OTListIt logfile created on: 26/04/2009 6:14:02 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Pete&Adie\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.98% Memory free
4.00 Gb Paging File | 2.67 Gb Available in Paging File | 66.65% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.96 Gb Total Space | 78.12 Gb Free Space | 55.03% Space Free | Partition Type: NTFS
Drive D: | 7.09 Gb Total Space | 0.88 Gb Free Space | 12.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 76.32 Gb Total Space | 58.00 Gb Free Space | 76.00% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PETEANDADIE-PC
Current User Name: Pete&Adie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2007/10/19 14:19:22 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/02/05 14:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 14:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/19 10:47:24 | 00,109,056 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009/03/20 13:26:16 | 00,266,240 | —- | M] () – C:\Windows\system32\CSHelper.exe
PRC - [2006/12/14 19:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.exe
PRC - [2009/02/05 14:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 14:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/10/09 07:56:48 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
PRC - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2009/02/22 14:45:54 | 02,272,592 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
PRC - [2008/10/29 00:29:41 | 02,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\Explorer.EXE
PRC - [2008/01/19 01:38:38 | 01,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/09/28 07:42:24 | 00,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2006/11/20 05:34:52 | 00,155,648 | —- | M] (OsdMaestro) – C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2008/01/15 12:26:18 | 04,874,240 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2006/11/02 06:34:44 | 00,176,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wpcumi.exe
PRC - [2007/10/25 17:37:32 | 02,178,832 | —- | M] () – C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2009/03/02 20:16:04 | 00,247,296 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2007/10/25 17:33:22 | 00,563,984 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/05/21 12:19:24 | 00,143,360 | —- | M] () – C:\Program Files\HiYo\Bin\HiYo.exe
PRC - [2008/04/01 14:41:10 | 00,166,424 | —- | M] (Intel Corporation) – C:\Windows\System32\hkcmd.exe
PRC - [2008/04/01 14:41:26 | 00,133,656 | —- | M] (Intel Corporation) – C:\Windows\System32\igfxpers.exe
PRC - [2008/11/20 11:06:14 | 00,178,688 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2008/04/01 14:41:30 | 00,256,536 | —- | M] (Intel Corporation) – C:\Windows\system32\igfxsrvc.exe
PRC - [2008/11/04 13:09:58 | 00,615,696 | —- | M] (Research In Motion Limited) – C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/02/05 14:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/01/19 01:33:39 | 00,202,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/01/19 01:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008/01/19 01:33:30 | 01,233,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2006/11/23 18:53:24 | 01,480,296 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
PRC - [2008/01/19 01:33:33 | 00,037,888 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\unsecapp.exe
PRC - [2008/09/08 18:43:11 | 00,133,104 | —- | M] (Google Inc.) – C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe
PRC - [2008/03/06 13:42:51 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/02/19 14:23:24 | 00,202,064 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
PRC - [2007/03/11 21:26:24 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/01/09 13:32:08 | 00,789,008 | —- | M] (Logitech, Inc.) – C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2008/01/19 01:33:30 | 01,233,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/02/02 13:45:56 | 00,189,824 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\IMApp.exe
PRC - [2007/10/25 17:32:58 | 00,407,824 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2007/03/11 21:32:42 | 00,151,552 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
PRC - [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2008/06/19 19:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
PRC - [2008/01/19 01:33:04 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\system32\conime.exe
PRC - [2009/03/02 20:16:04 | 00,247,296 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2006/10/30 20:59:14 | 00,505,520 | —- | M] (Symantec Corporation) – C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
PRC - [2005/02/02 09:44:24 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\hp\kbd\kbd.exe
PRC - [2009/04/26 18:11:19 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/11/19 10:47:24 | 00,109,056 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon [Auto | Running])
SRV - [2008/01/19 01:33:43 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\apphostsvc.dll – (AppHostSvc [Auto | Running])
SRV - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2009/02/05 14:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2009/02/05 14:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 14:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 14:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 12:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found – – (CLTNetCnService [Auto | Stopped])
SRV - [2009/03/20 13:26:16 | 00,266,240 | —- | M] () – C:\Windows\system32\CSHelper.exe – (CSHelper [Auto | Running])
SRV - [2008/06/19 19:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Running])
