\WebCyberCoach_wtrb) (Version: - )
    WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
    WebHelp (HKLM\...\{8C5BD501-AD5D-4A75-9321-076509B438FC}) (Version: 17.00.0000 - UPS)
    WebReg (Version: 43.1.5.000 - Hewlett-Packard) Hidden
    Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.7.0018.5 - Microsoft Corporation)
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
    Windows Imaging Component (HKLM\...\WIC) (Version: 3.0.0.0 - Microsoft Corporation)
    Windows Installer 3.1 (KB893803) (HKLM\...\KB893803v2) (Version: - Microsoft Corporation)
    Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
    Windows Live OneCare safety scanner (HKLM\...\Windows Live OneCare safety scanner) (Version: - )
    Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
    Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
    Windows Search 4.0 (HKLM\...\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
    Windows XP Hotfix - KB873339 (HKLM\...\KB873339) (Version: 20041117.092459 - Microsoft Corporation)
    Windows XP Hotfix - KB885250 (HKLM\...\KB885250) (Version: 20050118.202711 - Microsoft Corporation)
    Windows XP Hotfix - KB885835 (HKLM\...\KB885835) (Version: 20041027.181713 - Microsoft Corporation)
    Windows XP Hotfix - KB885836 (HKLM\...\KB885836) (Version: 20041028.173203 - Microsoft Corporation)
    Windows XP Hotfix - KB886185 (HKLM\...\KB886185) (Version: 20041021.090540 - Microsoft Corporation)
    Windows XP Hotfix - KB887472 (HKLM\...\KB887472) (Version: 20041014.162858 - Microsoft Corporation)
    Windows XP Hotfix - KB887742 (HKLM\...\KB887742) (Version: 20041103.095002 - Microsoft Corporation)
    Windows XP Hotfix - KB888113 (HKLM\...\KB888113) (Version: 20041116.131036 - Microsoft Corporation)
    Windows XP Hotfix - KB888302 (HKLM\...\KB888302) (Version: 20041207.111426 - Microsoft Corporation)
    Windows XP Hotfix - KB889673 (HKLM\...\KB889673) (Version: 20041116.085848 - Microsoft Corporation)
    Windows XP Hotfix - KB890175 (HKLM\...\KB890175) (Version: 20041201.233338 - Microsoft Corporation)
    Windows XP Hotfix - KB890859 (HKLM\...\KB890859) (Version: 1 - Microsoft Corporation)
    Windows XP Hotfix - KB891781 (HKLM\...\KB891781) (Version: 20050110.165439 - Microsoft Corporation)
    WorldShip (Version: 17.00.0000 - UPS) Hidden
    WSShared (Version: 17.00.0000 - UPS) Hidden

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{32D32337-1511-4416-85C5-FD96C99322A0}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{349D777D-F7A2-4AAE-967F-A54F05A7FF3B}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBFinder.dll No File
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{3EC350A7-5C5E-4192-B734-E13722E10914}\InprocServer32 -> C:\Program Files\HP\HP Software Update\HPRulesEngine.dll (Hewlett-Packard Company)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{4A56F19E-9F50-4F43-93C8-050E44AA83A9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{4CA41277-032D-4a20-B225-371EBA96ABF2}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{53B5243F-8302-4DAD-BE8F-1D0665E8225E}\InprocServer32 -> C:\Program Files\HP\Common\FWUpdateEDO3.dll (Hewlett-Packard Company)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{5428A9ED-6CD8-11D6-9C8A-0001023DCAA2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{5B7331FA-8910-4748-A8A4-60B445041F28}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{5ED8AC89-B2DE-476D-8EEA-E170B2FCB058}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{6402BEC7-162A-4558-BE23-08AE4BBCB195}\InprocServer32 -> C:\Documents and Settings\CINDY\Local Settings\Application Data\TidyNetwork\petn.dll No File
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{7694F1CD-A55B-4B7C-8820-A90892EB4E9E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{8FEDE364-AB37-4551-80C9-6D468E222AB2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{97090E2F-3062-4459-855B-014F0D3CDBB1}\InprocServer32 -> C:\Program Files\Windows Desktop Search\deskbar.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{F2C593CC-74B2-4F71-8556-DD4D426D0409}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
    CustomCLSID: HKU\S-1-5-21-408940103-543640705-2808721970-1007_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll (Intuit Inc.)

    ==================== Restore Points =========================

    10-11-2014 07:21:36 System Checkpoint
    11-11-2014 08:43:43 System Checkpoint
    12-11-2014 09:25:56 System Checkpoint
    13-11-2014 09:41:11 System Checkpoint
    14-11-2014 10:03:49 System Checkpoint
    15-11-2014 10:54:32 System Checkpoint
    16-11-2014 10:57:58 System Checkpoint
    17-11-2014 11:01:16 System Checkpoint
    18-11-2014 14:07:02 System Checkpoint
    19-11-2014 15:00:49 System Checkpoint
    20-11-2014 19:51:26 System Checkpoint
    21-11-2014 21:30:56 System Checkpoint
    22-11-2014 21:41:02 System Checkpoint
    24-11-2014 08:20:20 System Checkpoint
    25-11-2014 08:37:47 System Checkpoint
    26-11-2014 08:45:20 System Checkpoint
    27-11-2014 12:53:14 System Checkpoint
    28-11-2014 13:01:05 System Checkpoint
    29-11-2014 13:59:01 System Checkpoint
    30-11-2014 15:09:24 System Checkpoint
    01-12-2014 15:25:16 System Checkpoint
    02-12-2014 16:09:53 System Checkpoint
    03-12-2014 16:46:38 System Checkpoint
    04-12-2014 16:47:21 System Checkpoint
    05-12-2014 17:20:29 System Checkpoint
    06-12-2014 17:41:30 System Checkpoint
    07-12-2014 17:52:45 System Checkpoint
    08-12-2014 18:41:37 System Checkpoint
    09-12-2014 19:02:54 System Checkpoint
    10-12-2014 19:58:32 System Checkpoint
    11-12-2014 20:25:07 System Checkpoint
    12-12-2014 20:57:04 System Checkpoint
    14-12-2014 19:32:38 System Checkpoint
    15-12-2014 19:50:48 System Checkpoint
    16-12-2014 20:48:30 System Checkpoint
    17-12-2014 21:35:46 System Checkpoint
    19-12-2014 00:37:54 System Checkpoint
    20-12-2014 09:32:09 System Checkpoint
    21-12-2014 09:37:55 System Checkpoint
    22-12-2014 10:33:06 System Checkpoint
    23-12-2014 11:27:25 System Checkpoint
    25-12-2014 20:01:12 System Checkpoint
    29-12-2014 14:48:28 System Checkpoint
    30-12-2014 14:57:35 System Checkpoint
    31-12-2014 15:20:18 System Checkpoint
    01-01-2015 16:17:37 System Checkpoint
    02-01-2015 17:13:30 System Checkpoint
    03-01-2015 18:05:49 System Checkpoint
    04-01-2015 19:08:27 System Checkpoint
    05-01-2015 19:51:24 System Checkpoint
    06-01-2015 19:53:00 System Checkpoint
    07-01-2015 21:28:00 System Checkpoint
    09-01-2015 12:05:39 System Checkpoint
    10-01-2015 13:02:52 System Checkpoint
    12-01-2015 11:42:55 System Checkpoint

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2004-08-10 12:51 - 2011-04-14 13:09 - 00236669 ____R C:\WINDOWS\system32\Drivers\etc\hosts
    127.0.0.1 localhost
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.1001-search.info
    127.0.0.1 1001-search.info
    127.0.0.1 www.100888290cs.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 www.10sek.com
    127.0.0.1 10sek.com
    127.0.0.1 www.123topsearch.com
    127.0.0.1 123topsearch.com
    127.0.0.1 www.132.com
    127.0.0.1 132.com
    127.0.0.1 www.136136.net
    127.0.0.1 136136.net
    127.0.0.1 www.139mm.com
    127.0.0.1 139mm.com
    127.0.0.1 www.163ns.com
    127.0.0.1 163ns.com

    There are 1000 more lines.


    ==================== Scheduled Tasks (whitelisted) =============


    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\At1.job => C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe
    Task: C:\WINDOWS\Tasks\At2.job => C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe
    Task: C:\WINDOWS\Tasks\At3.job => C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe
    Task: C:\WINDOWS\Tasks\At4.job => C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe
    Task: C:\WINDOWS\Tasks\TidyNetwork Update.job => C:\Documents and Settings\CINDY\Local Settings\Application Data\TidyNetwork\petnupdate.exe

    ==================== Loaded Modules (whitelisted) =============

    2007-03-19 20:53 - 2001-07-03 08:17 - 00024576 _____ () C:\Program Files\Hewlett-Packard\HP Share-to-Web\HPGS2WNFPS.DLL
    2011-10-14 13:25 - 2011-10-14 13:25 - 00111160 _____ () C:\Program Files\HP\StatusAlerts\bin\nativeutils.dll
    2007-03-19 20:53 - 2001-07-03 08:17 - 00065536 _____ () C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    2006-12-22 07:31 - 2006-12-22 07:31 - 00108712 _____ () C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00268648 _____ () C:\Program Files\Intuit\QuickBooks 2012\boost_regex-vc90-mt-p-1_33.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00020840 _____ () C:\Program Files\Intuit\QuickBooks 2012\QBCompressor.dll
    2011-08-19 20:30 - 2011-08-19 20:30 - 00059904 _____ () C:\Program Files\Intuit\QuickBooks 2012\zlib1.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00380264 _____ () C:\Program Files\Intuit\QuickBooks 2012\BackupLib.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00138088 _____ () C:\Program Files\Intuit\QuickBooks 2012\QBMAPILibrary.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00176488 _____ () C:\Program Files\Intuit\QuickBooks 2012\boost_serialization-vc90-mt-p-1_33.dll
    2011-12-06 12:40 - 2011-12-06 12:40 - 00042344 _____ () C:\Program Files\Intuit\QuickBooks 2012\mbpopup.dll
    2010-06-09 16:17 - 2010-06-09 16:17 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a48a409c\mscorlib.dll
    2010-06-09 16:17 - 2010-06-09 16:17 - 03018752 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_f2c234db\system.windows.forms.dll
    2010-06-09 16:17 - 2010-06-09 16:17 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7816f674\system.dll
    2010-06-09 16:17 - 2010-06-09 16:17 - 00835584 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_c139de23\system.drawing.dll
    2010-06-09 16:17 - 2010-06-09 16:17 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_743461ab\system.xml.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:02C228CC
    AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Intuit Data Protect.lnk => C:\WINDOWS\pss\Intuit Data Protect.lnkCommon Startup
    MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
    MSCONFIG\startupfolder: C:^Documents and Settings^CINDY^Start Menu^Programs^Startup^Calendar Creator Scheduler.lnk => C:\WINDOWS\pss\Calendar Creator Scheduler.lnkStartup
    MSCONFIG\startupfolder: C:^Documents and Settings^CINDY^Start Menu^Programs^Startup^OpenOffice.org 2.2.lnk => C:\WINDOWS\pss\OpenOffice.org 2.2.lnkStartup
    MSCONFIG\startupreg: Adobe Photo Downloader => "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    MSCONFIG\startupreg: DellSupport => "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    MSCONFIG\startupreg: dscactivate => "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    MSCONFIG\startupreg: HP Software Update => "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    MSCONFIG\startupreg: MSKDetectorExe => C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
    MSCONFIG\startupreg: mxomssmenu => "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
    MSCONFIG\startupreg: QBCMAgent => C:\Program Files\Intuit\QuickBooks Customer Manager\QBCMAgent.exe
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\qttask.exe" -atboottime
    MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    ========================= Accounts: ==========================

    Administrator (S-1-5-21-408940103-543640705-2808721970-500 - Administrator - Enabled)
    ASPNET (S-1-5-21-408940103-543640705-2808721970-1020 - Limited - Enabled)
    CINDY (S-1-5-21-408940103-543640705-2808721970-1007 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\CINDY
    DEVON (S-1-5-21-408940103-543640705-2808721970-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\DEVON
    Guest (S-1-5-21-408940103-543640705-2808721970-501 - Limited - Enabled)
    HelpAssistant (S-1-5-21-408940103-543640705-2808721970-1005 - Limited - Disabled)
    QBDataServiceUser19 (S-1-5-21-408940103-543640705-2808721970-1008 - Limited - Enabled) => %SystemDrive%\Documents and Settings\QBDataServiceUser19
    QBDataServiceUser22 (S-1-5-21-408940103-543640705-2808721970-1021 - Limited - Enabled) => %SystemDrive%\Documents and Settings\QBDataServiceUser22
    SUPPORT_388945a0 (S-1-5-21-408940103-543640705-2808721970-1002 - Limited - Disabled)

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/12/2015 07:15:45 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application ntvdm.exe, version 5.1.2600.2180, faulting module ntvdm.exe, version 5.1.2600.2180, fault address 0x0004fcdf.
    Processing media-specific event for [ntvdm.exe!ws!]

    Error: (01/12/2015 04:36:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks Pro 2012":
    LicenseUtility::`anonymous-namespace'::LicenseUtilityImp::getProductMode: Product mode not found

    Error: (01/12/2015 04:35:23 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    Returning NULL QBWinInstance Handle

    Error: (01/12/2015 04:35:23 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    Returning NULL QBWinInstance Handle

    Error: (01/12/2015 04:35:23 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    Returning NULL QBWinInstance Handle

    Error: (01/12/2015 04:33:50 PM) (Source: McLogEvent) (EventID: 5022) (User: NT AUTHORITY)
    Description: MCSCAN32 Engine Initialisation failed.
    Engine returned error : 1

    Error: (01/12/2015 04:10:48 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks Pro 2012":
    LicenseUtility::`anonymous-namespace'::LicenseUtilityImp::getProductMode: Product mode not found

    Error: (01/12/2015 04:10:22 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    QBDBPF Log Monitor Service seems is running but not listening on the required port

    Error: (01/12/2015 04:10:10 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    Returning NULL QBWinInstance Handle

    Error: (01/12/2015 04:10:10 PM) (Source: QuickBooks) (EventID: 4) (User: )
    Description: An unexpected error has occured in "QuickBooks":
    Returning NULL QBWinInstance Handle


    System errors:
    =============
    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126

    Error: (01/12/2015 09:58:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Application Management service terminated with the following error:
    %%126


    Microsoft Office Sessions:
    =========================
    Error: (05/18/2014 02:22:19 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12143 seconds with 540 seconds of active time. This session ended with a crash.