SRV - [2009/03/25 15:28:42 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/10/09 07:56:48 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe – (HP Health Check Service [Auto | Running])
SRV - [2007/06/04 22:14:50 | 00,217,088 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Running])
SRV - [2007/06/04 22:14:50 | 00,131,072 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc [Auto | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 19:14:31 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2006/11/02 03:46:05 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\irmon.dll – (Irmon [Auto | Running])
SRV - [2008/01/09 13:30:08 | 00,121,360 | —- | M] (Logitech, Inc.) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe – (LBTServ [On_Demand | Stopped])
SRV - [2006/12/14 19:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2008/01/19 01:34:43 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\Windows\system32\lpdsvc.dll – (LPDSVC [Auto | Running])
SRV - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer [Auto | Running])
SRV - [2007/10/19 14:19:22 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv [Auto | Running])
SRV - [2007/10/19 14:21:16 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Auto | Stopped])
SRV - [2006/12/14 02:21:20 | 00,045,056 | —- | M] (Sony Corporation) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV [On_Demand | Stopped])
SRV - [2006/11/08 16:35:36 | 00,043,520 | —- | M] (Hewlett-Packard) – C:\Windows\system32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running])
SRV - [2008/06/19 19:14:31 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 16:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2006/12/14 01:46:16 | 00,057,344 | —- | M] () – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR [On_Demand | Stopped])
SRV - [2006/11/08 16:35:38 | 00,053,248 | —- | M] (Hewlett-Packard) – C:\Windows\system32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running])
SRV - [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort [Auto | Running])
SRV - [2007/06/15 16:55:00 | 00,300,544 | —- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer [On_Demand | Stopped])
SRV - [2006/12/14 02:02:08 | 00,069,632 | —- | M] (Sony Corporation) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV [On_Demand | Stopped])
SRV - [2006/11/01 13:58:02 | 00,078,752 | R— | M] (MicroVision Development, Inc.) – c:\Program Files\Common Files\SureThing Shared\stllssvr.exe – (stllssvr [On_Demand | Stopped])
SRV - [2008/01/19 01:34:32 | 00,371,200 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\iisw3adm.dll – (W3SVC [Auto | Running])
SRV - [2008/01/19 01:34:32 | 00,371,200 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\iisw3adm.dll – (WAS [On_Demand | Running])
SRV - [2008/01/19 01:38:24 | 00,272,952 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend [Auto | Running])
SRV - [2008/01/19 01:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
SRV - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.exe – (XAudioService [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2006/11/02 03:51:38 | 00,420,968 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 03:51:32 | 00,297,576 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpahci.sys – (adpahci [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,098,408 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 03:51:00 | 00,147,048 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 03:50:11 | 00,071,272 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 03:49:20 | 00,014,952 | —- | M] (Acer Laboratories Inc.) – C:\Windows\system32\drivers\aliide.sys – (aliide [Disabled | Stopped])
DRV - [2006/11/02 03:50:09 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arc.sys – (arc [Disabled | Stopped])
DRV - [2006/11/02 03:50:10 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arcsas.sys – (arcsas [Disabled | Stopped])
DRV - [2009/02/05 14:07:12 | 00,020,560 | —- | M] (ALWIL Software) – C:\Windows\system32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 14:06:59 | 00,051,792 | —- | M] (ALWIL Software) – C:\Windows\system32\DRIVERS\aswMonFlt.sys – (aswMonFlt [Auto | Running])
DRV - [2009/02/05 14:06:10 | 00,023,152 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys – (aswRdr [System | Running])
DRV - [2009/02/05 14:07:23 | 00,114,768 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2009/02/05 14:06:20 | 00,051,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys – (aswTdi [System | Running])
DRV - [2006/11/02 02:24:45 | 00,013,568 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 02:24:46 | 00,005,248 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 02:25:24 | 00,071,808 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserid.sys – (Brserid [Disabled | Stopped])
DRV - [2006/11/02 02:24:44 | 00,062,336 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 02:24:44 | 00,012,160 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 02:24:47 | 00,011,904 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 03:49:28 | 00,016,488 | —- | M] (CMD Technology, Inc.) – C:\Windows\system32\drivers\cmdide.sys – (cmdide [Disabled | Stopped])
DRV - [2006/11/02 01:30:54 | 00,117,760 | —- | M] (Intel Corporation) – C:\Windows\system32\DRIVERS\E1G60I32.sys – (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 03:51:34 | 00,316,520 | —- | M] (Emulex) – C:\Windows\system32\drivers\elxstor.sys – (elxstor [Disabled | Stopped])
DRV - [2009/03/19 16:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.) – C:\Windows\system32\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 03:50:10 | 00,037,480 | —- | M] (Hewlett-Packard Company) – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs [Disabled | Stopped])
DRV - [2008/05/08 05:03:18 | 00,980,992 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSX_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2008/05/08 05:05:18 | 00,266,752 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSXHWBS2.sys – (HSXHWBS2 [On_Demand | Running])
DRV - [2006/11/02 03:51:25 | 00,232,040 | —- | M] (Intel Corporation) – C:\Windows\system32\drivers\iastorv.sys – (iaStorV [Disabled | Stopped])
DRV - [2008/03/25 09:44:24 | 02,307,072 | —- | M] (Intel Corporation) – C:\Windows\system32\DRIVERS\igdkmd32.sys – (igfx [On_Demand | Running])
DRV - [2006/11/02 03:50:17 | 00,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\system32\drivers\iirsp.sys – (iirsp [Disabled | Stopped])
DRV - [2008/01/15 20:19:04 | 02,047,576 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\system32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2008/01/18 23:55:21 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\Windows\system32\DRIVERS\irsir.sys – (irsir [On_Demand | Stopped])
DRV - [2006/11/02 03:50:07 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 03:50:09 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteraid.sys – (iteraid [Disabled | Stopped])
DRV - [2007/04/11 15:32:30 | 00,020,496 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\L8042Kbd.sys – (L8042Kbd [On_Demand | Stopped])
DRV - [2007/11/29 03:17:34 | 00,063,120 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
DRV - [2007/11/29 03:17:48 | 00,035,088 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LHidFilt.Sys – (LHidFilt [On_Demand | Running])
DRV - [2007/11/29 03:17:56 | 00,036,368 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LMouFilt.Sys – (LMouFilt [On_Demand | Running])
DRV - [2007/11/29 03:18:04 | 00,078,992 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
DRV - [2006/11/02 03:50:04 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 03:50:05 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 03:50:10 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
DRV - [2007/04/11 15:33:14 | 00,028,688 | —- | M] (Logitech, Inc.) – C:\Windows\System32\Drivers\LUsbFilt.Sys – (LUsbFilt [On_Demand | Stopped])
DRV - [2007/10/19 14:16:30 | 02,109,976 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LVcKap.sys – (LVcKap [On_Demand | Stopped])
DRV - [2007/10/11 19:59:02 | 02,142,488 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 19:59:24 | 00,025,624 | —- | M] () – C:\Windows\system32\DRIVERS\LVPr2Mon.sys – (LVPr2Mon [On_Demand | Running])
DRV - [2007/10/11 20:00:42 | 00,041,752 | —- | M] (Logitech Inc.) – C:\Windows\system32\drivers\LVUSBSta.sys – (LVUSBSta [On_Demand | Running])
DRV - [2006/06/19 08:26:58 | 00,012,672 | —- | M] (Conexant) – C:\Windows\system32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2006/11/02 03:49:53 | 00,028,776 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\megasas.sys – (megasas [Disabled | Stopped])
DRV - [2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\Windows\system32\DRIVERS\motmodem.sys – (motmodem [On_Demand | Stopped])
DRV - [2006/11/02 03:49:59 | 00,033,384 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 03:50:19 | 00,045,160 | —- | M] (IBM Corporation) – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 01:36:50 | 00,020,608 | —- | M] (N-trig Innovative Technologies) – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 03:50:24 | 00,088,680 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvraid.sys – (nvraid [Disabled | Stopped])
DRV - [2006/11/02 03:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvstor.sys – (nvstor [Disabled | Stopped])
DRV - [2007/10/11 19:56:20 | 00,490,776 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LV561AV.SYS – (PID_0928 [On_Demand | Running])
DRV - [2005/12/12 10:27:00 | 00,019,072 | —- | M] (Hewlett-Packard Company) – C:\Windows\system32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Running])
DRV - [2006/07/24 05:00:00 | 00,036,528 | —- | M] (Sonic Solutions) – C:\Windows\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/02 03:51:45 | 00,900,712 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,106,088 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped])
DRV - [2008/09/10 18:47:24 | 00,031,104 | —- | M] (Research In Motion Limited) – C:\Windows\System32\Drivers\BlackBerrySCRDriver.sys – (Rim [On_Demand | Stopped])
DRV - [2008/05/20 20:33:50 | 00,022,784 | —- | M] (Research In Motion Limited) – C:\Windows\System32\Drivers\RimUsb.sys – (RimUsb [On_Demand | Stopped])
DRV - [2007/01/18 10:24:58 | 00,026,496 | —- | M] (Research in Motion Ltd) – C:\Windows\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Running])
DRV - [2008/01/18 23:57:15 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV - [2008/12/23 04:47:52 | 00,138,240 | —- | M] (Realtek Corporation ) – C:\Windows\system32\DRIVERS\Rtlh86.sys – (RTL8169 [On_Demand | Running])
DRV - [2006/11/02 00:37:21 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running])
DRV - [2006/11/02 03:50:10 | 00,038,504 | —- | M] (Silicon Integrated Systems Corp.) – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 03:50:16 | 00,071,784 | —- | M] (Silicon Integrated Systems) – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
DRV - [2006/11/02 03:50:05 | 00,035,944 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 03:49:56 | 00,031,848 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 03:50:03 | 00,034,920 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 03:51:25 | 00,235,112 | —- | M] (ULi Electronics Inc.) – C:\Windows\system32\drivers\uliahci.sys – (uliahci [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,098,408 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata.sys – (UlSata [Disabled | Stopped])
DRV - [2006/11/02 03:50:45 | 00,115,816 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped])