    Error: (03/27/2014 01:00:04 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 86447 seconds with 840 seconds of active time. This session ended with a crash.

    Error: (10/15/2013 11:53:53 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 7742 seconds with 840 seconds of active time. This session ended with a crash.

    Error: (09/30/2013 11:05:49 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 59 seconds with 0 seconds of active time. This session ended with a crash.

    Error: (09/30/2013 10:48:54 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 6884 seconds with 1980 seconds of active time. This session ended with a crash.

    Error: (08/16/2013 10:55:51 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 224 seconds with 180 seconds of active time. This session ended with a crash.

    Error: (08/16/2013 10:52:04 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 139 seconds with 60 seconds of active time. This session ended with a crash.

    Error: (08/16/2013 10:49:40 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 158 seconds with 120 seconds of active time. This session ended with a crash.

    Error: (08/16/2013 10:46:53 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 22, Application Name: Microsoft Expression Web, Application Version: 2008.1200.6329.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 4363 seconds with 1560 seconds of active time. This session ended with a crash.

    Error: (07/15/2013 10:56:33 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 4305 seconds with 1860 seconds of active time. This session ended with a crash.


    ==================== Memory info ===========================

    Processor: Intel(R) Pentium(R) D CPU 3.00GHz
    Percentage of memory in use: 66%
    Total physical RAM: 2046.09 MB
    Available physical RAM: 690.39 MB
    Total Pagefile: 3937.83 MB
    Available Pagefile: 2631.48 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1932.11 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:145.78 GB) (Free:25.02 GB) NTFS ==>[Drive with boot components (Windows XP)]
    Drive d: (20130218_1608) (CDROM) (Total:0.24 GB) (Free:0 GB) CDFS
    Drive f: (FreeAgent GoFlex Drive) (Fixed) (Total:931.51 GB) (Free:602.51 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 149 GB) (Disk ID: D0F4738C)
    Partition 1: (Not Active) - (Size=47 MB) - (Type=DE)
    Partition 2: (Active) - (Size=145.8 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=3.2 GB) - (Type=DB)

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 7E3D0894)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

    ==================== End Of Log ============================
     
  5. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Results of HijackThis. I'm running Malwarebytes now and then will run the Microsoft Malicious thing. I'm desperately trying to get this up so I can send out orders tomorrow (we have small online business). It won't let me run my Dazzle program either except when I first restart the computer and I can run one label before it stops.


    Logfile of Trend Micro HijackThis v2.0.5
    Scan saved at 11:07:10 PM, on 1/12/2015
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    FIREFOX: 34.0.5 (x86 en-US)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\HP\HPBDSService\HPBDSService.exe
    C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE
    C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Java\jre7\bin\jqs.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\Maxtor\Sync\SyncServices.exe
    C:\UPS\WSTD\WSTDMessaging.exe
    C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\UPS\WSTD\WSTDMessaging.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
    C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\HPZipm12.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\McAfee\MSC\mcuihost.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    F:\FRST.exe
    F:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=U162A&form=U162AHP
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.mocaflix.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O2 - BHO: MyWordTool - {45470599-8237-486D-87B5-E89CD6AED154} - C:\Documents and Settings\CINDY\Application Data\MyWordTool\temp.dat
    O2 - BHO: PETN - {6402BEC7-162A-4558-BE23-08AE4BBCB195} - C:\Documents and Settings\CINDY\Local Settings\Application Data\TidyNetwork\petn.dll (file missing)
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100421130906.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R300 Series on CINDYDELL] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P48 "Auto EPSON Stylus Photo R300 Series on CINDYDELL" /O20 "\\CINDYDELL\Printer5" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [StatusAlerts] "C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe" /enum:eek:n /alerts:eek:n /notifications:eek:n /fl:eek:n /fr:eek:n /appData:eek:n /tmcp:eek:n
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
    O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui
    O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\WINDOWS\system32\inf\rundll33.exe C:\WINDOWS\xccdf16_090131a.dll xccd16
    O4 - HKUS\S-1-5-21-408940103-543640705-2808721970-1021\..\Run: [DellSupport-] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser22')
    O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
    O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238510971578
    O16 - DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} (pmjpegaudioV4 Class) - http://192.168.15.102/JpegInstV4.cab
    O16 - DPF: {B9940246-4344-4D1B-BD82-DBAF7E657FF9} (AudioClient Control) - http://192.168.15.253/SysCamInst.cab
    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: intu-help-qb5 - {867FCB77-9823-4CD6-8210-D85F968D466F} - C:\Program Files\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: AutorunsDisabled - Invalid registry found
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP DS Service - Hewlett-Packard Company - C:\Program Files\HP\HPBDSService\HPBDSService.exe
    O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
    O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
    O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
    O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
    O23 - Service: QuestDns Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\QuestDns\questdns199.exe (file missing)
    O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~3\QBDBMgrN.exe
    O23 - Service: QuickBooksDB22 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUC2E1~1\QBDBMgrN.exe
    O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    --
    End of file - 13997 bytes
     
  6. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Ran this program and is showed infection by Tenga. I quarantined those files and restarted the computer. Also deleted the recycle bin just in case this might help. Log Malwarebytes produced is below.

    Unfortunately, this did not solve the internet problem and I had a few more errors. When the computer came back up I had these two errors:

    Win32N - 5.1.2600.131072 and then the option to click OK (which I did)

    and also this error message:

    HPStatusAlert encountered a problem and needs to close.

    Other than that the computer came up and Dazzle worked long enough to print one label and then wouldn't connect again. IE wouldn't bring up any web pages. I'm running the Microsoft Malicious program now.

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 1/12/2015
    Scan Time: 11:09:42 PM
    Logfile: MalwareLog.txt
    Administrator: Yes

    Version: 2.00.4.1028
    Malware Database: v2014.11.20.06
    Rootkit Database: v2014.11.18.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows XP Service Pack 2
    CPU: x86
    File System: NTFS
    User: CINDY

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 471876
    Time Elapsed: 47 min, 37 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)


    (end)
     
  7. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    When running our tools, you must always run these from your desktop, unless instructed otherwise.

    From the contents of your post, it seems that you have been the victim of a Backdoor.Trojan

    Backdoor.Trojan is a generic detection for a group of Trojan horse programs that open a back door and allow a remote attacker to have unauthorized access to the compromised computer.

    Please refer to the following article.

    http://www.dslreports.com/faq/10063

    We wont ask a member to reformat the computer, but you should have that in mind. If you still making financial transactions with your computer, I would suggest you contact all financial institutions you deal with and change your password using another computer.

    Please download ComboFix from Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    -----------------------------------------------------------​
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      -----------------------------------------------------------​
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link or this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      -----------------------------------------------------------​
    4. Close any open browsers.
    5. WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    6. Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    7. If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      • Double click on combofix.exe & follow the prompts.
      • Install the Recovery Console if prompted.
      • When finished, it will produce a report for you.
      • Please post the "C:\ComboFix.txt" .
      • **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
    Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
    Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.
     
  8. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Thank you for your help. I'm not able to get on the internet on this computer so I have to download the software from another computer and save it on a remote hard drive and then connect the hard drive to the infected computer and run from there or copy to the infected computer.

    Second, this computer was on a router connected to the computer I'm using now to do this and that I'm using for financial transactions. I changed all the passwords but I'm wondering how I would have gotten this virus and if it can transfer over to the other computer. The way we had it set up the uninfected computer could see the files on the infected one but not vice versa. The uninfected computer seems to be working fine.

    I can remove the files I need from the infected computer and buy a new one or try to wipe it out and start over but if I copy the files, will they be infected?

    I really appreciate your help/advice.
     
  9. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Before transferring files from this computer to the other, lets run these applications to know their status and attempt to restore your connection.

    The FRST.txt above was incompleted. Check the FRST.txt for more text and post it in your reply.
     
  10. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2015 02
    Ran by CINDY (administrator) on DARRYL on 13-01-2015 21:16:36
    Running from F:\
    Loaded Profiles: CINDY & QBDataServiceUser22 (Available profiles: DEVON & CINDY & QBDataServiceUser19 & QBDataServiceUser22)
    Platform: Microsoft Windows XP Home Edition Service Pack 2 (X86) OS Language: English (United States)
    Internet Explorer Version 8 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
    (brother Industries Ltd) C:\WINDOWS\system32\BRSVC01A.EXE
    (brother Industries Ltd) C:\WINDOWS\system32\BRSS01A.EXE
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    () C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
    (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
    (Seagate Technology LLC) C:\Program Files\Maxtor\Sync\SyncServices.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    (Microsoft Corporation) C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    (Intuit) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    (Intuit Inc.) C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
    (Memeo) C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
    (SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
    (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\realplay.exe
    (Sonic Solutions) C:\WINDOWS\system32\dla\tfswctrl.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
    () C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    (Adobe Systems, Inc.) C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    (Intuit Inc.) C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    (Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    (HP) C:\WINDOWS\system32\HPZipm12.exe
    (McAfee, Inc.) C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Intuit, Inc.) C:\PROGRA~1\Intuit\QUC2E1~1\QBDBMgrN.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SigmatelSysTrayApp] => C:\WINDOWS\stsystra.exe [339968 2005-03-22] (SigmaTel, Inc.)
    HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [139264 2005-06-17] (Intel Corporation)
    HKLM\...\Run: [DVDLauncher] => C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [53248 2005-02-23] (CyberLink Corp.)
    HKLM\...\Run: [RealTray] => C:\Program Files\Real\RealPlayer\RealPlay.exe [26112 2006-04-06] (RealNetworks, Inc.)
    HKLM\...\Run: [dla] => C:\WINDOWS\system32\dla\tfswctrl.exe [127035 2004-12-06] (Sonic Solutions)
    HKLM\...\Run: [Share-to-Web Namespace Daemon] => C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [57344 2001-07-03] (Hewlett-Packard)
    HKLM\...\Run: [Auto EPSON Stylus Photo R300 Series on CINDYDELL] => C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE [99776 2015-01-12] (SEIKO EPSON CORPORATION)
    HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM\...\Run: [StatusAlerts] => C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe [299008 2015-01-13] (Hewlett-Packard Company)
    HKLM\...\Run: [HP Component Manager] => C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)
    HKLM\...\Winlogon: [UIHost] logonui.exe No File
    HKLM\...\Policies\Explorer: [NoSetActiveDesktop] 0
    HKLM\...\Policies\Explorer: [NoCDBurning] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\system: [NoColorChoice] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\system: [NoSizeChoice] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\system: [NoVisualStyleChoice] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\Explorer: [NoBandCustomize] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\Explorer: [NoThemesTab] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\Policies\Explorer: [NoSetActiveDesktop] 0
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\...\MountPoints2: {0bda0a3b-d3a8-11da-8d60-806d6172696f} - D:\autorun.exe
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\...\Run: [DellSupport-] => "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    Lsa: [Notification Packages] scecli scecli scecli scecli
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
    ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
    ShortcutTarget: HP Image Zone Fast Start.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
    ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
    ShortcutTarget: Service Manager.lnk -> C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip Messaging Utility.lnk
    ShortcutTarget: UPS WorldShip Messaging Utility.lnk -> C:\UPS\WSTD\Support.exe ()
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk
    ShortcutTarget: UPS WorldShip PLD Reminder Utility.lnk -> C:\UPS\WSTD\wstdPldReminder.exe (UPS)
    Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
    ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-408940103-543640705-2808721970-1007\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc-rel&channel=us
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/dell?hl=en&client=dell-inc-rel&channel=us
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=U162A&form=U162AHP
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc-rel&channel=us
    HKU\S-1-5-21-408940103-543640705-2808721970-1007\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/dell?hl=en&client=dell-inc-rel&channel=us
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-inc-rel/en/side.html?channel=us
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-inc-rel/en/side.html?channel=us
    HKU\S-1-5-21-408940103-543640705-2808721970-1021\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc-rel&channel=us
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\.DEFAULT -> {2748A036-2B15-49D2-92A0-ED96EFBDC5C6} URL = http://www.questdns.com/?prt=QUESTDNS199&keywords={searchTerms}
    SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-408940103-543640705-2808721970-1007 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.bing.com/search?FORM=U162AD&PC=U162A&q={searchTerms}&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-408940103-543640705-2808721970-1007 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-408940103-543640705-2808721970-1021 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: PETN -> {6402BEC7-162A-4558-BE23-08AE4BBCB195} -> C:\Documents and Settings\CINDY\Local Settings\Application Data\TidyNetwork\petn.dll No File
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100421130906.dll (McAfee, Inc.)
    BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll No File
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    Toolbar: HKU\S-1-5-21-408940103-543640705-2808721970-1007 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
    Toolbar: HKU\S-1-5-21-408940103-543640705-2808721970-1021 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238510971578
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {B8E53531-F29E-4180-AE3E-DF485CC8BE32} http://192.168.15.102/JpegInstV4.cab
    DPF: {B9940246-4344-4D1B-BD82-DBAF7E657FF9} http://192.168.15.253/SysCamInst.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
    Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
    Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
    ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
    ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
    Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

    FireFox:
    ========
    FF ProfilePath: C:\Documents and Settings\CINDY\Application Data\Mozilla\Firefox\Profiles\brxef38m.cindy
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
    FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
    FF Extension: MyWordTool - C:\Documents and Settings\CINDY\Application Data\Mozilla\Firefox\Profiles\08yl3tot.default-1380764227468\Extensions\[email protected] [2013-11-29]

    Chrome:
    =======
    CHR HKLM\...\Chrome\Extension: [ikjmhpoenoohdhnnikiddfholhdfmoob] - C:\Documents and Settings\All Users\Application Data\SaveAs\ikjmhpoenoohdhnnikiddfholhdfmoob.crx [Not Found]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-10-14] (SUPERAntiSpyware.com)
    R2 AdobeActiveFileMonitor5.0; C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe [108712 2006-12-22] ()
    R2 Brother XP spl Service; C:\WINDOWS\system32\brsvc01a.exe [57344 2001-11-23] (brother Industries Ltd)
    R2 HP DS Service; C:\Program Files\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [File not signed]
    S2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [167936 2015-01-13] (HP) [File not signed]
    R2 IAANTMon; C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [86140 2005-06-17] (Intel Corporation) [File not signed]
    R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [161768 2012-09-24] (Oracle Corporation)
    R2 Maxtor Sync Service; C:\Program Files\Maxtor\Sync\SyncServices.exe [156976 2007-09-28] (Seagate Technology LLC)
    R2 mcmscsvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [271480 2009-12-14] (McAfee, Inc.)
    R2 McNASvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [271480 2009-12-14] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [271480 2009-12-14] (McAfee, Inc.)
    R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [170144 2010-01-05] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [188136 2010-01-05] (McAfee, Inc.)
    R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [141792 2010-01-05] (McAfee, Inc.)
    R2 MSSQL$UPSWSDBSERVER; C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe [9158656 2008-12-18] (Microsoft Corporation)
    R3 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [65536 2004-03-18] (HP) [File not signed]
    R2 QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2011-12-06] (Intuit) [File not signed]
    R2 QBVSS; C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2011-08-19] (Intuit Inc.) [File not signed]
    R3 QuickBooksDB22; C:\Program Files\Intuit\QuickBooks 2012\QBDBMgrN.exe [683520 2015-01-13] (Intuit, Inc.) [File not signed]
    R2 SeagateDashboardService; C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [14088 2010-04-30] (Memeo)
    R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
    S2 uploadmgr; C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38912 2004-08-04] (Microsoft Corporation)
    S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [X]
    S4 ClipSrv; %SystemRoot%\system32\clipsrv.exe [X]
    S4 clr_optimization_v2.0.50727_32; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [X]
    S3 COMSysApp; C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    S2 McAfee SiteAdvisor Service; "C:\Program Files\McAfee\SiteAdvisor\McSACore.exe" [X]
    S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [X]
    S4 NetDDE; %SystemRoot%\system32\netdde.exe [X]
    S4 NetDDEdsdm; %SystemRoot%\system32\netdde.exe [X]
    S3 ose; "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [X]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S4 abp480n5; C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
    R2 ASCTRM; C:\WINDOWS\system32\Drivers\ASCTRM.sys [8552 2006-04-06] (Windows (R) 2000 DDK provider) [File not signed]
    S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [55456 2010-01-05] (McAfee, Inc.)
    R0 drvmcdb; C:\WINDOWS\System32\drivers\drvmcdb.sys [87488 2004-12-01] (Sonic Solutions) [File not signed]
    R2 drvnddm; C:\WINDOWS\System32\drivers\drvnddm.sys [40480 2004-11-23] (Sonic Solutions) [File not signed]
    S3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) [File not signed]
    S3 gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [85969 2009-02-13] (GMER) [File not signed]
    R3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51088 2004-06-22] (HP)
    R3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2004-06-22] (HP)
    R3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2004-06-22] (HP)
    R3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [95568 2010-01-05] (McAfee, Inc.)
    R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [152320 2010-01-05] (McAfee, Inc.)
    R3 mfebopk; C:\WINDOWS\System32\drivers\mfebopk.sys [51688 2010-01-05] (McAfee, Inc.)
    R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [312584 2010-01-05] (McAfee, Inc.)
    R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [385536 2010-01-05] (McAfee, Inc.)
    S3 mfendisk; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [88480 2010-01-05] (McAfee, Inc.)
    R3 mfendiskmp; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [88480 2010-01-05] (McAfee, Inc.)
    S3 mferkdet; C:\WINDOWS\System32\drivers\mferkdet.sys [83496 2010-01-05] (McAfee, Inc.)
    S3 mferkdk; C:\WINDOWS\System32\drivers\mferkdk.sys [34216 2009-01-16] (McAfee, Inc.)
    R1 mfetdi2k; C:\WINDOWS\System32\drivers\mfetdi2k.sys [82952 2010-01-05] (McAfee, Inc.)
    S3 MXOPSWD; C:\WINDOWS\System32\DRIVERS\mxopswd.sys [22152 2007-05-03] (Maxtor Corp.)
    R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20640 2005-04-25] (Sonic Solutions) [File not signed]
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 sscdbhk5; C:\WINDOWS\System32\drivers\sscdbhk5.sys [5627 2004-07-14] (Sonic Solutions) [File not signed]
    R1 ssrtln; C:\WINDOWS\System32\drivers\ssrtln.sys [23545 2004-07-14] (Sonic Solutions) [File not signed]
    R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1047816 2005-11-16] (SigmaTel, Inc.)
    R2 tfsnboio; C:\WINDOWS\System32\dla\tfsnboio.sys [25883 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsncofs; C:\WINDOWS\System32\dla\tfsncofs.sys [34843 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsndrct; C:\WINDOWS\System32\dla\tfsndrct.sys [4123 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsndres; C:\WINDOWS\System32\dla\tfsndres.sys [2239 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsnifs; C:\WINDOWS\System32\dla\tfsnifs.sys [86586 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsnopio; C:\WINDOWS\System32\dla\tfsnopio.sys [15227 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsnpool; C:\WINDOWS\System32\dla\tfsnpool.sys [6363 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsnudf; C:\WINDOWS\System32\dla\tfsnudf.sys [98714 2004-12-06] (Sonic Solutions) [File not signed]
    R2 tfsnudfa; C:\WINDOWS\System32\dla\tfsnudfa.sys [100603 2004-12-06] (Sonic Solutions) [File not signed]
    S4 31bc8770; \SystemRoot\System32\drivers\31bc8770.sys [X]
    U3 mfeavfk01; No ImagePath
    U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96256 2004-08-04] (Microsoft Corporation)
    S3 wanatw; system32\DRIVERS\wanatw4.sys [X]
    U1 WS2IFSL; No ImagePath

    ==================== NetSvcs (Whitelisted) ===================


    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-01-13 00:38 - 2015-01-13 11:47 - 00000000 ____D () C:\AdwCleaner
    2015-01-12 23:44 - 2015-01-12 23:44 - 00000000 ____D () C:\WINDOWS\ERUNT
    2015-01-12 23:09 - 2015-01-12 23:09 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-01-12 23:09 - 2015-01-12 23:09 - 00000818 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    2015-01-12 23:09 - 2015-01-12 23:09 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-01-12 23:08 - 2015-01-12 23:08 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
    2015-01-12 23:08 - 2014-11-21 06:14 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-01-12 23:08 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-01-12 23:06 - 2015-01-13 21:16 - 00000000 ____D () C:\FRST
    2015-01-12 19:18 - 2015-01-12 19:19 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
    2015-01-12 18:23 - 2015-01-13 11:53 - 00000243 _____ () C:\Documents and Settings\CINDY\dl.exe
    2015-01-12 16:31 - 2015-01-12 16:31 - 00003471 _____ () C:\Documents and Settings\CINDY\reset.log
    2015-01-07 22:41 - 2015-01-07 22:41 - 00010785 _____ () C:\Documents and Settings\CINDY\My Documents\SalesTax4thQuarter2014.xlsx
    2015-01-07 22:41 - 2015-01-07 22:41 - 00000165 ____H () C:\Documents and Settings\CINDY\My Documents\~$SalesTax4thQuarter2014.xlsx
    2015-01-06 17:07 - 2015-01-06 17:07 - 00000000 ____D () C:\Documents and Settings\CINDY\Application Data\Oracle
    2015-01-06 16:44 - 2015-01-06 16:44 - 00002368 _____ () C:\Documents and Settings\CINDY\Desktop\DCS-930L(70957001).lnk
    2015-01-06 16:27 - 2015-01-06 16:34 - 00000000 ____D () C:\DLink
    2014-12-31 12:27 - 2014-12-31 12:27 - 00005895 _____ () C:\PriorityMailPackageLost.htm