DRV - [2008/11/07 15:23:30 | 00,032,000 | —- | M] (Apple, Inc.) – C:\Windows\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2006/11/02 03:49:30 | 00,017,512 | —- | M] (VIA Technologies, Inc.) – C:\Windows\system32\drivers\viaide.sys – (viaide [Disabled | Stopped])
DRV - [2006/11/02 03:50:41 | 00,112,232 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped])
DRV - [2006/11/02 01:41:53 | 00,251,904 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\VSTBS23.SYS – (VSTHWBS2 [On_Demand | Stopped])
DRV - [2006/11/02 01:41:50 | 00,987,648 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\VSTDPV3.SYS – (VST_DPV [On_Demand | Stopped])
DRV - [2008/05/08 05:04:16 | 00,661,504 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2007/10/18 07:36:54 | 00,008,704 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.sys – (XAudio [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://sympatico.msn.ca/?lang=en-CA&OCID=FW69157
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 A8 12 1E 2D C6 C9 01 [binary data]
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\S-1-5-21-961656175-201489447-2584037788-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\S-1-5-21-961656175-201489447-2584037788-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Yahoo Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/ig?hl=en"
FF - prefs.js..extensions.enabledItems: {f02289b7-b23a-49b1-a7da-b60880e69629}:1.300.199
FF - prefs.js..extensions.enabledItems: [removed]:0.8.1
FF - prefs.js..extensions.enabledItems: {47624dda-b77e-4feb-820a-e4f077d5d4ca}:9.3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:3.9.1
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:2.7.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.2
FF - prefs.js..extensions.enabledItems: {249df6a2-e336-47d1-b6c3-ec711ad140ca}:0.4.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:1.6.11
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.9
FF - prefs.js..extensions.enabledItems: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374}:3.0.4
FF - prefs.js..extensions.enabledItems: {469CEB59-8266-438b-91D9-82F56D595E15}:2.3
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.29
FF - prefs.js..extensions.enabledItems: [removed]:3.6.0
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:2.1.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9
FF - prefs.js..extensions.enabledItems: {BB359C50-BFC9-4f40-8302-3FE5A499A859}:3.2
FF - prefs.js..extensions.enabledItems: {55c25c30-73c7-11dd-ad8b-0800200c9a66}:2.9.1
FF - prefs.js..extensions.enabledItems: {66871bd1-5ba2-4739-b485-2a15f5969bd8}:2.081108
FF - prefs.js..extensions.enabledItems: {BF32D2C8-9C75-404b-ACF4-880DB4679236}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20090322
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.08
FF - prefs.js..extensions.enabledItems: {5f0a19e0-2921-11dd-bd0b-0800200c9a66}:1.00.49
FF - prefs.js..extensions.enabledItems: {ff356687-aa08-463d-a46c-11c451824939}:[removed]
FF - prefs.js..extensions.enabledItems: {F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}:3.2
FF - prefs.js..extensions.enabledItems: {33A8946C-B859-4f7d-8382-ADAB29623DEE}:3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {285da7e0-729d-11db-9fe1-0800200c9a66}:2.121408
FF - prefs.js..extensions.enabledItems: {C288E3D6-3588-4b60-BD4A-7413899D269B}:1.1
FF - prefs.js..keyword.URL: "
http://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&ei=utf-8&yahoo_domain=search.yahoo.com&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2 [2008/09/10 21:28:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/10/04 15:21:05 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/14 15:21:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/23 08:52:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/23 08:52:34 | 00,000,000 | —D | M]
[2008/12/25 11:49:18 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions
[2008/08/26 09:06:59 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/25 11:49:18 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions\[removed]
[2009/04/26 16:38:51 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions
[2009/04/17 10:27:37 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/03/27 12:58:50 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/04/10 22:39:36 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{249df6a2-e336-47d1-b6c3-ec711ad140ca}
[2008/12/21 13:07:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{285da7e0-729d-11db-9fe1-0800200c9a66}
[2009/01/06 22:31:51 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/03/24 12:56:58 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}
[2008/07/30 20:46:08 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2009/03/19 22:19:28 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{469CEB59-8266-438b-91D9-82F56D595E15}
[2009/03/19 22:19:25 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca}
[2008/10/15 19:31:10 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{55c25c30-73c7-11dd-ad8b-0800200c9a66}
[2008/09/19 09:50:34 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{5f0a19e0-2921-11dd-bd0b-0800200c9a66}
[2009/04/24 13:12:19 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2008/09/15 18:15:54 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}(300)
[2008/08/26 09:10:06 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2008/10/20 10:30:06 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2009/04/24 13:12:16 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/03/22 11:08:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}
[2008/03/07 08:42:34 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}(139)
[2009/02/17 19:43:33 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2008/12/09 15:01:58 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{C288E3D6-3588-4b60-BD4A-7413899D269B}