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-01-13 21:18 - 2012-05-27 20:37 - 00000000 ____D () C:\Documents and Settings\QBDataServiceUser22\Local Settings\Temp
    2015-01-13 21:17 - 2006-05-03 20:26 - 00000000 ____D () C:\Documents and Settings\CINDY\Local Settings\Temp
    2015-01-13 21:16 - 2012-05-28 10:42 - 00000369 _____ () C:\International Gold Chain.QBW.DSN
    2015-01-13 21:16 - 2009-06-01 10:51 - 00000398 _____ () C:\International Gold Chain.QBW.ND
    2015-01-13 21:16 - 2009-06-01 10:50 - 82485248 _____ () C:\International Gold Chain.QBW
    2015-01-13 21:16 - 2007-10-14 13:31 - 64356352 _____ () C:\International Gold Chain.QBW.TLG
    2015-01-13 20:45 - 2012-11-21 16:13 - 00000374 _____ () C:\WINDOWS\Tasks\At2.job
    2015-01-13 19:08 - 2004-08-10 13:02 - 01791052 _____ () C:\WINDOWS\WindowsUpdate.log
    2015-01-13 16:13 - 2012-11-21 16:13 - 00000374 _____ () C:\WINDOWS\Tasks\At3.job
    2015-01-13 14:30 - 2012-11-21 16:13 - 00000374 _____ () C:\WINDOWS\Tasks\At4.job
    2015-01-13 14:25 - 2006-04-24 11:05 - 108220928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2015-01-13 11:50 - 2007-10-14 16:36 - 00000242 _____ () C:\WINDOWS\wstdUPSWSHIP.INI
    2015-01-13 11:49 - 2004-08-10 13:08 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
    2015-01-13 11:49 - 2004-08-10 12:59 - 00000159 _____ () C:\WINDOWS\wiadebug.log
    2015-01-13 11:49 - 2004-08-10 12:59 - 00000000 _____ () C:\WINDOWS\wiaservc.log
    2015-01-13 11:48 - 2006-05-03 20:26 - 00000278 ___SH () C:\Documents and Settings\CINDY\ntuser.ini
    2015-01-13 11:48 - 2006-05-03 20:26 - 00000000 ____D () C:\Documents and Settings\CINDY
    2015-01-13 11:48 - 2004-08-10 13:08 - 00032524 _____ () C:\WINDOWS\SchedLgU.Txt
    2015-01-13 11:39 - 2010-07-14 16:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2229593$
    2015-01-13 11:38 - 2010-05-25 19:19 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB981793$
    2015-01-13 11:38 - 2010-04-15 15:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB979683$
    2015-01-13 11:38 - 2010-03-11 03:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB975561$
    2015-01-13 11:38 - 2010-02-24 17:05 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB979306$
    2015-01-13 11:38 - 2010-02-10 19:53 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB978706$
    2015-01-13 11:38 - 2010-02-10 19:52 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB977165$
    2015-01-13 11:38 - 2009-11-26 01:07 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB976098-v2$
    2015-01-13 11:38 - 2009-10-16 02:00 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB971486$
    2015-01-13 11:38 - 2009-08-26 18:15 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB970653-v3$
    2015-01-13 11:38 - 2009-08-12 15:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB960859$
    2015-01-13 11:38 - 2009-08-07 16:21 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB925720$
    2015-01-13 11:38 - 2009-04-15 16:12 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956572$
    2015-01-13 11:38 - 2009-04-15 16:11 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB923561$
    2015-01-13 11:38 - 2008-12-10 03:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB955839$
    2015-01-13 11:38 - 2008-12-10 03:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB952069_WM9$
    2015-01-13 11:38 - 2008-10-17 02:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB956841$
    2015-01-13 11:38 - 2008-08-13 15:38 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB951072-v2$
    2015-01-13 11:38 - 2008-03-24 11:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB939683$
    2015-01-13 11:38 - 2008-03-21 15:25 - 00000000 __HDC () C:\WINDOWS\$NtUninstallwmp11$
    2015-01-13 11:38 - 2008-03-21 15:24 - 00000000 __HDC () C:\WINDOWS\$NtUninstallWMFDist11$
    2015-01-13 11:38 - 2007-12-12 18:46 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942763$
    2015-01-13 11:38 - 2007-08-29 21:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB933360$
    2015-01-13 11:38 - 2007-08-15 02:02 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB938828$
    2015-01-13 11:38 - 2007-04-11 12:27 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB931784$
    2015-01-13 11:38 - 2007-03-16 02:00 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB929338$
    2015-01-13 11:38 - 2007-02-18 22:12 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB923723$
    2015-01-13 11:38 - 2006-12-17 03:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB925454$
    2015-01-13 11:38 - 2006-11-18 08:16 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB920213$
    2015-01-13 11:38 - 2006-11-18 08:15 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB922760$
    2015-01-13 11:38 - 2006-09-27 16:21 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB918899$
    2015-01-13 11:38 - 2006-09-27 16:18 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB922582$
    2015-01-13 11:38 - 2006-04-24 11:04 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB912812$
    2015-01-13 11:38 - 2006-04-24 11:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB898458$
    2015-01-13 11:38 - 2006-04-24 11:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB896428$
    2015-01-13 11:38 - 2006-04-24 11:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB896358$
    2015-01-13 11:37 - 2009-08-20 08:31 - 00000000 __HDC () C:\WINDOWS\ie8
    2015-01-13 11:37 - 2007-01-02 10:14 - 00000000 __HDC () C:\WINDOWS\ie7
    2015-01-13 11:37 - 2004-08-10 13:09 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
    2015-01-13 11:37 - 2004-08-10 12:52 - 00000000 ____D () C:\WINDOWS\msagent
    2015-01-13 11:36 - 2011-01-09 19:46 - 00000000 ____D () C:\WINDOWS\SQLTools9_KB970892_ENU
    2015-01-13 11:36 - 2011-01-09 19:44 - 00000000 ____D () C:\WINDOWS\SQL9_KB970892_ENU
    2015-01-13 11:36 - 2006-06-07 13:17 - 00000000 ____D () C:\WINDOWS\speech
    2015-01-13 11:36 - 2006-04-06 10:12 - 00000000 ____D () C:\WINDOWS\system32\dla
    2015-01-13 11:35 - 2009-08-06 15:34 - 00000000 ____D () C:\WINDOWS\system32\XPSViewer
    2015-01-13 11:35 - 2008-10-03 15:32 - 00000000 ____D () C:\ZUD55725
    2015-01-13 11:35 - 2007-10-15 09:55 - 00000000 ____D () C:\ZUD55721
    2015-01-13 11:35 - 2004-08-10 13:09 - 00000000 ____D () C:\WINDOWS\system32\URTTemp
    2015-01-13 11:35 - 2004-08-10 13:02 - 00000000 ____D () C:\WINDOWS\system32\Restore
    2015-01-13 11:35 - 2004-08-10 12:52 - 00000000 ____D () C:\WINDOWS\system32\usmt
    2015-01-13 11:35 - 2004-08-10 12:52 - 00000000 ____D () C:\WINDOWS\system32\npp
    2015-01-13 10:15 - 2012-11-21 16:13 - 00000374 _____ () C:\WINDOWS\Tasks\At1.job
    2015-01-13 02:46 - 2004-08-10 12:51 - 00135376 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
    2015-01-13 00:03 - 2009-01-14 16:55 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB958687$
    2015-01-13 00:02 - 2014-07-03 23:04 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
    2015-01-13 00:02 - 2014-04-11 10:53 - 00000000 ____D () C:\Program Files\iTunes
    2015-01-13 00:02 - 2014-04-11 10:53 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
    2015-01-13 00:02 - 2014-04-11 10:52 - 00000000 ____D () C:\Program Files\Apple Software Update
    2015-01-13 00:02 - 2013-02-11 18:28 - 00000000 ____D () C:\Program Files\GPLGS
    2015-01-13 00:02 - 2011-10-06 09:57 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2015-01-13 00:02 - 2009-08-21 13:17 - 00000000 ____D () C:\Program Files\ACT
    2015-01-13 00:02 - 2009-07-24 12:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
    2015-01-13 00:02 - 2009-07-16 12:24 - 00000000 ____D () C:\Program Files\QuickTime
    2015-01-13 00:02 - 2009-05-26 10:01 - 00000000 ____D () C:\Program Files\Graboid
    2015-01-13 00:02 - 2009-03-31 09:51 - 00000000 ____D () C:\Program Files\Windows Live Safety Center
    2015-01-13 00:02 - 2008-10-04 22:03 - 00000000 ____D () C:\Documents and Settings\CINDY\Brhlxp03
    2015-01-13 00:02 - 2008-03-21 15:25 - 00000000 ____D () C:\Program Files\Windows Media Connect 2
    2015-01-13 00:02 - 2007-04-08 08:00 - 00000000 ____D () C:\Program Files\DellSupport
    2015-01-13 00:02 - 2007-01-24 08:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
    2015-01-13 00:02 - 2006-12-22 15:07 - 00000000 ____D () C:\Program Files\PhotoParade
    2015-01-13 00:02 - 2006-12-13 07:35 - 00000000 ____D () C:\Program Files\EPSON Print CD
    2015-01-13 00:02 - 2006-09-16 01:08 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy
    2015-01-13 00:02 - 2006-04-06 10:09 - 00000000 ____D () C:\Program Files\Microsoft Plus! Photo Story 2 LE
    2015-01-13 00:02 - 2006-04-06 10:09 - 00000000 ____D () C:\Program Files\Microsoft Plus! Digital Media Edition
    2015-01-13 00:02 - 2004-08-10 13:02 - 00000000 ____D () C:\Program Files\Outlook Express
    2015-01-13 00:02 - 2004-08-10 13:02 - 00000000 ____D () C:\Program Files\NetMeeting
    2015-01-13 00:02 - 2004-08-10 13:02 - 00000000 ____D () C:\Program Files\Movie Maker
    2015-01-13 00:02 - 2004-08-10 13:01 - 00000000 ____D () C:\WINDOWS\system32\Com
    2015-01-13 00:02 - 2004-08-10 13:01 - 00000000 ____D () C:\Program Files\Windows NT
    2015-01-13 00:02 - 2004-08-10 13:01 - 00000000 ____D () C:\Program Files\Messenger
    2015-01-12 23:08 - 2011-08-04 15:17 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2015-01-12 23:05 - 2009-03-31 13:06 - 00001392 _____ () C:\Documents and Settings\CINDY\Desktop\McAfee Virtual Technician.lnk
    2015-01-12 23:03 - 2009-04-01 09:02 - 00762504 _____ () C:\WINDOWS\setupapi.log
    2015-01-12 19:37 - 2004-08-10 13:02 - 00046924 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-01-12 19:37 - 2004-08-10 12:51 - 00111448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
    2015-01-12 19:36 - 2011-12-30 14:32 - 00113152 _____ (Sonic Solutions) C:\WINDOWS\system32\pxinsi64.exe
    2015-01-12 19:36 - 2011-12-30 14:32 - 00112128 _____ (Sonic Solutions) C:\WINDOWS\system32\pxcpyi64.exe
    2015-01-12 19:36 - 2009-12-18 20:55 - 00024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
    2015-01-12 19:36 - 2004-08-10 13:01 - 00138704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sndvol32.exe
    2015-01-12 19:36 - 2004-08-10 12:51 - 00033072 _____ (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
    2015-01-12 19:36 - 2004-08-10 12:51 - 00031224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
    2015-01-12 19:36 - 2004-08-10 12:51 - 00011496 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvr32.exe
    2015-01-12 19:35 - 2009-12-18 20:55 - 00227800 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmiprvse.exe
    2015-01-12 19:35 - 2009-12-18 20:55 - 00215496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wordpad.exe
    2015-01-12 19:35 - 2009-12-18 20:55 - 00049744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\utilman.exe
    2015-01-12 19:35 - 2007-03-15 17:17 - 00327056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\WgaTray.exe
    2015-01-12 19:35 - 2004-08-10 13:02 - 00063876 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wmplayer.exe
    2015-01-12 19:35 - 2004-08-10 13:02 - 00046924 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wuauclt.exe
    2015-01-12 19:35 - 2004-08-10 12:51 - 00317242 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\unregmp2.exe
    2015-01-12 19:35 - 2004-08-10 12:51 - 00215136 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
    2015-01-12 19:35 - 2004-08-10 12:51 - 00072608 _____ (Microsoft Corporation) C:\WINDOWS\system32\magnify.exe
    2015-01-12 19:35 - 2004-08-10 12:51 - 00045126 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
    2015-01-12 19:34 - 2010-07-14 11:51 - 00743712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\helpsvc.exe
    2015-01-12 19:34 - 2010-03-10 09:31 - 03555016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\moviemk.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 02143544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 02063660 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 02021750 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ntkrpamp.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 01032992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\explorer.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00388272 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00256328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agentsvr.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00215136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\osk.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00186976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpcount.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00185616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cfgwiz.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00110512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\services.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00108784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98swin.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00075880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\telnet.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00072608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\magnify.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00053728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\narrator.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00029032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tcptest.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00023000 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fltmc.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00017768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpremadm.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00014156 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98sadm.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00013640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shtml.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00013608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\author.exe
    2015-01-12 19:34 - 2009-12-18 20:55 - 00013608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admin.exe
    2015-01-12 19:34 - 2009-12-16 07:58 - 00342752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mspaint.exe
    2015-01-12 19:34 - 2009-08-06 15:33 - 00597144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
    2015-01-12 19:34 - 2009-04-15 08:33 - 00034848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sc.exe
    2015-01-12 19:34 - 2007-05-09 15:47 - 00013406 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieudinit.exe
    2015-01-12 19:34 - 2006-11-07 03:26 - 00172732 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
    2015-01-12 19:34 - 2006-10-17 12:04 - 00632580 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iexplore.exe
    2015-01-12 19:34 - 2006-10-17 11:56 - 00045126 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshta.exe
    2015-01-12 19:34 - 2006-06-23 03:48 - 00068850 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedw.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00480144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintsetp.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00454792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintsetp.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00307608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsv.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00305008 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00259504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputy.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00232768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjprw.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00206768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpmig.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00205132 _____ () C:\WINDOWS\system32\dllcache\imjpinst.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00152208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdsvr.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00070056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlphr.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00067000 _____ () C:\WINDOWS\system32\dllcache\imscinst.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00059664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imkrinst.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00055040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cplexe.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00054456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdadm.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00043800 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmig.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00043728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlphr.exe
    2015-01-12 19:34 - 2006-05-10 11:24 - 00042248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpuex.exe
    2015-01-12 19:34 - 2004-08-10 13:02 - 01668926 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\setup_wm.exe
    2015-01-12 19:34 - 2004-08-10 13:02 - 00988128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\migrate.exe
    2015-01-12 19:34 - 2004-08-10 13:02 - 00039920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msinfo32.exe
    2015-01-12 19:34 - 2004-08-10 13:01 - 00114528 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
    2015-01-12 19:34 - 2004-08-10 12:51 - 00100430 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllcache\logagent.exe
    2015-01-12 19:34 - 2004-08-10 12:51 - 00014976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ctfmon.exe
    2015-01-12 19:34 - 2004-08-10 12:50 - 00019320 _____ (Microsoft Corporation) C:\WINDOWS\system32\arp.exe
    2015-01-12 19:34 - 2004-08-10 12:50 - 00011248 _____ (Microsoft Corporation) C:\WINDOWS\system32\chkntfs.exe
    2015-01-12 19:34 - 2004-08-10 12:50 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
    2015-01-12 19:34 - 2004-08-10 12:50 - 00007768 _____ (Microsoft Corporation) C:\WINDOWS\system32\control.exe
    2015-01-12 17:43 - 2013-08-07 20:08 - 00053760 ___SH () C:\Documents and Settings\CINDY\My Documents\Thumbs.db
    2015-01-12 16:34 - 2004-08-10 12:51 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
    2015-01-12 15:36 - 2013-01-19 18:06 - 00000000 ____D () C:\Documents and Settings\CINDY\Desktop\Old Firefox Data
    2015-01-10 15:02 - 2012-05-28 12:10 - 00000000 ____D () C:\QuickBooksAutoDataRecovery
    2015-01-09 14:37 - 2009-08-06 13:00 - 21626880 ____R () C:\ChristmansTreeWreaths.QBW
    2015-01-09 14:37 - 2009-08-06 13:00 - 00000368 _____ () C:\ChristmansTreeWreaths.QBW.ND
    2015-01-09 14:37 - 2008-10-13 14:27 - 72876032 ____R () C:\ChristmansTreeWreaths.QBW.TLG
    2015-01-09 14:35 - 2012-07-17 09:56 - 00000369 _____ () C:\ChristmansTreeWreaths.QBW.DSN
    2015-01-06 11:17 - 2012-05-28 12:02 - 00000360 _____ () C:\BeadingUSAcom.QBW.ND
    2015-01-06 11:17 - 2009-05-31 21:53 - 45387776 ____R () C:\BeadingUSAcom.QBW
    2015-01-06 11:17 - 2007-10-14 13:32 - 24182784 ____R () C:\BeadingUSAcom.QBW.TLG
    2015-01-05 14:38 - 2012-05-28 12:02 - 00000369 _____ () C:\BeadingUSAcom.QBW.DSN
    2015-01-04 21:17 - 2011-04-25 17:17 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat
    2014-12-29 21:30 - 2014-12-10 16:38 - 00000000 ____D () C:\LoanDocsDec2014
    2014-12-16 18:09 - 2009-06-01 08:41 - 00000362 _____ () C:\Charmcountrycom.QBW.ND
    2014-12-16 18:09 - 2009-06-01 08:40 - 64294912 ____R () C:\Charmcountrycom.QBW
    2014-12-16 18:09 - 2007-10-14 13:32 - 16252928 ____R () C:\Charmcountrycom.QBW.TLG
    2014-12-16 12:59 - 2012-05-31 15:14 - 00000369 _____ () C:\Charmcountrycom.QBW.DSN

    Files to move or delete:
    ====================
    C:\Documents and Settings\CINDY\dl.exe
    C:\Documents and Settings\CINDY\WSSEMAPHORES.dat
    C:\Documents and Settings\DEVON\WSSEMAPHORES.dat
    C:\Windows\Tasks\At1.job
    C:\Windows\Tasks\At2.job
    C:\Windows\Tasks\At3.job
    C:\Windows\Tasks\At4.job


    Some content of TEMP:
    ====================
    C:\Documents and Settings\CINDY\Local Settings\Temp\dblgen11.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\dblgen8.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\dblib8.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\Intuit.Spc.Map.EntitlementClient.Install.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\MFC71.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\msvcp71.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\msvcr71.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\QBFirwal.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\qbinstal.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\Quarantine.exe
    C:\Documents and Settings\CINDY\Local Settings\Temp\Setup.exe
    C:\Documents and Settings\CINDY\Local Settings\Temp\sqlite3.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\stlport_vc746.dll
    C:\Documents and Settings\CINDY\Local Settings\Temp\StopQBServer.dll


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe
    [2009-12-18 20:55] - [2015-01-12 19:36] - 0024416 ____A (Microsoft Corporation) 09e2d2ec83f83b59691de3cb283c9bbf

    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    ==================== End Of Log ============================
     
  11. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Users shortcut scan result (x86) Version: 12-01-2015 02
    Ran by CINDY at 2015-01-13 21:22:08
    Running from F:\
    Boot Mode: Normal
    ==================== Shortcuts =============================
    (The entries could be listed to be restored or removed.)



    Shortcut: C:\Documents and Settings\All Users\Start Menu\HP Image Zone.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\HP Director.lnk -> C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk -> C:\WINDOWS\system32\wupdmgr.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Help Center.lnk -> C:\Program Files\Adobe\Adobe Help Center\ahc.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop Album Starter Edition 3.2.lnk -> C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\Photoshop Album Starter Edition.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop Elements 5.0.lnk -> C:\Program Files\Adobe\Photoshop Elements 5.0\Photoshop Elements 5.0.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk -> C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk -> C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\I.R.I.S. OCR Registration.lnk -> C:\Program Files\HP\Digital Imaging\DocProc\regipe.exe (I.R.I.S. SA)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Plus! Photo Story 2 LE.lnk -> C:\Program Files\Microsoft Plus! Photo Story 2 LE\PS2Trial.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk -> C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PowerDVD.lnk -> C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe (CyberLink Corp.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware Alternate Start.lnk -> C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk -> C:\Program Files\Messenger\msmsgs.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk -> C:\Program Files\Movie Maker\moviemk.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files\VideoLAN\VLC\Documentation.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files\VideoLAN\VLC\NEWS.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files\VideoLAN\VLC\VideoLAN Website.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\UPS\UPS WorldShip Support Utility.lnk -> C:\UPS\WSTD\wstdSupport.exe (United Parcel Service, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\UPS\UPS WorldShip Uninstall.lnk -> C:\UPS\WSTD\Uninstall\Uninstall.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\UPS\UPS WorldShip.lnk -> C:\UPS\WSTD\WorldShipTD.exe (UPS)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\ReadMe.lnk -> C:\Tax Forms Helper 2011\Readme.exe (EC Software)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\Tax Forms Helper 2011.lnk -> C:\Tax Forms Helper 2011\TFH.exe (Adams, a division of TOPS)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\TFH 2011 Directory.lnk -> C:\Tax Forms Helper 2011 ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\TFH 2011 Help.lnk -> C:\Tax Forms Helper 2011\TFH_Help.exe (EC Software)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\Uninstall TFH.lnk -> C:\Tax Forms Helper 2011\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1098 IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1098.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1098T IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1098t.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099 General IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099gi.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099-DIV IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099div.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099-INT IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099int.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099-MISC IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099msc.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099-R IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099r.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\1099-S IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\i1099s.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\2011 IRS Instructions\W-2 & W-3 IRS Instructions.lnk -> C:\Tax Forms Helper 2011\Tax Files\iw2w3.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware\BootSafe.lnk -> C:\Program Files\SUPERAntiSpyware\BootSafe.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Free Edition.lnk -> C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Help.lnk -> C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip Messaging Utility.lnk -> C:\UPS\WSTD\Support.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk -> C:\UPS\WSTD\wstdPldReminder.exe (UPS)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SourceTec\Sothink DHTMLMenu\DHTMLMenu Converting Wizard.lnk -> C:\Program Files\SourceTec\Sothink DHTMLMenu\DMENUConv.exe (SourceTec)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SourceTec\Sothink DHTMLMenu\Sothink DHTMLMenu.lnk -> C:\Program Files\SourceTec\Sothink DHTMLMenu\dhtmlmenu.exe (SourceTec)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SourceTec\Sothink DHTMLMenu\Uninstall Sothink DHTMLMenu.lnk -> C:\Program Files\SourceTec\Sothink DHTMLMenu\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Vegas Movie Studio Platinum 6.0\Vegas Movie Studio Platinum 6.0 Readme.lnk -> C:\Program Files\Sony\Vegas Movie Studio Platinum 6.0\Readme\Vegas_readme.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Vegas Movie Studio Platinum 6.0\Vegas Movie Studio Platinum 6.0.lnk -> C:\Program Files\Sony\Vegas Movie Studio Platinum 6.0\VegasMovieStudioPE60.exe (Madison Media Software, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Vegas Movie Studio Platinum 6.0\Video Capture 6.0 Readme.lnk -> C:\Program Files\Sony\Vegas Movie Studio Platinum 6.0\Readme\Videocapture_readme.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Migration Tool Readme.lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\SF2Sony_readme.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\DVD Architect Studio 3.0\DVD Architect Studio 3.0 Readme.lnk -> C:\Program Files\Sony\DVD Architect Studio 3.0\Readme\DVD Architect_readme.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\DVD Architect Studio 3.0\DVD Architect Studio 3.0.lnk -> C:\Program Files\Sony\DVD Architect Studio 3.0\dvdarchst30.exe (Madison Media Software, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\DigitalMedia Home.lnk -> C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\DLA\DLA Help.lnk -> C:\Program Files\Sonic\DLA\vxdla.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Shipstream Manager\Shipstream Manager Getting Started Guide.lnk -> C:\Program Files\Pitney Bowes\PBship\Getting Started with Shipstream Manager.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Shipstream Manager\Shipstream Manager How to Guide.lnk -> C:\Program Files\Pitney Bowes\PBship\How To Use Shipstream Manager.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Shipstream Manager\Shipstream Manager Read Me.lnk -> C:\Program Files\Pitney Bowes\PBship\README.TXT ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Shipstream Manager\Shipstream Manager.lnk -> C:\Program Files\Pitney Bowes\PBship\PBSHIP.EXE (Pitney Bowes)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\License Agreement.lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\EULA.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\Multi-Langauge Site.lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\Help\Multi-Language.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\ReadMe.lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\ReadMe_1st.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\RezEasy Mobile.lnk -> C:\Program Files\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\rez60mobile.exe (Hallisoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\RezEasy.lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\rez60std.exe (Hallisoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\Set Permissions (Vista,7).lnk -> F:\Hallisoft\RezEasy_6\rez_std_set.bat ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\Unistall RezEasy.lnk -> F:\ZSUninstal.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\User Manual (HTML).lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\Help\rezeasy_7_std.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RezEasy Standard\User Manual PDF (Printable).lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\Help\Rezeasy_7_Std.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer Help.lnk -> C:\Program Files\Real\RealPlayer\realplay.hlp ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer License Agreement.lnk -> C:\Program Files\Real\RealPlayer\playrlic.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer ReadMe.lnk -> C:\Program Files\Real\RealPlayer\Readme.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer Setup.lnk -> C:\Program Files\Real\RealPlayer\Setup\setup.exe (RealNetworks, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer Subscription.lnk -> C:\Program Files\Real\RealPlayer\subs.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\About QuickTime.lnk -> C:\WINDOWS\Installer\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}\RichText.ico ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\PictureViewer.lnk -> C:\WINDOWS\Installer\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}\PictureViewer.ico ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\QuickTime Player.lnk -> C:\WINDOWS\Installer\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}\QTPlayer.ico ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk -> C:\WINDOWS\system32\msiexec.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks Customer Manager\QuickBooks Customer Manager Version 1.lnk -> C:\Program Files\Intuit\QuickBooks Customer Manager\QBCM.exe (Intuit, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\QuickBooks Database Server Manager.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBServerUtilityMgr.exe (Intuit)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\QuickBooks Pro 2006.lnk -> C:\Program Files\Intuit\QuickBooks 2006\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\QuickBooks Pro 2009.lnk -> C:\Program Files\Intuit\QuickBooks 2009\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\QuickBooks Pro 2012.lnk -> C:\Program Files\Intuit\QuickBooks 2012\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\QuickBooks Simple Start Special Edition.lnk -> C:\Program Files\Intuit\QuickBooks 2005\QBW32SimplestartLimited.exe (Intuit, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\Web Connector.lnk -> C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Pixelan\SpiceMASTER 2.5 Vegas\Help.lnk -> C:\Program Files\Pixelan\SpiceMASTER 2.5\Help\help.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Pixelan\SpiceMASTER 2.5 Vegas\Pixelan Software Homepage.lnk -> C:\Program Files\Pixelan\SpiceMASTER 2.5\Pixelan Software Homepage.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Pixelan\SpiceMASTER 2.5 Vegas\Please Read FIRST.lnk -> C:\Program Files\Pixelan\SpiceMASTER 2.5\Please Read FIRST.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Pixelan\SpiceMASTER 2.5 Vegas\Quick Start.lnk -> C:\Program Files\Pixelan\SpiceMASTER 2.5\Quick Start.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PhotoShow Deluxe 3\PhotoShow Deluxe.lnk -> C:\Program Files\Simple Star\PhotoShow Deluxe 3\PhotoShow Deluxe.exe (Simple Star, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PhotoShow Deluxe 3\Remove PhotoShow Deluxe.lnk -> C:\Program Files\Simple Star\PhotoShow Deluxe 3\data\Xtras\Uninstall.exe (Simple Star, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PhotoParade\My PhotoParades.lnk -> C:\Documents and Settings\CINDY\My Documents\My PhotoParades ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PhotoParade\PhotoParade Player.lnk -> C:\Program Files\PhotoParade\PhotoParade.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Base.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\sbase.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Calc.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\scalc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Draw.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\sdraw.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Impress.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\simpress.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Math.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\smath.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 2.2\OpenOffice.org Writer.lnk -> C:\WINDOWS\Installer\{A1C8D94A-4303-4489-B585-4B6E6CD408CB}\swriter.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office FrontPage 2003.lnk -> C:\WINDOWS\Installer\{91170409-6000-11D3-8CFE-0150048383C9}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Language Settings.lnk -> C:\WINDOWS\Installer\{91170409-6000-11D3-8CFE-0150048383C9}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk -> C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Expression\Microsoft Expression Web 2 .lnk -> C:\WINDOWS\Installer\{90120000-0045-0000-0000-0000000FF1CE}\xwebicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maxtor\Maxtor Manager.lnk -> C:\WINDOWS\Installer\{B8281D46-D846-4BB9-BC84-F1115A7BF820}\NewShortcut1_D5E5682B2798457BBBF70892B58EFF3A.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maxtor\OneTouch Status Icon.lnk -> C:\WINDOWS\Installer\{B8281D46-D846-4BB9-BC84-F1115A7BF820}\NewShortcut3_D5E5682B2798457BBBF70892B58EFF3A.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\iTunes\About iTunes.lnk -> C:\Program Files\iTunes\iTunes.Resources\en.lproj\About iTunes.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\iTunes\iTunes.lnk -> C:\Program Files\iTunes\iTunes.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Intel(R) Matrix Storage Manager\Help.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\Shell_ENU.hlp ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Intel(R) Matrix Storage Manager\Intel Matrix Storage Console.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\Shell.exe (Intel Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Intel(R) Matrix Storage Manager\Readme.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\readme.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Intel Network Adapters\Intel(R) PROSet for Wired Connections.lnk -> C:\Program Files\Intel\PROSetWired\NCS\PROSet\PROSet.exe (Intel(R) Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP Diagnostic Assistant.lnk -> C:\Program Files\HP\Diagnostic Assistant\bin\hprbevwr.exe (Hewlett-Packard)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP Director.lnk -> C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP Image Zone Tour.lnk -> C:\Program Files\HP\Digital Imaging\Help\cuetour\START.exe (Macromedia, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP Print Screen.lnk -> C:\Program Files\HP\Digital Imaging\HP Print Screen\prnsys.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\Image Zone .lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\System Diagnostics.lnk -> C:\Program Files\HP\Digital Imaging\Diagnostics\HPSysDig.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Help.lnk -> C:\Program Files\HP\Digital Imaging\Help\AIO12.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Product Support Website.lnk -> C:\Program Files\HP\Digital Imaging\hp officejet 5500 series\help\HP Product Support Website.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Readme.lnk -> C:\Program Files\HP\Digital Imaging\Help\Readme.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Tour.lnk -> C:\Program Files\HP\Digital Imaging\hp officejet 5500 series\tour\START.exe (Macromedia, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP LaserJet 400 M401\HP Help & Learn Center.lnk -> C:\Program Files\HP\HP LaserJet 400 M401\Help_Learn\Help.exe (Hewlett-Packard Company)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP LaserJet 400 M401\HP Printer Status and Alerts.lnk -> C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe (Hewlett-Packard Company)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Freecell.lnk -> C:\WINDOWS\system32\freecell.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Hearts.lnk -> C:\WINDOWS\system32\mshearts.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Backgammon.lnk -> C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Checkers.lnk -> C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Hearts.lnk -> C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Reversi.lnk -> C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Spades.lnk -> C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Minesweeper.lnk -> C:\WINDOWS\system32\winmine.