[2009/04/21 17:31:35 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2009/03/24 14:25:25 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/03/20 13:27:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}
[2009/03/24 12:56:40 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}
[2008/03/07 08:42:38 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}(140)
[2008/09/16 13:33:54 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}(301)
[2009/03/26 08:51:04 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{ff356687-aa08-463d-a46c-11c451824939}
[2009/01/29 10:13:55 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/10 23:35:59 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/24 13:12:19 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/09/12 10:06:15 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/12/23 10:46:55 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/03/16 21:22:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/10/15 19:32:47 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/03/27 12:57:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/09/10 20:06:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/17 10:27:31 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/17 10:27:31 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]-trash
[2008/09/16 11:32:03 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\pink-bee@loic(299).com
[2009/02/14 22:39:52 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/10/15 19:30:27 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:56 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]\chrome
[2009/03/24 12:57:07 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}\chrome\mozapps\extensions
[2009/03/23 19:06:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}\chrome\mozapps\extensions
[2009/03/22 11:08:48 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}\chrome\mozapps\extensions
[2009/03/24 12:56:45 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}\chrome\mozapps\extensions
[2008/12/23 20:19:23 | 00,001,632 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\live-search.xml
[2008/09/21 18:18:20 | 00,002,137 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\MyStart Search.xml
[2009/03/20 20:09:04 | 00,000,872 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.gif
[2009/03/20 20:09:04 | 00,000,466 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.src
[2009/03/20 20:09:04 | 00,001,767 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.xml
[2009/04/10 11:00:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/23 08:52:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/14 11:59:33 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/14 11:03:55 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/11/01 22:01:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/03/05 23:49:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/10 11:00:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/23 08:52:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 08:52:30 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/19 13:33:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 13:33:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 13:33:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 13:33:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 13:33:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 13:33:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 13:33:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background (Research In Motion Limited)
O4 - HKLM..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.EXE ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" (OsdMaestro)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [Google Update] "C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c (IncrediMail, Ltd.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe ()
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m (IObit)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe (soft thinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: IE Theme Search Bar - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm ()
O9 - Extra 'Tools' menuitem : Free Themes for Internet Explorer - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm ()
O9 - Extra 'Tools' menuitem : Online Themes Gallery - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe (Eye Can Publishing)
O9 - Extra 'Tools' menuitem : Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe (Eye Can Publishing)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Reg Error: Value error.)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\SYSTEM32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{d0380e54-b893-11dc-88ea-001921f5f9ba}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/04/26 18:11:06 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe
[2009/04/25 23:20:44 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Local\Apple Computer
[2009/04/24 15:23:20 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Composer
[2009/04/21 11:11:40 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Malwarebytes
[2009/04/21 11:11:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/21 11:11:30 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/21 11:11:27 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/21 11:11:26 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/18 12:26:41 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/18 12:24:49 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/04/18 12:24:28 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/18 10:29:08 | 00,026,624 | —- | C] () – C:\Users\Pete&Adie\Documents\Adriennes cleaning schedule.xls