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Pinball.lnk -> C:\Program Files\Windows NT\Pinball\pinball.exe (Cinematronics)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Solitaire.lnk -> C:\WINDOWS\system32\sol.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Spider Solitaire.lnk -> C:\WINDOWS\system32\spider.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Film Factory\EPSON PhotoStarter3.0.lnk -> C:\Program Files\EPSON\EPSON PhotoStarter3.0\EPSON PhotoStarter3.0.exe (SEIKO EPSON CORPORATION)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Printers\EPSON Stylus Photo R300 Series Readme.lnk -> C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DI13AE.DOC ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Print CD\EPSON Print CD Help.lnk -> C:\Program Files\EPSON Print CD\EPSONCD.HLP ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Print CD\EPSON Print CD.lnk -> C:\Program Files\EPSON Print CD\EPSONCD.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Print CD\Read Me.lnk -> C:\Program Files\EPSON Print CD\Readme.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON\EPSON Stylus Photo R300 Series Readme.lnk -> C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DI13AE.TXT ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Endicia\DYMO Printable Postage.lnk -> C:\Program Files\Endicia\DYMO Printable Postage\Printable Postage.exe (Endicia Internet Postage)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Dell Accessories\Driver Reset Tool.lnk -> C:\dell\Utilities\Driver Reset Tool\Driver Reset.exe (Dell Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DAZzle\DAZzle Read Me.lnk -> C:\Program Files\Envelope Manager\DAZzle\README.TXT ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DAZzle\DAZzle.lnk -> C:\Program Files\Envelope Manager\DAZzle\DAZZLE.EXE (Endicia)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DAZzle\Quick Start Guide.lnk -> C:\Program Files\Envelope Manager\DAZzle\Quick Start Guide.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Ameritrade\Advanced Analyzer Help.lnk -> C:\Program Files\Ameritrade\Advanced Analyzer\htm\ADVANCED ANALYZER.HLP ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Ameritrade\Advanced Analyzer.lnk -> C:\Program Files\Ameritrade\Advanced Analyzer\stock.exe (Ameritrade IP Company, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Ameritrade\Easy Steps.lnk -> C:\Program Files\Ameritrade\Advanced Analyzer\htm\EASYSTEPS.HLP ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe\Photoshop Elements\Adobe Photoshop Elements.lnk -> C:\Program Files\Adobe\Photoshop Elements\PhotoshopElements.exe (Adobe Systems, Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe\Photoshop Elements\Photoshop Elements ReadMe.lnk -> C:\Program Files\Adobe\Photoshop Elements\Photoshop Elements ReadMe.wri ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\system32\Com\comexp.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\WINDOWS\system32\odbcad32.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Configuration.lnk -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorcfg.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Wizards.lnk -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Server Extensions Administrator.lnk -> C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bin\FPMMC.MSC ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ACT !\ACT! 2000.lnk -> C:\Program Files\ACT\act.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ACT !\Read Me.lnk -> C:\Program Files\ACT\readme.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ACT !\SideACT!.lnk -> C:\Program Files\ACT\SideACT.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ACT !\Uninstall.lnk -> C:\WINDOWS\IsUnInst.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Calculator.lnk -> C:\WINDOWS\system32\calc.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\system32\mstsc.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Scanner and Camera Wizard.lnk -> C:\WINDOWS\system32\wiaacmgr.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\WordPad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\system32\charmap.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\WINDOWS\system32\cleanmgr.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Defragmenter.lnk -> C:\WINDOWS\system32\dfrg.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk -> C:\WINDOWS\system32\usmt\migwiz.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\security center.lnk -> C:\WINDOWS\system32\wscui.cpl (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\WINDOWS\system32\Restore\rstrui.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Microsoft Interactive Training\Microsoft Interactive Training Help.lnk -> C:\WINDOWS\Help\SBSI\Training\LSINGLE.HLP ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Sound Recorder.lnk -> C:\WINDOWS\system32\sndrec32.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Volume Control.lnk -> C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\HyperTerminal.lnk -> C:\Program Files\Windows NT\hypertrm.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Fax\Fax Console.lnk -> C:\WINDOWS\system32\fxsclnt.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Fax\Fax Cover Page Editor.lnk -> C:\WINDOWS\system32\fxscover.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Fax\Send a Fax....lnk -> C:\WINDOWS\system32\fxssend.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Accessibility\Accessibility Wizard.lnk -> C:\WINDOWS\system32\accwiz.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Documents\Local Disk (C).lnk -> C:\ ()
    Shortcut: C:\Documents and Settings\All Users\Documents\Shortcut to Local Disk (C).lnk -> C:\ ()
    Shortcut: C:\Documents and Settings\All Users\Desktop\ACT! 2000.lnk -> C:\Program Files\ACT\act.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Adobe Photoshop Album Starter Edition 3.2.lnk -> C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\Photoshop Album Starter Edition.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Adobe Photoshop Elements 5.0.lnk -> C:\Program Files\Adobe\Photoshop Elements 5.0\Photoshop Elements 5.0.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk -> C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Advanced Analyzer.lnk -> C:\Program Files\Ameritrade\Advanced Analyzer\stock.exe (Ameritrade IP Company, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Burn CDs & DVDs with Sonic DigitalMedia LE.lnk -> C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe ()
    Shortcut: C:\Documents and Settings\All Users\Desktop\dazzle.lnk -> C:\Program Files\Envelope Manager\DAZzle\DAZZLE.EXE (Endicia)
    Shortcut: C:\Documents and Settings\All Users\Desktop\DYMO Printable Postage.lnk -> C:\Program Files\Endicia\DYMO Printable Postage\Printable Postage.exe (Endicia Internet Postage)
    Shortcut: C:\Documents and Settings\All Users\Desktop\HP Image Zone.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\HP Director.lnk -> C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Co.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\HP LaserJet 400 M401 - Help & Learn Center.lnk -> C:\Program Files\HP\HP LaserJet 400 M401\Help_Learn\Help.exe (Hewlett-Packard Company)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Maxtor Manager.lnk -> C:\WINDOWS\Installer\{B8281D46-D846-4BB9-BC84-F1115A7BF820}\NewShortcut2_60EEB642E9E045A2A676B9D8FE17C4A9.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Desktop\My PhotoParades.lnk -> C:\Documents and Settings\CINDY\My Documents\My PhotoParades ()
    Shortcut: C:\Documents and Settings\All Users\Desktop\Owner's Manual.lnk -> C:\dell\docs\manual\eom.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Desktop\PhotoParade Player.lnk -> C:\Program Files\PhotoParade\PhotoParade.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Desktop\PhotoShow Deluxe 3.lnk -> C:\Program Files\Simple Star\PhotoShow Deluxe 3\PhotoShow Deluxe.exe (Simple Star, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\QuickBooks Customer Manager v1.lnk -> C:\Program Files\Intuit\QuickBooks Customer Manager\QBCM.exe (Intuit, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\QuickBooks Pro 2006.lnk -> C:\Program Files\Intuit\QuickBooks 2006\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\QuickBooks Pro 2009.lnk -> C:\Program Files\Intuit\QuickBooks 2009\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\QuickBooks Pro 2012.lnk -> C:\Program Files\Intuit\QuickBooks 2012\QBW32Pro.exe (Intuit Inc.)
    Shortcut: C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk -> C:\Program Files\QuickTime\QuickTimePlayer.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Desktop\RezEasy Mobile.lnk -> C:\Program Files\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\rez60mobile.exe (Hallisoft)
    Shortcut: C:\Documents and Settings\All Users\Desktop\RezEasy Standard.lnk -> F:\Hallisoft\RezEasy_6\RezEasy_6_Std\RezEasy\rez60std.exe (Hallisoft)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Shipstream Manager.lnk -> C:\Program Files\Pitney Bowes\PBship\PBSHIP.EXE (Pitney Bowes)
    Shortcut: C:\Documents and Settings\All Users\Desktop\SideACT!.lnk -> C:\Program Files\ACT\SideACT.exe (No File)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Sothink DHTMLMenu.lnk -> C:\Program Files\SourceTec\Sothink DHTMLMenu\dhtmlmenu.exe (SourceTec)
    Shortcut: C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk -> C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware)
    Shortcut: C:\Documents and Settings\All Users\Desktop\UPS WorldShip.lnk -> C:\UPS\WSTD\WorldShipTD.exe (UPS)
    Shortcut: C:\Documents and Settings\All Users\Desktop\VLC media player.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe ()
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Seagate Dashboard\Seagate Dashboard.lnk -> C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\MyWordTool\Uninstall.lnk -> C:\Documents and Settings\CINDY\Application Data\MyWordTool\uninst.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Microsoft WSE 2.0\Release Notes.lnk -> C:\Program Files\Microsoft WSE\v2.0\readme.htm ()
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\McAfee\McAfee Virtual Technician.lnk -> C:\Documents and Settings\CINDY\Desktop\mvtapp.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\McAfee\Uninstall McAfee Virtual Technician.lnk -> C:\Documents and Settings\CINDY\Desktop\mvtapp.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Legal Products\Broderbund Business Lawyer 2003\Register\Register Your Software.lnk -> C:\::C:\PROGRA~1\LEGALP~1\BRODER~1\Ereg\EREG32.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Legal Products\Broderbund Business Lawyer 2003\Register\Uninstall the BL2003 Registration.lnk -> C:\Program Files\Legal Products\Broderbund Business Lawyer 2003\Ereg\UNWISE.EXE ()
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\HP\HP Software Update.lnk -> C:\Program Files\HP\HP Software Update\HPWUCli.exe (Hewlett-Packard Company)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Dell Accessories\Express Service Code.lnk -> C:\dell\EXPRESS.EXE ()
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Dell\Phone Support.lnk -> C:\dell\contact\help.htm ()
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\NetHood\Upstairs on Darryl (Darryl)\target.lnk -> C:\ ()
    Shortcut: C:\Documents and Settings\CINDY\NetHood\SharedDocs on Darryl (Darryl)\target.lnk -> \\DARRYL\SharedDocs (No File)
    Shortcut: C:\Documents and Settings\CINDY\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\CINDY\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\CINDY\Desktop\ACT! 2000.lnk -> C:\Program Files\ACT\act.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Desktop\Downloaded Program Updates.lnk -> C:\Documents and Settings\CINDY\My Documents\Downloaded Program Updates ()
    Shortcut: C:\Documents and Settings\CINDY\Desktop\McAfee Virtual Technician.lnk -> C:\Documents and Settings\CINDY\Desktop\mvtapp.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Desktop\Seagate Dashboard.lnk -> C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Desktop\SideACT!.lnk -> C:\Program Files\ACT\SideACT.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Desktop\Tax Forms Helper 2011.lnk -> C:\Tax Forms Helper 2011\TFH.exe (Adams, a division of TOPS)
    Shortcut: C:\Documents and Settings\CINDY\Desktop\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\ACT! 2000.lnk -> C:\Program Files\ACT\act.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmjb.exe (No File)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Sothink DHTMLMenu.lnk -> C:\Program Files\SourceTec\Sothink DHTMLMenu\dhtmlmenu.exe (SourceTec)
    Shortcut: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Dell Accessories\Express Service Code.lnk -> C:\dell\EXPRESS.EXE ()
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Dell\Phone Support.lnk -> C:\dell\contact\help.htm ()
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\SendTo\Musicmatch Burner Plus.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMFWLaunch.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\Default User\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk -> C:\Program Files\America Online 9.0\aol.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmjb.exe (No File)
    Shortcut: C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk -> C:\Program Files\QuickTime\QuickTimePlayer.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Dell Accessories\Express Service Code.lnk -> C:\dell\EXPRESS.EXE ()
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Dell\Phone Support.lnk -> C:\dell\contact\help.htm ()
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\SendTo\Musicmatch Burner Plus.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMFWLaunch.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\SendTo\Share-to-Web Upload Folder.lnk -> C:\Documents and Settings\CINDY\Application Data\Share-to-Web Upload Folder ()
    Shortcut: C:\Documents and Settings\DEVON\NetHood\Upstairs on Darryl (Darryl)\target.lnk -> \\DARRYL\Upstairs (No File)
    Shortcut: C:\Documents and Settings\DEVON\NetHood\SharedDocs on Darryl (Darryl)\target.lnk -> \\DARRYL\SharedDocs (No File)
    Shortcut: C:\Documents and Settings\DEVON\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\DEVON\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\DEVON\Desktop\Downloaded Program Updates.lnk -> C:\Documents and Settings\CINDY\My Documents\Downloaded Program Updates ()
    Shortcut: C:\Documents and Settings\DEVON\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Desktop\Spybot - Search & Destroy.lnk -> C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Desktop\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk -> C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmjb.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk -> C:\Program Files\QuickTime\QuickTimePlayer.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk -> C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (No File)
    Shortcut: C:\Documents and Settings\DEVON\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\LocalService\Desktop\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Dell Accessories\Express Service Code.lnk -> C:\dell\EXPRESS.EXE ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Dell\Phone Support.lnk -> C:\dell\contact\help.htm ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\SendTo\Musicmatch Burner Plus.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMFWLaunch.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk -> C:\Program Files\America Online 9.0\aol.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmjb.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser19\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk -> C:\Program Files\QuickTime\QuickTimePlayer.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Dell Accessories\Express Service Code.lnk -> C:\dell\EXPRESS.EXE ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Dell\Phone Support.lnk -> C:\dell\contact\help.htm ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\SendTo\Musicmatch Burner Plus.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMFWLaunch.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk -> C:\Program Files\America Online 9.0\aol.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk -> C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmjb.exe (No File)
    Shortcut: C:\Documents and Settings\QBDataServiceUser22\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk -> C:\Program Files\QuickTime\QuickTimePlayer.exe (No File)


    ShortcutWithArgument: C:\Documents and Settings\All Users\Desktop\Dell Download Center.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.dell.com/smb/software
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Start Menu\Programs\Microsoft WSE 2.0\WSE on the Web.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://go.microsoft.com/fwlink/?linkid=10708&clcid=0x409


    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Microsoft Update.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> C:\WINDOWS\system32\muweb.dll,LaunchMUSite
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) -> /launchsearchwindow
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Reset VLC media player preferences and cache files.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --reset-config --reset-plugins-cache vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to Direct3D (no hardware acceleration).lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout direct3d --overlay --no-directx-hw-yuv --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to Direct3D.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout direct3d --overlay --directx-hw-yuv --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to DirectX (no hardware acceleration).lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout directx --no-overlay --no-directx-hw-yuv --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to DirectX (no video overlay).lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout directx --no-overlay --directx-hw-yuv --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to DirectX.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout directx --overlay --directx-hw-yuv --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Video\Set Video mode to OpenGL.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --vout opengl --overlay --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Interface\Set Main Interface to Qt (default).lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> -I qt --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Interface\Set Main Interface to Skinnable.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> -I skins --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Audio\Set Audio mode to DirectX (default).lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --aout aout_directx --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Quick Settings\Audio\Set Audio mode to Waveout.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe () -> --aout waveout --save-config vlc://quit
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\Registration.lnk -> C:\Tax Forms Helper 2011\Registration.exe () -> -reg
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Tax Forms Helper 2011\Tax Forms Helper 2011 without Update Checking.lnk -> C:\Tax Forms Helper 2011\TFH.exe (Adams, a division of TOPS) -> noUpdateCheck
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Registration-Activation.lnk -> C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware) -> /register
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.) -> -s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk -> C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.) -> -silent
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk -> C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation) -> /n
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) -> /startup
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Copy Sonic Foundry Plug-In Licenses from Installed Sony Plug-Ins .lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\sf2sony20.exe (Madison Media Software, Inc.) -> /q /key all /rev
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Copy Sony Plug-In Licenses from Installed Sonic Foundry Plug-Ins .lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\sf2sony20.exe (Madison Media Software, Inc.) -> /q /key mp3plug mcplug ac3plug
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Copy Sony Templates from Sonic Foundry .lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\sf2sony20.exe (Madison Media Software, Inc.) -> /q /templ all
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Copy Sony User Information from Sonic Foundry .lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\sf2sony20.exe (Madison Media Software, Inc.) -> /q /userinfo
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sony\Utilities\Migration Tools\Register Sony DirectX Audio Plug-Ins .lnk -> C:\Program Files\Sony\Shared Plug-Ins\Utilities\Migration Tools\sf2sony20.exe (Madison Media Software, Inc.) -> /q /aplugins reg
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\MyDVD LE.lnk -> C:\Program Files\Sonic\MyDVD\MyDVD.EXE (Sonic Solutions) -> -LaunchSC
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\DigitalMedia Projects\RecordNow Audio.lnk -> C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe () -> /Launch Audio
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\DigitalMedia Projects\RecordNow Copy.lnk -> C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe () -> /Launch Copy
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Sonic\DigitalMedia Projects\RecordNow Data.lnk -> C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe () -> /Launch Data
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Shipstream Manager\Uninstall Shipstream Manager.lnk -> C:\Program Files\Pitney Bowes\PBship\UNWISE32.EXE () -> C:\PROGRA~1\PITNEY~1\PBship\INSTALL.LOG
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Real\RealPlayer\RealPlayer Uninstaller.lnk -> C:\Program Files\Common Files\Real\Update\rnuninst.exe (RealNetworks, Inc.) -> RealNetworks
    RealPlayer
    6.0
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks\Choose Simple Start Desktop or Online Edition.lnk -> C:\Program Files\Intuit\QuickBooks 2005\Atom\start.exe () -> ""
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Pixelan\SpiceMASTER 2.5 Vegas\Uninstall SpiceMASTER 2.5.lnk -> C:\Program Files\Pixelan\SpiceMASTER 2.5\UnInstall\UnInstall.exe () -> "C:\PROGRA~1\Pixelan\SPICEM~1.5\UnInstall\Install.log"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Save My Settings Wizard.lnk -> C:\WINDOWS\Installer\{91170409-6000-11D3-8CFE-0150048383C9}\opwicon.exe () -> /u
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Application Recovery.lnk -> C:\WINDOWS\Installer\{91170409-6000-11D3-8CFE-0150048383C9}\misc.exe () -> -c
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\McAfee\McAfee SecurityCenter.lnk -> C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) -> /desktopicon
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Intel(R) Matrix Storage Manager\Uninstall.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}\setup.exe" -l0409 -INTELUNINST
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP Share-to-Web\HP Share-to-Web Setup Wizard.lnk -> C:\Program Files\Hewlett-Packard\HP Share-to-Web\S2WEx.exe (Hewlett-Packard Company) -> -loudupdate=true
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP Document Viewer.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.) -> -Document
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Product Registration.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe (Hewlett-Packard Co.) -> "officejet 5500 series"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP\OfficeJet All-In-One 5500 series\Uninstall.lnk -> C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe (Hewlett-Packard) -> -datfile hposcr04.dat -forcereboot -nocopytotemp
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP LaserJet 400 M401\HP Device Toolbox.lnk -> C:\Program Files\HP\HP LaserJet 400 M401\bin\EWSProxy.exe (Hewlett-Packard Co.) -> /printdriver "HP LaserJet 400 M401 PCL 6" /app Home
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\HP\HP LaserJet 400 M401\HP Product Improvement Study.lnk -> C:\Program Files\HP\HPLJUT\HPLJUTSCH.exe (Hewlett Packard) -> /optToggle /prod "HP LaserJet 400 M401 PCL 6"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Printers\EPSON Printer Software Uninstall.lnk -> C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUPDATE.EXE (SEIKO EPSON CORPORATION) -> /R
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON Print CD\Uninstall EPSON Print CD.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -REMOVE
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\EPSON\EPSON Printer Software Uninstall.lnk -> C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUPDATE.EXE (SEIKO EPSON CORPORATION) -> /R
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Dell Support Center\About Dell Support Center.lnk -> C:\WINDOWS\Installer\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}\dsc.ico () -> /P DellSupportCenter /entry "Programs Menu" /snapins:starting_snapin snapin_content_template /content_guid 8dc4871d-7f69-40e6-a588-5aef120939d3
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Dell Support Center\Dell Support Center Alerts.lnk -> C:\WINDOWS\Installer\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}\dsc.ico () -> /P DellSupportCenter /entry "Programs Menu" /snapins:starting_snapin snapin_messagelisting
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Dell Support Center\Dell Support Center User Settings.lnk -> C:\WINDOWS\Installer\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}\dsc.ico () -> /P DellSupportCenter /entry "Programs Menu" /snapins:starting_snapin snapin_servicedirect_settings
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Dell Support Center\Dell Support Center.lnk -> C:\WINDOWS\Installer\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}\dsc.ico () -> /P DellSupportCenter /entry "Programs Menu"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\DAZzle\Remove DAZzle.lnk -> C:\Program Files\Envelope Manager\DAZzle\UNWISE32.EXE () -> C:\PROGRA~1\ENVELO~1\DAZzle\INSTALL.LOG
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Performance.lnk -> C:\WINDOWS\system32\perfmon.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk -> C:\WINDOWS\system32\services.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Scheduled Tasks.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Microsoft Interactive Training\Microsoft Interactive Training.lnk -> C:\WINDOWS\Help\SBSI\Training\orun32.exe (Microsoft Corporation) -> -f "C:\WINDOWS\Help\SBSI\Training\StartMenu.cbo"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{7007acc7-3202-11d1-aad2-00805fc1270e}
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> hnetwiz.dll,HomeNetWizardRunDll
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\New Connection Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> netshell.dll,StartNCW
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Wireless Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> shell32.dll,Control_RunDLL NetSetup.cpl,@0,WNSW
    ShortcutWithArgument: C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk -> C:\WINDOWS\Installer\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}\dsc.ico () -> /P DellSupportCenter /entry "Desktop Shortcut"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Desktop\HP Document Viewer.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.) -> -Document
    ShortcutWithArgument: C:\Documents and Settings\All Users\Desktop\MyDVD LE.lnk -> C:\Program Files\Sonic\MyDVD\MyDVD.EXE (Sonic Solutions) -> -LaunchSC
    ShortcutWithArgument: C:\Documents and Settings\All Users\Desktop\Simple Start Edition.lnk -> C:\Program Files\Intuit\QuickBooks 2005\Atom\start.exe () -> ""
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Start Menu\Programs\HP\HP LaserJet 400 M401\Reconfigure your HP Device.lnk -> C:\Program Files\HP\csiInstaller\8989F6D9-550C-4178-A8CB-75B82A06621F\Setup.exe (Hewlett-Packard) -> /ReconfigWireless
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Start Menu\Programs\HP\HP LaserJet 400 M401\Uninstall Product Software.lnk -> C:\Program Files\HP\csiInstaller\8989F6D9-550C-4178-A8CB-75B82A06621F\Setup.exe (Hewlett-Packard) -> /Uninstall
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -extoff
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Desktop\DCS-930L(70957001).lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> "https://us.mydlink.com/device#70957001?lang=en_US"
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Desktop\Resume Adobe Downloads.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> C:\DOCUME~1\CINDY\LOCALS~1\Temp\nosget_start_manager.html
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Desktop\Tax Forms Helper 2011 without Update Checking.lnk -> C:\Tax Forms Helper 2011\TFH.exe (Adams, a division of TOPS) -> noUpdateCheck
    ShortcutWithArgument: C:\Documents and Settings\CINDY\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation) -> /recycle
    ShortcutWithArgument: C:\Documents and Settings\DEVON\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -extoff
     