[2009/04/14 20:05:49 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/14 20:05:46 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/14 20:05:46 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/14 20:05:33 | 00,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/04/14 20:05:32 | 03,599,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/04/14 20:05:31 | 03,547,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/04/14 20:05:29 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/04/14 20:05:28 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/14 20:05:28 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/14 20:05:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/04/14 20:05:27 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/14 20:05:27 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/14 20:05:27 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/14 20:05:16 | 01,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/04/14 20:05:15 | 00,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/14 20:05:13 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/14 20:05:13 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/14 20:05:13 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/11 10:32:43 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/04/11 10:32:42 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/04/11 10:32:42 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/04/11 10:32:42 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/04/11 10:32:42 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/04/11 10:32:40 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/04/11 10:32:40 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/11 10:32:40 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/04/11 10:32:39 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/04/11 10:32:39 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/04/11 10:32:39 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/04/11 10:32:38 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/11 10:32:38 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/04/11 10:32:38 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/04/11 10:32:38 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/04/11 10:32:37 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/04/11 10:32:37 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/04/11 10:32:36 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/11 10:32:36 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/04/11 10:32:36 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/11 10:32:36 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/04/11 10:32:36 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/04/11 10:32:35 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/04/11 10:32:35 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/04/11 10:32:35 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/04/11 10:32:35 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/04/11 10:32:35 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/04/11 10:32:35 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/04/11 10:32:34 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/11 10:32:34 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/11 10:32:34 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/04/11 10:32:33 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/04/11 10:32:32 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/04/11 10:32:32 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/04/11 10:32:31 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/04/11 10:32:31 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/04/11 10:32:30 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/11 10:32:28 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/11 10:32:28 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/04/11 10:32:28 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/04/11 10:32:27 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/04/11 10:32:27 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/11 10:32:27 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/04/11 10:32:27 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/04/11 10:32:27 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/04/11 10:32:27 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/04/11 10:32:27 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/04/11 10:32:26 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/11 10:32:26 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/04/11 10:32:25 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/11 10:32:24 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/11 10:32:23 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/04/11 10:32:22 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/11 10:32:21 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/07 16:41:38 | 00,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/07 16:40:30 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/04/07 16:40:20 | 00,000,000 | —D | C] – C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/07 16:40:20 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/04/07 16:33:57 | 00,000,227 | —- | C] () – C:\Users\Pete&Adie\Desktop\Sound - Shortcut.lnk
[2009/04/07 11:26:42 | 00,001,893 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/03/31 14:42:53 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/03/30 18:01:12 | 00,225,280 | —- | C] () – C:\Windows\System32\net_rim_plazmic_flint_dialog.dll
[2009/03/30 18:01:08 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Plazmic
[2009/03/30 17:58:55 | 00,000,000 | —D | C] – C:\Program Files\Plazmic CDK 4.7
[2009/03/30 17:58:40 | 00,000,000 | -H-D | C] – C:\Program Files\Zero G Registry
[2009/03/13 18:07:13 | 00,000,227 | —- | C] () – C:\Windows\AvDetected.ini
[2009/01/17 14:49:36 | 00,000,087 | —- | C] () – C:\Windows\ka.ini
[2009/01/15 14:10:02 | 00,001,554 | —- | C] () – C:\Windows\yahtzee.ini
[2008/12/21 15:42:38 | 00,000,119 | —- | C] () – C:\Windows\mrpotato.ini
[2008/07/23 10:50:52 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/07/23 10:47:34 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/07/23 10:47:34 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/07/23 10:46:38 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/26 16:42:08 | 00,000,000 | —- | C] () – C:\Windows\setup32.INI
[2008/04/02 21:06:53 | 00,012,288 | —- | C] () – C:\Windows\impborl.dll
[2008/03/25 09:56:08 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1461.dll
[2008/03/24 22:18:04 | 00,000,252 | —- | C] () – C:\Windows\phedit.ini
[2008/03/24 22:03:50 | 00,210,944 | —- | C] () – C:\Windows\System32\msvcrt10.dll
[2008/03/24 22:03:50 | 00,005,515 | —- | C] () – C:\Windows\fmachine.ini
[2008/02/25 16:34:49 | 00,059,500 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2008/01/02 17:57:36 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2007/10/22 09:44:38 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/10/11 19:59:24 | 00,025,624 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2007/09/04 13:48:13 | 00,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007/09/04 13:48:13 | 00,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2007/08/24 12:46:48 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/01 20:48:55 | 00,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2007/03/10 03:02:56 | 00,102,400 | —- | C] () – C:\Windows\System32\pywintypes24.dll
[2007/03/10 03:02:55 | 00,327,680 | —- | C] () – C:\Windows\System32\pythoncom24.dll
[2007/03/10 02:55:09 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1132.dll
[2007/03/06 12:49:42 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1227.dll
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2007/01/10 05:56:34 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 04:23:31 | 00,000,436 | —- | C] () – C:\Windows\win.ini
[2006/11/02 04:23:31 | 00,000,235 | —- | C] () – C:\Windows\system.ini
[2006/11/02 01:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/08/11 01:00:40 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/08/11 01:00:40 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
========== Files - Modified Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/04/26 18:15:00 | 00,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{017B901C-58CB-49BD-A4C4-916A2BA03B41}.job
[2009/04/26 18:11:19 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe
[2009/04/26 16:52:15 | 00,003,680 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/26 16:52:15 | 00,003,680 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/26 12:50:13 | 00,000,430 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F40F8D07-D9D7-4C72-83BB-10C4B4A44DDF}.job
[2009/04/26 12:39:10 | 00,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2009/04/26 11:24:28 | 00,000,378 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2009/04/26 10:52:19 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/26 10:52:09 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/26 10:50:57 | 06,291,456 | -H– | M] () – C:\Users\Pete&Adie\AppData\Local\IconCache.db
[2009/04/19 21:20:25 | 00,000,436 | —- | M] () – C:\Windows\win.ini
[2009/04/18 11:21:49 | 00,026,624 | —- | M] () – C:\Users\Pete&Adie\Documents\Adriennes cleaning schedule.xls
[2009/04/15 08:21:19 | 00,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-961656175-201489447-2584037788-1000.job
[2009/04/11 10:33:28 | 00,652,874 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/11 10:33:27 | 00,764,022 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/11 10:33:27 | 00,123,742 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/08 20:15:43 | 00,168,448 | —- | M] () – C:\Users\Pete&Adie\Desktop\Superintendent Diary.xls
[2009/04/07 16:41:38 | 00,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/07 16:33:57 | 00,000,227 | —- | M] () – C:\Users\Pete&Adie\Desktop\Sound - Shortcut.lnk
[2009/04/07 11:26:42 | 00,001,893 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/04/06 18:33:36 | 00,030,720 | —- | M] () – C:\Users\Pete&Adie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/06 08:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/03/31 20:29:03 | 00,089,160 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2009/03/31 14:42:53 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/03/30 18:06:30 | 00,089,160 | —- | M] () – C:\Users\Pete&Adie\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/03/30 18:04:25 | 00,352,480 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/03/29 18:28:05 | 00,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2009/03/28 22:12:02 | 00,002,595 | —- | M] () – C:\Users\Pete&Adie\Desktop\Microsoft Word.lnk
========== LOP Check ==========
[2009/04/26 11:24:28 | 00,000,378 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2009/04/26 12:39:10 | 00,000,868 | —- | M] () – C:\Windows\Tasks\Google Software Updater.job
[2009/04/15 08:21:19 | 00,000,872 | —- | M] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-961656175-201489447-2584037788-1000.job
[2009/04/26 10:52:19 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/26 10:51:08 | 00,032,636 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/04/26 18:15:00 | 00,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{017B901C-58CB-49BD-A4C4-916A2BA03B41}.job
[2009/04/26 12:50:13 | 00,000,430 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F40F8D07-D9D7-4C72-83BB-10C4B4A44DDF}.job
========== Purity Check ==========
< End of report >