  12. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\UPS\UPS WorldShip Help.url -> hxxp://www.ups.com/worldshiphelp/WS17/ENU/AppHelp/SHIPUPS.htm
    InternetURL: C:\Documents and Settings\All Users\Desktop\Checks & More for QuickBooks.url -> hxxp://www.intuitmarket.com/qb06DesktopIcon
    InternetURL: C:\Documents and Settings\All Users\Desktop\Process Credit Cards in QuickBooks.url -> hxxp://www.quickbooksms.com/signup/index.php?p_prioritycode=icon
    InternetURL: C:\Documents and Settings\All Users\Desktop\QuickBooks Technical Support.url -> hxxp://www.usequickbooks.com/qb2006_desktop_icon/
    InternetURL: C:\Documents and Settings\All Users\Desktop\Software that works with QB.url -> hxxp://www.quickbooksdirect.com/qb2006_idn
    InternetURL: C:\Documents and Settings\CINDY\Favorites\925 Sterling Silver Charm Manufacturer exporting direct from India.url -> hxxp://pinkcityindia.trustpass.alibaba.com/product/100355331/925_Sterling_Silver_Charm.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\about.com http--www.dltk-kids.com-crafts-cartoons-oz-coloring.html.url -> hxxp://familycrafts.about.com/gi/dynamic/offsite.htm?zi=1/XJ/Ya&sdn=familycrafts&cdn=parenting&tm=26&gps=149_233_1020_527&f=10&tt=14&bt=0&bts=0&zu=http%3A//www.dltk-kids.com/crafts/cartoons/oz-coloring.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Art Jewelry - Advertising Representatives for Art Jewelry -.url -> hxxp://www.artjewelrymag.com/art/default.aspx?c=ss&id=56
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Better Whois The WHOIS domain search that works with all registrars..url -> hxxp://www.betterwhois.com/
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Brother TZAF131 Acid Free P-touch Tape - Black on Clear TZ Tape.url -> hxxp://www.ptouchdirect.com/ptouch/tzaf131.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Buy Personalized Photo Frame Christmas Ornaments - Gifts at Santa's Ornament Shop..url -> hxxp://www.santasornamentshop.com/shopdisplayproducts.asp?cat=Photo+Frame&catid=5
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Character Theme Party Favor Sets at Birthday in a Box.url -> hxxp://www.birthdayinabox.com/lobby.asp-page-alacarte-prodtype_id-24-subcat-194-acat_id-9-offset-0
    InternetURL: C:\Documents and Settings\CINDY\Favorites\CodeLifter.com - JavaScript 1-Click Easy Drop-Down Munues.url -> hxxp://www.codelifter.com/main/javascript/dropdown.shtml
    InternetURL: C:\Documents and Settings\CINDY\Favorites\DCS-930L(70957001).url -> "https://us.mydlink.com/device#70957001?lang=en_US"
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Drawing Lessons for Children Kids can Learn how to draw Cartooning Lessons for Children Teach your Child to Draw Cartoons.url -> hxxp://www.artistshelpingchildren.org/howtodraw.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\eBay Powerseller Challenge.url -> hxxp://ebay.promotionexpert.com/PowerSeller2007/restricted/dashboard.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Exposures Online.url -> hxxp://www.exposuresonline.com/ExposuresOnline/Shopping/ProductDetail.aspx?CID=Gift+Ideas&SCID=Ornament+Shop&CollectionID=L080855OR&SiteNum=0
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Fashionable Initial Letter Lock Charms Bracelet from China Shenzhen Manufacturer, Exporter Amio Jewelry Co. Ltd.url -> hxxp://amiojewelry.manufacturer.globalsources.com/si/6008813910687/pdtl/Bracelet/1005574760/Fashionable-Initial-Letter-Lock-Charms-Bracelet.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Francesca's Flower Ring.url -> hxxp://www.inspiredsilver.com/index.cfm?fa=site.showproduct&product_id=945&product_category_id=1&viewall=1&page=1
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Gorgeous and unique handcrafted bracelets of semi-precious stone, glass, pearl, and precious metals.url -> hxxp://www.beadeuphoria.net/site/558649/page/165628
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Grandkids Silver Photo Frame Ornament - - Christianbook.com.url -> hxxp://www.christianbook.com/Christian/Books/product?item_no=12253X&event=51500GRPHIM%7C1135550%7C55020
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Growers Solution Learning Center.url -> hxxp://learning.growerssolution.com/
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Haute Trends.url -> hxxp://www.hautetrends.com/
    InternetURL: C:\Documents and Settings\CINDY\Favorites\HomeSchoolRequirements.url -> hxxp://www.ncdnpe.org/hhh103.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\I Need You Lampwork Charm Bracelet - Custom Order bylgd.com.url -> hxxp://bylgd.com/i_need_you_bracelet.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Landing a Spot in the Retail Big Leagues.url -> hxxp://www.entrepreneur.com/growyourbusiness/howtoguides/article159254.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Learn About Gold Cuban Chain Jewelry Education and Information - Emperor Jewels.url -> hxxp://www.emperorjewels.com/glossary/gold-cuban-chain.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Manufacturing Jewelers and Suppliers of America.url -> hxxp://www.mjsa.org/view/search.php
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Mohawk-Aladdin-Sticks and Stones.url -> hxxp://www.becklerscarpet.com/carpet/displaycolordetail.php?p_id=81&coll_id=382&manu_id=2&color_id=7390
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Motionwear Tank Dress for Girls - MM4311C.url -> hxxp://www.allaboutdance.com/s.nl/it.A/id.16786/.f?sc=2&category=743
    InternetURL: C:\Documents and Settings\CINDY\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Naughtycodes.com.url -> hxxp://www.naughtycodes.com/
    InternetURL: C:\Documents and Settings\CINDY\Favorites\nche Conference Info.url -> hxxp://nche.com/conference.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\North Carolina Homeschooling - A to Z Home's Cool Homeschooling.url -> hxxp://homeschooling.gomilpitas.com/regional/NorthCarolina.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Paper Mart Packaging Store - LIP & TAPE SELF SEALING BAGS.url -> hxxp://www.papermart.com/templates/75-8-50.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Photo Ornament - Scallop Shape.url -> hxxp://www.mandysmoon.com/Qstore/Qstore.cgi?CMD=011&PROD=1065400904
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Radio Station Guide.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
    InternetURL: C:\Documents and Settings\CINDY\Favorites\RealPlayer Home Page.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Related Info for ewatchwholesale.com-.url -> hxxp://www.alexa.com/data/details/?url=ewatchwholesale.com
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Scrapbooking Supplies and Information at The Scrap Stop.url -> hxxp://www.scrapstop.com/shop.php?op=catbrowse&vendor=&cat=143&startitem=16
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Snap Back Watch Case Openers.url -> hxxp://www.ofrei.com/page555.html
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Snappy Case Opener Watch Case Tool.url -> hxxp://www.thewatchprince.com/s.nl;jsessionid=0a000d4a1f434f6a636cd1e347b39c5bc91dea9cbd72.e3eSc34RbhyRe34Pa38Ta38Qbhv0?it=A&id=182&sc=10&category=38
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Style# D175 - Scoop Leotard w-Skirt and Sleeves - Dancewear Solutions.url -> hxxp://www.dancewearsolutions.com/default.asp?STYLENUMBER=D175&CATEGORY=Clearance Items&Subcategory=Dresses&Brand=Balera
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Telegraph newspaper online.url -> hxxp://www.telegraph.co.uk/;jsessionid=CT3BYHK2VBPG1QFIQMFCFFWAVCBQYIV0
    InternetURL: C:\Documents and Settings\CINDY\Favorites\WhitePages.com - Online Directory Assistance.url -> hxxp://www.whitepages.com/search/FindPerson?extra_listing=mixed&form_mode=opt_b&post_back=1&firstname_begins_with=1&firstname=Hal&name=Willet&street=&city_zip=Taylorsville&state_id=NC&localtime=survey
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Zebra TLP 2844 Labels - Barcode Discount.url -> hxxp://www.barcodediscount.com/catalog/zebra/tlp2844-labels.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\IE Add-on site.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?linkid=44661
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\Marketplace.url -> hxxp://go.microsoft.com/fwlink/?linkid=69151
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\Microsoft At Home.url -> hxxp://go.microsoft.com/fwlink/?linkid=55424
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\Microsoft At Work.url -> hxxp://go.microsoft.com/fwlink/?linkid=68920
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Microsoft Websites\Welcome to IE7.url -> hxxp://go.microsoft.com/fwlink/?linkid=68919
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Media\Real.com Radio Tuner.url -> hxxp://realguide.real.com/stations/
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Links\Add to ThisNext.url -> hxxp://www.thisnext.com/bookmarklet/?ua=ie
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Links\RealPlayer.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Links\Suggested Sites.url -> https://ieonline.microsoft.com/#ieslice
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Links\Web Slice Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Homeschooling\North Carolina Field Trips - A to Z Home's Cool Homeschooling in North Carolina.url -> hxxp://homeschooling.gomilpitas.com/trips/NorthCarolinaTrips.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Homeschooling\North Carolina Homeschooling - A to Z Home's Cool Homeschooling.url -> hxxp://homeschooling.gomilpitas.com/regional/NorthCarolina.htm
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Dell\Dell Auction.url -> hxxp://www.dellauction.com
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Dell\Dell Internet Security.url -> hxxp://support.dell.com/support/topics/global.aspx/support/security/security?c=us&cs=19&l=en&s=dhs
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Dell\Dell.url -> hxxp://www.dell.com
    InternetURL: C:\Documents and Settings\CINDY\Favorites\Dell\Support.Dell.Com.url -> hxxp://support.dell.com
    InternetURL: C:\Documents and Settings\CINDY\Application Data\Adobe\Photoshop Elements\5.0\Editor\Browser\cache4\dcache4.url -> 0
    InternetURL: C:\Documents and Settings\Default User\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
    InternetURL: C:\Documents and Settings\Default User\Favorites\Radio Station Guide.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
    InternetURL: C:\Documents and Settings\Default User\Favorites\RealPlayer Home Page.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\Default User\Favorites\Media\Real.com Radio Tuner.url -> hxxp://realguide.real.com/stations/
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\Customize Links.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=CLinks
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\RealPlayer.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\Windows Marketplace.url -> hxxp://go.microsoft.com/fwlink/?LinkId=30857&clcid=0x409
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\Windows Media.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windowsmedia
    InternetURL: C:\Documents and Settings\Default User\Favorites\Links\Windows.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windows
    InternetURL: C:\Documents and Settings\Default User\Favorites\Dell\Dell Auction.url -> hxxp://www.dellauction.com
    InternetURL: C:\Documents and Settings\Default User\Favorites\Dell\Dell Internet Security.url -> hxxp://support.dell.com/support/topics/global.aspx/support/security/security?c=us&cs=19&l=en&s=dhs
    InternetURL: C:\Documents and Settings\Default User\Favorites\Dell\Dell.url -> hxxp://www.dell.com
    InternetURL: C:\Documents and Settings\Default User\Favorites\Dell\Support.Dell.Com.url -> hxxp://support.dell.com
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Drivers & Downloads.url -> hxxp://support.dell.com/support/downloads/download.aspx?c=us&l=en&s=gen&releaseid=R130051&SystemID=DIMENSION%205150/E510&os=WW1&osl=en&deviceid=10373&devlib=0&typecnt=1&vercnt=2&formatcnt=1&libid=32&fileid=173334&appindex=ds
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Heart Disease.url -> hxxp://www.heart-disease-bypass-surgery.com/HeartDisease.htm
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Jewelry photography tips - how to photograph jewelry.url -> hxxp://www.tabletopstudio.com/documents/jewelry_photography.htm
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Manufactured Homes Direct - Classifieds.url -> hxxp://www.net5000.com/mhdclass/mhdclass.html
    InternetURL: C:\Documents and Settings\DEVON\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Radio Station Guide.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
    InternetURL: C:\Documents and Settings\DEVON\Favorites\RealPlayer Home Page.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\IE Add-on site.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?linkid=44661
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\Marketplace.url -> hxxp://go.microsoft.com/fwlink/?linkid=69151
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\Microsoft At Home.url -> hxxp://go.microsoft.com/fwlink/?linkid=55424
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\Microsoft At Work.url -> hxxp://go.microsoft.com/fwlink/?linkid=68920
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Microsoft Websites\Welcome to IE7.url -> hxxp://go.microsoft.com/fwlink/?linkid=68919
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Media\Real.com Radio Tuner.url -> hxxp://realguide.real.com/stations/
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Links\RealPlayer.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Links\Suggested Sites.url -> https://ieonline.microsoft.com/#ieslice
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Links\Web Slice Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Dell\Dell Auction.url -> hxxp://www.dellauction.com
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Dell\Dell Internet Security.url -> hxxp://support.dell.com/support/topics/global.aspx/support/security/security?c=us&cs=19&l=en&s=dhs
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Dell\Dell.url -> hxxp://www.dell.com
    InternetURL: C:\Documents and Settings\DEVON\Favorites\Dell\Support.Dell.Com.url -> hxxp://support.dell.com
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\Advertisement.url -> hxxp://pagead2.googlesyndication.com/pagead/ads?client=ca-newsweek_460x232&dt=1161306776656&adsafe=high&lmt=1161306776&format=460x232_sln&output=html&url=http%3A%2F%2Fwww.msnbc.msn.com%2Fid%2F15332531%2Fsite%2Fnewsweek%2Fpage%2F3%2F&ref=http%3A%2F%2Fwww.msnbc.msn.com%2Fid%2F15332531%2Fsite%2Fnewsweek%2Fpage%2F2%2F&cc=26&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=-240&u_his=3&u_java=true
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\daniel gray&a.url -> hxxp://www.geekbooks.com/index.rdf
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\deere...Deale.url -> hxxp://dealerlocator.deere.com/servlet/DealerLocator?command=locate&locator=3&selectLocale=en_US&selectCountry=USA&selectProduct=21&locale=en_US&countryCode=USA&option=Z&zmLvl=5&navData=http%3A//dealerlocation.deere.com/servlet/DealerLocationList%3Fformat%3Dhmap%26option%3DL%26street%3D%26city%3D%20%26state%3DNorth%20Carolina%26postalCode%3D28644%26countryCode%3DUSA%26limit%3D5%26radius%3D100%26uom%3Dmi%26locale%3Den_US%26groupType%3D3%26groupCode%3D10%26destLat%3D36.434300%26destLong%3D-81.244300%26panVal%3D0.0%26zoomLevel%3D6%26appID%3Dtest%26%26sessionId%3D2N9B6mfhdRup1s4Wf1w9hZ9%26callerUserId%3D%26addressDetail%3DNO%26currentRow%3D0&showLocales=en_US%3Aen_CA%3Afr_CA%3Aes_MX&showCountries=USA%3ACAN&startIndex=0&street=&city=%20&state=&postalCode=28644&valid=1&sessionId=2N9B6mfhdRup1s4Wf1w9hZ9
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\ebay _W0QQa10.url -> hxxp://motors.listings.ebay.com/_W0QQa10239ZQ2d24QQa10244ZQ2d24QQa38v1yZ1965QQa38v2yZ1975QQa39ZQ2d24QQa39705ZQ2d24QQalistZa39Q2ca41Q2ca38v1yQ2ca38v2yQ2ca10239Q2ca3801Q2ca85Q2ca10246Q2ca33512Q2ca10241Q2ca10244Q2ca39705QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfsooZ1QQfsopZ1QQftrtZ1QQftrvZ1QQgcsZ13QQlopgZ3QQpf_queryZQQpfidZ2473QQpfmodeZ1QQreqtypeZ2QQsacatZQ2d100QQsaprchiZQQsaprcloZQQsatitleZQQsocmdZListingItemList
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\ewossnewsbar.url -> hxxp://www.ewossnewsbar.com/go.ashx?url=http%3a%2f%2fwww20.overture.com%2fd%2fsr%2f%3fxargs%3d15KPjg1NxSj5Xyl%255FruNLbXU6TFhUBdycz%252DrZVwXM4kAIpBsic5CKIqPefO35QvWO8TpVGWkLbH9vhQebHm27%255FeDwyO2mLYTaXowLz4ntRjcrKjWZxShbVsl66x%252DrB%252DKDxTMyziIc%255Fmz7CYfIPkejwX4dZdmUjR6PIak5Pjm7NLRK%255Fa3VB9%252DVqCeM5Yub1y1IWEdthdCdpmToPGy3gKQ69An4kg0rhYDxNPeXXntTOMm2aGZmU85PKJP5JJ%252D%252Dqiz8zcX9epyY8PLhjXGMdXvEfViS%255FZmpJPBEq3lvEMxksHP%252DuoD3mB51Rpx%252DqAzLHGKLObnwCcJs3cFnbxZUBzE0RnBq7oPVXIdmw%255Fnj23SpNEccGq%252DjXrDbaADyAhZCAI6NW3PsNz6nvemJ5aO0LrHtbauS5ON%252DVs1xnjqmSQo0B6%252DJhF%252DoKrWNRBu%255FWD7DDCQipfuFiclqSiWs%252D3%252DXRwkDUq%252DOZUEt5NzeRTqFpD2R78o%252DWWqtsG59xfdKahlXlbtrvodfQbe%255FvadjVwLr89dl7JAq%255F2L9Xb3FMPQFwUK0GCwrrq00%252DeyQQiaq3ZiQ4i9ljfFvgAp2pJg7Tav5f91yyWGzT1o3aSFrmFnwLrnppTSSiuHL5Vi1iky6YyVmsBtdl8jOBE70cQfa4bggcj6%252DK1UTXkWIfj2K2F5ReGweHPtboT5ZYYvMWBTnLwjbHsymUf8h8e3k7uDBg18AwSwdGa23lT6GTsDMnbupU4lSJl%255FvuOqocTL751%26yargs%3dwww.amazon.com&id=2207269&pos=2&ClickType=2&page=1
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\Live Market Q.url -> hxxp://www.kitco.com/market/
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\msnbc.msn.com.url -> hxxp://www.msnbc.msn.com/
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\More\Advertisement - pagead2.googlesyndication.com.url -> hxxp://pagead2.googlesyndication.com/pagead/ads?client=ca-newsweek_460x232&dt=1161306138015&adsafe=high&lmt=1161306138&format=460x232_sln&output=html&url=http%3A%2F%2Fwww.msnbc.msn.com%2Fid%2F15332531%2Fsite%2Fnewsweek%2F&ref=http%3A%2F%2Fwww.msnbc.msn.com%2F&cc=24&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=-240&u_his=1&u_java=true
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\More\Kitco - Gold Precious Metals -.. - kitco.com.url -> hxxp://www.kitco.com/
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\More\kitco.com market.url -> hxxp://www.kitco.com/market
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\More\msnbc.msn.com id 15332531... 2.url -> hxxp://www.msnbc.msn.com/id/15332531/site/newsweek/page/2
    InternetURL: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Desktop\7b29a6985812\Links\More\msnbc.msn.com id 15332531... 3.url -> hxxp://www.msnbc.msn.com/id/15332531/site/newsweek/page/3
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Radio Station Guide.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\RealPlayer Home Page.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Media\Real.com Radio Tuner.url -> hxxp://realguide.real.com/stations/
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\Customize Links.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=CLinks
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\RealPlayer.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\Windows Marketplace.url -> hxxp://go.microsoft.com/fwlink/?LinkId=30857&clcid=0x409
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\Windows Media.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windowsmedia
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Links\Windows.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windows
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Dell\Dell Auction.url -> hxxp://www.dellauction.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Dell\Dell Internet Security.url -> hxxp://support.dell.com/support/topics/global.aspx/support/security/security?c=us&cs=19&l=en&s=dhs
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Dell\Dell.url -> hxxp://www.dell.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser19\Favorites\Dell\Support.Dell.Com.url -> hxxp://support.dell.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Radio Station Guide.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\RealPlayer Home Page.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Media\Real.com Radio Tuner.url -> hxxp://realguide.real.com/stations/
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\Customize Links.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=CLinks
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\RealPlayer.url -> hxxp://www.real.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\Windows Marketplace.url -> hxxp://go.microsoft.com/fwlink/?LinkId=30857&clcid=0x409
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\Windows Media.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windowsmedia
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Links\Windows.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windows
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Dell\Dell Auction.url -> hxxp://www.dellauction.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Dell\Dell Internet Security.url -> hxxp://support.dell.com/support/topics/global.aspx/support/security/security?c=us&cs=19&l=en&s=dhs
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Dell\Dell.url -> hxxp://www.dell.com
    InternetURL: C:\Documents and Settings\QBDataServiceUser22\Favorites\Dell\Support.Dell.Com.url -> hxxp://support.dell.com

    ==================== End of log =============================
     
  13. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Download the enclosed file. (see below) Save it in the same location FRST is saved. Launch FRST and click on the Fix button. The tool will produce a log, Fixlog.txt. Please post its contents on your reply.

    While on FRST, type orcopy and paste the following in the edit box on FRST, after "Search:".

    netdde.exe;OSE.EXE;clipsrv.exe;aspnet_state.exe;ws2ifsl.sys;userinit.exe

    It then should look like:

    Search: netdde.exe;OSE.EXE;clipsrv.exe;aspnet_state.exe;ws2ifsl.sys;userinit.exe

    Click Search Files button and post the log (Search.txt) it will produce in your next reply.

    Why is this computer SP2 and not SP3?
     

    Attached Files:

  14. CindyJB

    CindyJB Thread Starter

    Joined:
    Jan 12, 2015
    Messages:
    10
    Thanks for your help. I am going to be away for a little while but will try this when I return. I'm planning to be back in about a week. I'm hoping someone will still be able to help after this.

    About the SP2 instead of SP3 - I'm not really computer literate and didn't know what version I had. I'm guessing I needed to update this.
     
  15. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    I'll wait until you come back.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1141059

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice