willyontour
Topic Starter
Here's my OTL log (quick scan) - extra registry set to "none" all others so save list
OTL logfile created on: 6/15/2010 9:47:02 AM - Run 6
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Adam\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 66.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.40 Gb Total Space | 67.79 Gb Free Space | 23.92% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM_GEN
Current User Name: Adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe ()
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere.exe (WebToGo Mobiles Internet GmbH)
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Launcher.exe ()
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (InternetEverywhere_Service) – C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe ()
SRV - (Macromedia Licensing Service) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VSS) – C:\Windows\Vss [2009/07/14 06:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/14 06:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (ewsercd) – C:\Windows\SysNative\drivers\ewsercd.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (ALWIL Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (ALWIL Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwififlt) – C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (hwusbfake) – C:\Windows\SysNative\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\SysWOW64\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\SysWOW64\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (ewsercd) – C:\Windows\SysWOW64\drivers\ewsercd.sys (Huawei Technologies Co., Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.hotmail.com/"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.gopher_port: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/11 21:21:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/09 18:55:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/13 20:02:20 | 000,000,000 | —D | M]
[2009/11/12 11:56:57 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Mozilla\Extensions
[2010/05/16 10:32:43 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\md2mcmep.default\extensions
[2010/05/09 18:55:02 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/07 11:52:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/01 19:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 19:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 19:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 19:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/06/11 00:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (WsftpBrowserHelper Class) - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files (x86)\Ipswitch\WS_FTP Pro\wsbho2k0.dll (Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0de2d712-5f3a-11df-9183-0025646d1823}\Shell - "" = AutoRun
O33 - MountPoints2\{0de2d712-5f3a-11df-9183-0025646d1823}\Shell\AutoRun\command - "" = F:\.\Setup.exe – File not found
O33 - MountPoints2\{b1614f0d-f432-11de-995a-0025646d1823}\Shell - "" = AutoRun
O33 - MountPoints2\{b1614f0d-f432-11de-995a-0025646d1823}\Shell\AutoRun\command - "" = E:\.\Setup.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\.\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 90 Days ==========
[2010/06/14 08:24:28 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\Shabbas
[2010/06/02 14:12:22 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\InternetEverywhere
[2010/06/02 14:12:12 | 000,691,712 | —- | C] (DiBcom SA) – C:\Windows\SysWow64\drivers\mod7700.sys
[2010/06/02 14:12:12 | 000,132,608 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbnet.sys
[2010/06/02 14:12:12 | 000,116,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbmdm.sys
[2010/06/02 14:12:12 | 000,116,224 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbfake.sys
[2010/06/02 14:12:12 | 000,112,896 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewsercd.sys
[2010/06/02 14:12:12 | 000,029,696 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\SysWow64\drivers\ewdcsc.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewsercd.sys
[2010/06/02 14:12:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\InternetEverywhere
[2010/06/02 14:10:12 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Temp
[2010/05/29 08:46:43 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\TOWN HOUSE
[2010/05/25 19:48:15 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/05/25 19:48:14 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/05/22 17:12:59 | 000,000,000 | —D | C] – C:\Users\Adam\Vital Pet Products
[2010/05/22 12:35:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vital
[2010/05/21 11:23:08 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/05/17 11:57:18 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2010/05/17 10:55:37 | 000,121,936 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/05/17 10:55:37 | 000,028,752 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/05/17 10:55:37 | 000,022,096 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/05/17 10:55:35 | 000,051,280 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/05/17 10:55:34 | 000,063,568 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/05/17 10:55:05 | 000,165,032 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/05/17 10:55:05 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/05/17 10:55:03 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/17 10:55:03 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/05/16 10:40:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/14 13:06:27 | 000,116,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewusbmdm.sys
[2010/05/13 18:29:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Easy Text To HTML Converter
[2010/05/13 18:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Text To HTML Converter
[2010/05/13 18:21:18 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\SoftwareDownload
[2010/05/13 08:55:27 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/05/12 16:33:35 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Monster Pet Supplies
[2010/05/12 16:32:16 | 000,000,000 | —D | C] – C:\Monster Pet Supplies
[2010/05/12 08:33:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/09 19:03:39 | 000,000,000 | —D | C] – C:\Users\Adam\DoctorWeb
[2010/05/08 13:30:43 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Lonely Planet
[2010/05/08 13:30:24 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Water For People
[2010/05/07 12:02:30 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Malwarebytes
[2010/05/07 12:02:22 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/07 12:02:21 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/07 12:02:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/07 12:02:21 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/06 15:59:15 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/05/06 15:59:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/05/06 15:50:56 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/05/05 15:53:19 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\U3
[2010/05/04 19:21:40 | 000,000,000 | R–D | C] – C:\Users\Adam\Documents\My Dropbox
[2010/05/04 19:20:17 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Dropbox
[2010/04/17 18:12:01 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\SoundSpectrum
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\PDF Writer
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Local\PDF Writer
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\ProgramData\PDF Writer
[2010/04/13 11:45:35 | 000,227,840 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzFlRdr.dll
[2010/04/13 11:45:35 | 000,135,168 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzpdfc.dll
[2010/04/13 11:45:35 | 000,103,424 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzDCT.dll
[2010/04/13 11:45:35 | 000,008,192 | —- | C] (bioPDF) – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.dll
[2010/04/13 11:45:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bullzip
[2010/04/13 11:45:32 | 000,212,480 | —- | C] (Bullzip) – C:\Windows\SysNative\bzpdf.dll
[2010/04/13 11:45:29 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/04/11 21:21:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/04/11 21:21:25 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/04/11 21:21:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2010/04/11 21:21:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Real
[2010/04/11 21:21:22 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010/04/11 21:21:20 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Real
[2010/04/11 16:17:44 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/04/09 10:49:00 | 000,000,000 | —D | C] – C:\Documents
[2010/04/06 18:34:23 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Music info
[2010/04/03 14:37:55 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\TeamViewer
[2010/04/03 14:37:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamViewer
[2010/04/03 14:20:57 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Remote Assistance Logs
[2010/04/03 08:51:50 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/03 08:51:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/04/01 15:42:09 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Zoom
[2010/03/22 20:01:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\SopCast
[2010/03/22 19:08:30 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2010/03/22 19:08:30 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2010/03/22 19:08:16 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2010/03/22 19:08:16 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2010/03/22 19:08:16 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2010/03/22 19:08:16 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2010/03/22 19:08:16 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2010/03/22 19:08:16 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2010/03/22 19:08:16 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2010/03/22 19:08:16 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2010/03/22 19:08:16 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2010/03/22 19:08:16 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2010/03/22 19:08:16 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2010/03/22 19:08:16 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2010/03/22 19:08:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2010/03/22 16:29:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\PrintFolders
[2010/03/22 00:29:04 | 000,000,000 | —D | C] – C:\Users\Adam\EurekaLog
[2010/03/20 19:28:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2010/03/20 19:10:34 | 000,000,000 | —D | C] – C:\Program Files\DivX_3.1alpha
[2010/03/20 18:53:26 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\MPEG-4v3_codec_fix
[2010/03/20 10:17:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xvid
[2010/03/20 09:55:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\bobyte
[2010/03/20 08:30:19 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\Movies
[2010/03/20 08:20:38 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Bowling - Alleygators
========== Files - Modified Within 90 Days ==========
[2010/06/15 09:50:10 | 007,077,888 | -HS- | M] () – C:\Users\Adam\NTUSER.DAT
[2010/06/15 09:39:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001UA.job
[2010/06/15 09:17:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/15 08:17:00 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/15 08:06:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/15 08:06:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/15 08:03:23 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/15 08:03:23 | 000,619,642 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/15 08:03:23 | 000,107,792 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/15 07:58:59 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/15 07:58:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/15 07:58:43 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2010/06/14 22:30:46 | 003,383,167 | -H– | M] () – C:\Users\Adam\AppData\Local\IconCache.db
[2010/06/14 17:39:00 | 000,000,850 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001Core.job
[2010/06/11 11:25:30 | 002,358,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/10 07:40:28 | 000,002,400 | —- | M] () – C:\Users\Adam\Desktop\Google Chrome.lnk
[2010/06/09 13:56:00 | 000,243,001 | —- | M] () – C:\Users\Adam\Desktop\MOVING_SALE[1].pdf
[2010/06/09 10:27:15 | 000,095,744 | —- | M] () – C:\Users\Adam\Desktop\2010.06.14 INVOICE Adam Williams.xls
[2010/06/09 07:26:20 | 000,082,944 | —- | M] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/03 17:09:38 | 002,895,360 | —- | M] () – C:\Users\Adam\Documents\mpawilliams.appendix.doc
[2010/06/03 09:24:12 | 000,014,733 | —- | M] () – C:\Users\Adam\Desktop\Hairstyle.docx
[2010/06/02 14:12:09 | 000,002,039 | —- | M] () – C:\Users\Public\Desktop\Internet Everywhere.lnk
[2010/06/02 14:12:03 | 000,002,104 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk
[2010/06/02 14:12:02 | 000,691,712 | —- | M] (DiBcom SA) – C:\Windows\SysWow64\drivers\mod7700.sys
[2010/06/02 14:12:02 | 000,132,608 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbnet.sys
[2010/06/02 14:12:02 | 000,116,864 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbmdm.sys
[2010/06/02 14:12:02 | 000,116,224 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbfake.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewsercd.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewsercd.sys
[2010/06/02 14:12:02 | 000,029,696 | —- | M] (Huawei Tech. Co., Ltd.) – C:\Windows\SysWow64\drivers\ewdcsc.sys
[2010/06/01 21:27:52 | 000,032,768 | —- | M] () – C:\Users\Adam\Desktop\BAGAGGA MOLDECHAI.doc
[2010/05/30 11:17:40 | 098,966,519 | —- | M] () – C:\Users\Adam\Desktop\Dick Weber Bowling.wmv
[2010/05/29 22:03:29 | 000,013,012 | —- | M] () – C:\Users\Adam\Desktop\Elaine.docx
[2010/05/28 09:11:52 | 000,008,080 | —- | M] () – C:\Users\Adam\Desktop\lmsfwctickets.fifa.com - PrintTicketResult.pdf
[2010/05/26 17:00:39 | 000,176,688 | —- | M] () – C:\Users\Adam\Desktop\Toxoplasmosis.docx
[2010/05/26 14:41:24 | 000,110,870 | —- | M] () – C:\Users\Adam\Desktop\Zaiden invite.jpg
[2010/05/26 13:22:33 | 000,029,446 | —- | M] () – C:\Users\Adam\Desktop\Street art festival June 5, 11am.jpg
[2010/05/24 17:33:02 | 000,001,945 | —- | M] () – C:\Users\Public\Desktop\Vital Pet Products Catalogue.lnk
[2010/05/19 11:32:17 | 000,181,541 | —- | M] () – C:\Users\Adam\Desktop\Marks - China May 2010.pdf
[2010/05/17 10:55:38 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/17 10:55:34 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/05/16 10:36:07 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$Let.docx
[2010/05/16 10:33:39 | 000,016,506 | —- | M] () – C:\Users\Adam\Desktop\Let.docx
[2010/05/16 10:32:44 | 000,000,033 | —- | M] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/05/14 13:06:27 | 000,116,864 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewusbmdm.sys
[2010/05/14 11:14:09 | 000,011,276 | —- | M] () – C:\Users\Adam\Desktop\Hi Melissa.docx
[2010/05/13 18:21:19 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\To HTML-Markdown.lnk
[2010/05/13 11:50:01 | 000,100,750 | —- | M] () – C:\Users\Adam\Desktop\ANZ details.JPG
[2010/05/13 11:37:03 | 000,134,290 | —- | M] () – C:\Users\Adam\Desktop\Wii charger amazon order.JPG
[2010/05/13 08:55:35 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/05/12 08:43:46 | 000,002,971 | —- | M] () – C:\Users\Adam\Desktop\HiJackThis.lnk
[2010/05/12 08:41:39 | 001,402,880 | —- | M] () – C:\Users\Adam\Desktop\HiJackThis.msi
[2010/05/11 17:23:17 | 000,018,905 | —- | M] () – C:\Users\Adam\Documents\Schools order form.xlsx
[2010/05/09 18:55:04 | 000,001,905 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/07 12:02:24 | 000,000,975 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/06 23:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/05/06 23:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/05/06 23:39:27 | 000,051,280 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/05/06 23:39:06 | 000,121,936 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/05/06 23:34:30 | 000,028,752 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/05/06 23:34:14 | 000,063,568 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/05/06 23:33:50 | 000,022,096 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/05/06 15:59:23 | 000,001,224 | —- | M] () – C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk
[2010/05/04 19:21:40 | 000,001,042 | —- | M] () – C:\Users\Adam\Desktop\Dropbox.lnk
[2010/05/03 11:28:52 | 000,010,555 | —- | M] () – C:\Users\Adam\Documents\Map to Naguru Vale.docx
[2010/04/30 15:49:54 | 000,016,896 | —- | M] () – C:\Users\Adam\Desktop\Baby_Group_Apr'10.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/28 08:52:54 | 000,116,480 | —- | M] () – C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/22 07:49:04 | 000,001,976 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/20 14:53:54 | 000,148,529 | —- | M] () – C:\Users\Adam\Documents\title screen.pptx
[2010/04/13 16:30:38 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$nce floor fillers.docx
[2010/04/13 11:45:39 | 000,002,100 | —- | M] () – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010/04/11 21:21:25 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/04/11 17:34:22 | 000,001,814 | —- | M] () – C:\Users\Public\Desktop\Vuze.lnk
[2010/04/11 13:02:30 | 000,119,296 | —- | M] () – C:\Users\Adam\Documents\Hard drive contents.xls
[2010/04/07 13:33:30 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$NGS FOR ALICE PARTY.docx
[2010/04/06 22:57:00 | 000,010,524 | —- | M] () – C:\Users\Adam\Desktop\Colourful.docx
[2010/03/28 11:55:24 | 000,016,479 | —- | M] () – C:\Users\Adam\Documents\Woodstock 1969 Lineup.docx
[2010/03/22 16:29:07 | 000,001,159 | —- | M] () – C:\Users\Adam\Desktop\PrintFolders.lnk
========== Files Created - No Company Name ==========
[2010/06/09 13:56:00 | 000,243,001 | —- | C] () – C:\Users\Adam\Desktop\MOVING_SALE[1].pdf
[2010/06/09 10:27:15 | 000,095,744 | —- | C] () – C:\Users\Adam\Desktop\2010.06.14 INVOICE Adam Williams.xls
[2010/06/03 17:09:38 | 002,895,360 | —- | C] () – C:\Users\Adam\Documents\mpawilliams.appendix.doc
[2010/06/02 22:37:27 | 000,014,733 | —- | C] () – C:\Users\Adam\Desktop\Hairstyle.docx
[2010/06/02 14:12:09 | 000,002,039 | —- | C] () – C:\Users\Public\Desktop\Internet Everywhere.lnk
[2010/06/02 14:12:03 | 000,002,104 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk
[2010/06/02 07:29:41 | 000,032,768 | —- | C] () – C:\Users\Adam\Desktop\BAGAGGA MOLDECHAI.doc
[2010/05/30 11:10:17 | 098,966,519 | —- | C] () – C:\Users\Adam\Desktop\Dick Weber Bowling.wmv
[2010/05/29 22:03:29 | 000,013,012 | —- | C] () – C:\Users\Adam\Desktop\Elaine.docx
[2010/05/29 08:10:23 | 002,202,974 | R— | C] () – C:\Users\Adam\Desktop\PaulRobesonCharlesPenrose-TheLaughingPoliceman1926incomplete.mp3
[2010/05/28 09:11:50 | 000,008,080 | —- | C] () – C:\Users\Adam\Desktop\lmsfwctickets.fifa.com - PrintTicketResult.pdf
[2010/05/26 16:51:36 | 000,176,688 | —- | C] () – C:\Users\Adam\Desktop\Toxoplasmosis.docx
[2010/05/26 14:41:24 | 000,110,870 | —- | C] () – C:\Users\Adam\Desktop\Zaiden invite.jpg
[2010/05/26 13:22:33 | 000,029,446 | —- | C] () – C:\Users\Adam\Desktop\Street art festival June 5, 11am.jpg
[2010/05/24 17:33:02 | 000,001,945 | —- | C] () – C:\Users\Public\Desktop\Vital Pet Products Catalogue.lnk
[2010/05/19 11:32:17 | 000,181,541 | —- | C] () – C:\Users\Adam\Desktop\Marks - China May 2010.pdf
[2010/05/17 10:55:38 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/17 10:55:34 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/05/16 10:36:07 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$Let.docx
[2010/05/16 10:33:39 | 000,016,506 | —- | C] () – C:\Users\Adam\Desktop\Let.docx
[2010/05/16 10:32:44 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/05/14 11:14:09 | 000,011,276 | —- | C] () – C:\Users\Adam\Desktop\Hi Melissa.docx
[2010/05/13 18:21:19 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\To HTML-Markdown.lnk
[2010/05/13 11:50:01 | 000,100,750 | —- | C] () – C:\Users\Adam\Desktop\ANZ details.JPG
[2010/05/13 11:37:03 | 000,134,290 | —- | C] () – C:\Users\Adam\Desktop\Wii charger amazon order.JPG
[2010/05/12 08:43:46 | 000,002,971 | —- | C] () – C:\Users\Adam\Desktop\HiJackThis.lnk
[2010/05/12 08:41:29 | 001,402,880 | —- | C] () – C:\Users\Adam\Desktop\HiJackThis.msi
[2010/05/11 15:07:25 | 000,018,905 | —- | C] () – C:\Users\Adam\Documents\Schools order form.xlsx
[2010/05/09 18:57:50 | 000,002,400 | —- | C] () – C:\Users\Adam\Desktop\Google Chrome.lnk
[2010/05/09 18:55:04 | 000,001,905 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/07 12:02:24 | 000,000,975 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/06 15:59:23 | 000,001,224 | —- | C] () – C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk
[2010/05/04 19:21:40 | 000,001,042 | —- | C] () – C:\Users\Adam\Desktop\Dropbox.lnk
[2010/05/03 11:28:52 | 000,010,555 | —- | C] () – C:\Users\Adam\Documents\Map to Naguru Vale.docx
[2010/04/30 15:49:42 | 000,016,896 | —- | C] () – C:\Users\Adam\Desktop\Baby_Group_Apr'10.xls
[2010/04/20 14:53:54 | 000,148,529 | —- | C] () – C:\Users\Adam\Documents\title screen.pptx
[2010/04/13 16:30:38 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$nce floor fillers.docx
[2010/04/13 11:45:38 | 000,002,100 | —- | C] () – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010/04/11 17:34:03 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001UA.job
[2010/04/11 17:34:03 | 000,000,850 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001Core.job
[2010/04/07 13:33:30 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$NGS FOR ALICE PARTY.docx
[2010/04/06 16:21:26 | 000,012,800 | -HS- | C] () – C:\Users\Adam\Thumbs.db
[2010/04/05 14:29:25 | 000,010,524 | —- | C] () – C:\Users\Adam\Desktop\Colourful.docx
[2010/03/28 11:55:24 | 000,016,479 | —- | C] () – C:\Users\Adam\Documents\Woodstock 1969 Lineup.docx
[2010/03/22 19:08:30 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2010/03/22 19:08:16 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2010/03/22 19:08:16 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2010/03/22 19:08:16 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2010/03/22 19:08:16 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2010/03/22 19:08:16 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2010/03/22 19:08:16 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2010/03/22 19:08:16 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2010/03/22 19:08:16 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2010/03/22 16:29:07 | 000,001,159 | —- | C] () – C:\Users\Adam\Desktop\PrintFolders.lnk
[2010/03/20 10:17:18 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/03/20 10:17:18 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/03/20 10:17:18 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\xvid.ax
[2009/07/14 02:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 00:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2004/01/12 23:53:52 | 000,172,032 | —- | C] () – C:\Windows\SysWow64\lame_enc.dll
========== LOP Check ==========
[2010/05/08 20:02:53 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Azureus
[2010/05/21 10:36:40 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Dropbox
[2010/06/14 08:15:33 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\FileZilla
[2009/11/13 19:49:59 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\ImgBurn
[2010/06/03 08:19:37 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\InternetEverywhere
[2010/04/13 11:47:34 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\PDF Writer
[2010/05/13 18:21:18 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\SoftwareDownload
[2010/04/17 18:12:59 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\SoundSpectrum
[2010/04/03 14:43:08 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\TeamViewer
[2010/06/02 14:10:12 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Temp
[2010/02/10 16:39:26 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\TheSage
[2010/05/13 19:39:05 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
OTL logfile created on: 6/15/2010 9:47:02 AM - Run 6
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Adam\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 66.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.40 Gb Total Space | 67.79 Gb Free Space | 23.92% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM_GEN
Current User Name: Adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe ()
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere.exe (WebToGo Mobiles Internet GmbH)
PRC - C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Launcher.exe ()
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Adam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (InternetEverywhere_Service) – C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe ()
SRV - (Macromedia Licensing Service) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VSS) – C:\Windows\Vss [2009/07/14 06:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/14 06:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (ewsercd) – C:\Windows\SysNative\drivers\ewsercd.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (ALWIL Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (ALWIL Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwififlt) – C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (hwusbfake) – C:\Windows\SysNative\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\SysWOW64\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) – C:\Windows\SysWOW64\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (ewsercd) – C:\Windows\SysWOW64\drivers\ewsercd.sys (Huawei Technologies Co., Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.hotmail.com/"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.gopher_port: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/11 21:21:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/09 18:55:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/13 20:02:20 | 000,000,000 | —D | M]
[2009/11/12 11:56:57 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Mozilla\Extensions
[2010/05/16 10:32:43 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\md2mcmep.default\extensions
[2010/05/09 18:55:02 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/07 11:52:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/01 19:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 19:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 19:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 19:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/06/11 00:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (WsftpBrowserHelper Class) - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files (x86)\Ipswitch\WS_FTP Pro\wsbho2k0.dll (Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0de2d712-5f3a-11df-9183-0025646d1823}\Shell - "" = AutoRun
O33 - MountPoints2\{0de2d712-5f3a-11df-9183-0025646d1823}\Shell\AutoRun\command - "" = F:\.\Setup.exe – File not found
O33 - MountPoints2\{b1614f0d-f432-11de-995a-0025646d1823}\Shell - "" = AutoRun
O33 - MountPoints2\{b1614f0d-f432-11de-995a-0025646d1823}\Shell\AutoRun\command - "" = E:\.\Setup.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\.\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 90 Days ==========
[2010/06/14 08:24:28 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\Shabbas
[2010/06/02 14:12:22 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\InternetEverywhere
[2010/06/02 14:12:12 | 000,691,712 | —- | C] (DiBcom SA) – C:\Windows\SysWow64\drivers\mod7700.sys
[2010/06/02 14:12:12 | 000,132,608 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbnet.sys
[2010/06/02 14:12:12 | 000,116,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbmdm.sys
[2010/06/02 14:12:12 | 000,116,224 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbfake.sys
[2010/06/02 14:12:12 | 000,112,896 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewsercd.sys
[2010/06/02 14:12:12 | 000,029,696 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\SysWow64\drivers\ewdcsc.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewsercd.sys
[2010/06/02 14:12:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\InternetEverywhere
[2010/06/02 14:10:12 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Temp
[2010/05/29 08:46:43 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\TOWN HOUSE
[2010/05/25 19:48:15 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/05/25 19:48:14 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/05/22 17:12:59 | 000,000,000 | —D | C] – C:\Users\Adam\Vital Pet Products
[2010/05/22 12:35:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vital
[2010/05/21 11:23:08 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/05/17 11:57:18 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2010/05/17 10:55:37 | 000,121,936 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/05/17 10:55:37 | 000,028,752 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/05/17 10:55:37 | 000,022,096 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/05/17 10:55:35 | 000,051,280 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/05/17 10:55:34 | 000,063,568 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/05/17 10:55:05 | 000,165,032 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/05/17 10:55:05 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/05/17 10:55:03 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/17 10:55:03 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/05/16 10:40:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/14 13:06:27 | 000,116,864 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewusbmdm.sys
[2010/05/13 18:29:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Easy Text To HTML Converter
[2010/05/13 18:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Text To HTML Converter
[2010/05/13 18:21:18 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\SoftwareDownload
[2010/05/13 08:55:27 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/05/12 16:33:35 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Monster Pet Supplies
[2010/05/12 16:32:16 | 000,000,000 | —D | C] – C:\Monster Pet Supplies
[2010/05/12 08:33:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/09 19:03:39 | 000,000,000 | —D | C] – C:\Users\Adam\DoctorWeb
[2010/05/08 13:30:43 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Lonely Planet
[2010/05/08 13:30:24 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Water For People
[2010/05/07 12:02:30 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Malwarebytes
[2010/05/07 12:02:22 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/07 12:02:21 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/07 12:02:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/07 12:02:21 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/06 15:59:15 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/05/06 15:59:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/05/06 15:50:56 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/05/05 15:53:19 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\U3
[2010/05/04 19:21:40 | 000,000,000 | R–D | C] – C:\Users\Adam\Documents\My Dropbox
[2010/05/04 19:20:17 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Dropbox
[2010/04/17 18:12:01 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\SoundSpectrum
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\PDF Writer
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Local\PDF Writer
[2010/04/13 11:47:34 | 000,000,000 | —D | C] – C:\ProgramData\PDF Writer
[2010/04/13 11:45:35 | 000,227,840 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzFlRdr.dll
[2010/04/13 11:45:35 | 000,135,168 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzpdfc.dll
[2010/04/13 11:45:35 | 000,103,424 | —- | C] (Bullzip) – C:\Windows\SysWow64\bzDCT.dll
[2010/04/13 11:45:35 | 000,008,192 | —- | C] (bioPDF) – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.dll
[2010/04/13 11:45:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bullzip
[2010/04/13 11:45:32 | 000,212,480 | —- | C] (Bullzip) – C:\Windows\SysNative\bzpdf.dll
[2010/04/13 11:45:29 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/04/11 21:21:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/04/11 21:21:25 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/04/11 21:21:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2010/04/11 21:21:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Real
[2010/04/11 21:21:22 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010/04/11 21:21:20 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\Real
[2010/04/11 16:17:44 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/04/09 10:49:00 | 000,000,000 | —D | C] – C:\Documents
[2010/04/06 18:34:23 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Music info
[2010/04/03 14:37:55 | 000,000,000 | —D | C] – C:\Users\Adam\AppData\Roaming\TeamViewer
[2010/04/03 14:37:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamViewer
[2010/04/03 14:20:57 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Remote Assistance Logs
[2010/04/03 08:51:50 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/03 08:51:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/04/01 15:42:09 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Zoom
[2010/03/22 20:01:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\SopCast
[2010/03/22 19:08:30 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2010/03/22 19:08:30 | 000,070,656 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\i420vfw.dll
[2010/03/22 19:08:16 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) – C:\Windows\SysWow64\nbDX.dll
[2010/03/22 19:08:16 | 000,186,880 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLOgg.ax
[2010/03/22 19:08:16 | 000,179,200 | RHS- | C] (Gabest) – C:\Windows\SysWow64\DiracSplitter.ax
[2010/03/22 19:08:16 | 000,169,472 | RHS- | C] (Gabest) – C:\Windows\SysWow64\MatroskaDX.ax
[2010/03/22 19:08:16 | 000,163,328 | RHS- | C] (Gabest) – C:\Windows\SysWow64\flvDX.dll
[2010/03/22 19:08:16 | 000,161,792 | RHS- | C] (Gabest) – C:\Windows\SysWow64\RealMediaDX.ax
[2010/03/22 19:08:16 | 000,123,904 | RHS- | C] (CoreCodec) – C:\Windows\SysWow64\AVCDX.ax
[2010/03/22 19:08:16 | 000,092,672 | RHS- | C] (RadLight) – C:\Windows\SysWow64\RLVorbisDec.ax
[2010/03/22 19:08:16 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSSplitter.ax
[2010/03/22 19:08:16 | 000,090,112 | RHS- | C] (-) – C:\Windows\SysWow64\TTADSDecoder.ax
[2010/03/22 19:08:16 | 000,067,584 | RHS- | C] (RadLight, LLC) – C:\Windows\SysWow64\RLTheoraDec.ax
[2010/03/22 19:08:16 | 000,031,232 | RHS- | C] (Hans Mayerl) – C:\Windows\SysWow64\msfDX.dll
[2010/03/22 19:08:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\eRightSoft
[2010/03/22 16:29:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\PrintFolders
[2010/03/22 00:29:04 | 000,000,000 | —D | C] – C:\Users\Adam\EurekaLog
[2010/03/20 19:28:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\AviSynth 2.5
[2010/03/20 19:10:34 | 000,000,000 | —D | C] – C:\Program Files\DivX_3.1alpha
[2010/03/20 18:53:26 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\MPEG-4v3_codec_fix
[2010/03/20 10:17:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xvid
[2010/03/20 09:55:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\bobyte
[2010/03/20 08:30:19 | 000,000,000 | —D | C] – C:\Users\Adam\Desktop\Movies
[2010/03/20 08:20:38 | 000,000,000 | —D | C] – C:\Users\Adam\Documents\Bowling - Alleygators
========== Files - Modified Within 90 Days ==========
[2010/06/15 09:50:10 | 007,077,888 | -HS- | M] () – C:\Users\Adam\NTUSER.DAT
[2010/06/15 09:39:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001UA.job
[2010/06/15 09:17:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/15 08:17:00 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/15 08:06:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/15 08:06:07 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/15 08:03:23 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/15 08:03:23 | 000,619,642 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/15 08:03:23 | 000,107,792 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/15 07:58:59 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/15 07:58:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/15 07:58:43 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2010/06/14 22:30:46 | 003,383,167 | -H– | M] () – C:\Users\Adam\AppData\Local\IconCache.db
[2010/06/14 17:39:00 | 000,000,850 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001Core.job
[2010/06/11 11:25:30 | 002,358,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/10 07:40:28 | 000,002,400 | —- | M] () – C:\Users\Adam\Desktop\Google Chrome.lnk
[2010/06/09 13:56:00 | 000,243,001 | —- | M] () – C:\Users\Adam\Desktop\MOVING_SALE[1].pdf
[2010/06/09 10:27:15 | 000,095,744 | —- | M] () – C:\Users\Adam\Desktop\2010.06.14 INVOICE Adam Williams.xls
[2010/06/09 07:26:20 | 000,082,944 | —- | M] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/03 17:09:38 | 002,895,360 | —- | M] () – C:\Users\Adam\Documents\mpawilliams.appendix.doc
[2010/06/03 09:24:12 | 000,014,733 | —- | M] () – C:\Users\Adam\Desktop\Hairstyle.docx
[2010/06/02 14:12:09 | 000,002,039 | —- | M] () – C:\Users\Public\Desktop\Internet Everywhere.lnk
[2010/06/02 14:12:03 | 000,002,104 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk
[2010/06/02 14:12:02 | 000,691,712 | —- | M] (DiBcom SA) – C:\Windows\SysWow64\drivers\mod7700.sys
[2010/06/02 14:12:02 | 000,132,608 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbnet.sys
[2010/06/02 14:12:02 | 000,116,864 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbmdm.sys
[2010/06/02 14:12:02 | 000,116,224 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewusbfake.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysWow64\drivers\ewsercd.sys
[2010/06/02 14:12:02 | 000,112,896 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewsercd.sys
[2010/06/02 14:12:02 | 000,029,696 | —- | M] (Huawei Tech. Co., Ltd.) – C:\Windows\SysWow64\drivers\ewdcsc.sys
[2010/06/01 21:27:52 | 000,032,768 | —- | M] () – C:\Users\Adam\Desktop\BAGAGGA MOLDECHAI.doc
[2010/05/30 11:17:40 | 098,966,519 | —- | M] () – C:\Users\Adam\Desktop\Dick Weber Bowling.wmv
[2010/05/29 22:03:29 | 000,013,012 | —- | M] () – C:\Users\Adam\Desktop\Elaine.docx
[2010/05/28 09:11:52 | 000,008,080 | —- | M] () – C:\Users\Adam\Desktop\lmsfwctickets.fifa.com - PrintTicketResult.pdf
[2010/05/26 17:00:39 | 000,176,688 | —- | M] () – C:\Users\Adam\Desktop\Toxoplasmosis.docx
[2010/05/26 14:41:24 | 000,110,870 | —- | M] () – C:\Users\Adam\Desktop\Zaiden invite.jpg
[2010/05/26 13:22:33 | 000,029,446 | —- | M] () – C:\Users\Adam\Desktop\Street art festival June 5, 11am.jpg
[2010/05/24 17:33:02 | 000,001,945 | —- | M] () – C:\Users\Public\Desktop\Vital Pet Products Catalogue.lnk
[2010/05/19 11:32:17 | 000,181,541 | —- | M] () – C:\Users\Adam\Desktop\Marks - China May 2010.pdf
[2010/05/17 10:55:38 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/17 10:55:34 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/05/16 10:36:07 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$Let.docx
[2010/05/16 10:33:39 | 000,016,506 | —- | M] () – C:\Users\Adam\Desktop\Let.docx
[2010/05/16 10:32:44 | 000,000,033 | —- | M] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/05/14 13:06:27 | 000,116,864 | —- | M] (Huawei Technologies Co., Ltd.) – C:\Windows\SysNative\drivers\ewusbmdm.sys
[2010/05/14 11:14:09 | 000,011,276 | —- | M] () – C:\Users\Adam\Desktop\Hi Melissa.docx
[2010/05/13 18:21:19 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\To HTML-Markdown.lnk
[2010/05/13 11:50:01 | 000,100,750 | —- | M] () – C:\Users\Adam\Desktop\ANZ details.JPG
[2010/05/13 11:37:03 | 000,134,290 | —- | M] () – C:\Users\Adam\Desktop\Wii charger amazon order.JPG
[2010/05/13 08:55:35 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTL.exe
[2010/05/12 08:43:46 | 000,002,971 | —- | M] () – C:\Users\Adam\Desktop\HiJackThis.lnk
[2010/05/12 08:41:39 | 001,402,880 | —- | M] () – C:\Users\Adam\Desktop\HiJackThis.msi
[2010/05/11 17:23:17 | 000,018,905 | —- | M] () – C:\Users\Adam\Documents\Schools order form.xlsx
[2010/05/09 18:55:04 | 000,001,905 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/07 12:02:24 | 000,000,975 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/06 23:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/05/06 23:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/05/06 23:39:27 | 000,051,280 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/05/06 23:39:06 | 000,121,936 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/05/06 23:34:30 | 000,028,752 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/05/06 23:34:14 | 000,063,568 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/05/06 23:33:50 | 000,022,096 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/05/06 15:59:23 | 000,001,224 | —- | M] () – C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk
[2010/05/04 19:21:40 | 000,001,042 | —- | M] () – C:\Users\Adam\Desktop\Dropbox.lnk
[2010/05/03 11:28:52 | 000,010,555 | —- | M] () – C:\Users\Adam\Documents\Map to Naguru Vale.docx
[2010/04/30 15:49:54 | 000,016,896 | —- | M] () – C:\Users\Adam\Desktop\Baby_Group_Apr'10.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/28 08:52:54 | 000,116,480 | —- | M] () – C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/22 07:49:04 | 000,001,976 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/20 14:53:54 | 000,148,529 | —- | M] () – C:\Users\Adam\Documents\title screen.pptx
[2010/04/13 16:30:38 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$nce floor fillers.docx
[2010/04/13 11:45:39 | 000,002,100 | —- | M] () – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010/04/11 21:21:25 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/04/11 17:34:22 | 000,001,814 | —- | M] () – C:\Users\Public\Desktop\Vuze.lnk
[2010/04/11 13:02:30 | 000,119,296 | —- | M] () – C:\Users\Adam\Documents\Hard drive contents.xls
[2010/04/07 13:33:30 | 000,000,162 | -H– | M] () – C:\Users\Adam\Desktop\~$NGS FOR ALICE PARTY.docx
[2010/04/06 22:57:00 | 000,010,524 | —- | M] () – C:\Users\Adam\Desktop\Colourful.docx
[2010/03/28 11:55:24 | 000,016,479 | —- | M] () – C:\Users\Adam\Documents\Woodstock 1969 Lineup.docx
[2010/03/22 16:29:07 | 000,001,159 | —- | M] () – C:\Users\Adam\Desktop\PrintFolders.lnk
========== Files Created - No Company Name ==========
[2010/06/09 13:56:00 | 000,243,001 | —- | C] () – C:\Users\Adam\Desktop\MOVING_SALE[1].pdf
[2010/06/09 10:27:15 | 000,095,744 | —- | C] () – C:\Users\Adam\Desktop\2010.06.14 INVOICE Adam Williams.xls
[2010/06/03 17:09:38 | 002,895,360 | —- | C] () – C:\Users\Adam\Documents\mpawilliams.appendix.doc
[2010/06/02 22:37:27 | 000,014,733 | —- | C] () – C:\Users\Adam\Desktop\Hairstyle.docx
[2010/06/02 14:12:09 | 000,002,039 | —- | C] () – C:\Users\Public\Desktop\Internet Everywhere.lnk
[2010/06/02 14:12:03 | 000,002,104 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk
[2010/06/02 07:29:41 | 000,032,768 | —- | C] () – C:\Users\Adam\Desktop\BAGAGGA MOLDECHAI.doc
[2010/05/30 11:10:17 | 098,966,519 | —- | C] () – C:\Users\Adam\Desktop\Dick Weber Bowling.wmv
[2010/05/29 22:03:29 | 000,013,012 | —- | C] () – C:\Users\Adam\Desktop\Elaine.docx
[2010/05/29 08:10:23 | 002,202,974 | R— | C] () – C:\Users\Adam\Desktop\PaulRobesonCharlesPenrose-TheLaughingPoliceman1926incomplete.mp3
[2010/05/28 09:11:50 | 000,008,080 | —- | C] () – C:\Users\Adam\Desktop\lmsfwctickets.fifa.com - PrintTicketResult.pdf
[2010/05/26 16:51:36 | 000,176,688 | —- | C] () – C:\Users\Adam\Desktop\Toxoplasmosis.docx
[2010/05/26 14:41:24 | 000,110,870 | —- | C] () – C:\Users\Adam\Desktop\Zaiden invite.jpg
[2010/05/26 13:22:33 | 000,029,446 | —- | C] () – C:\Users\Adam\Desktop\Street art festival June 5, 11am.jpg
[2010/05/24 17:33:02 | 000,001,945 | —- | C] () – C:\Users\Public\Desktop\Vital Pet Products Catalogue.lnk
[2010/05/19 11:32:17 | 000,181,541 | —- | C] () – C:\Users\Adam\Desktop\Marks - China May 2010.pdf
[2010/05/17 10:55:38 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/17 10:55:34 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/05/16 10:36:07 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$Let.docx
[2010/05/16 10:33:39 | 000,016,506 | —- | C] () – C:\Users\Adam\Desktop\Let.docx
[2010/05/16 10:32:44 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/05/14 11:14:09 | 000,011,276 | —- | C] () – C:\Users\Adam\Desktop\Hi Melissa.docx
[2010/05/13 18:21:19 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\To HTML-Markdown.lnk
[2010/05/13 11:50:01 | 000,100,750 | —- | C] () – C:\Users\Adam\Desktop\ANZ details.JPG
[2010/05/13 11:37:03 | 000,134,290 | —- | C] () – C:\Users\Adam\Desktop\Wii charger amazon order.JPG
[2010/05/12 08:43:46 | 000,002,971 | —- | C] () – C:\Users\Adam\Desktop\HiJackThis.lnk
[2010/05/12 08:41:29 | 001,402,880 | —- | C] () – C:\Users\Adam\Desktop\HiJackThis.msi
[2010/05/11 15:07:25 | 000,018,905 | —- | C] () – C:\Users\Adam\Documents\Schools order form.xlsx
[2010/05/09 18:57:50 | 000,002,400 | —- | C] () – C:\Users\Adam\Desktop\Google Chrome.lnk
[2010/05/09 18:55:04 | 000,001,905 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/05/07 12:02:24 | 000,000,975 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/06 15:59:23 | 000,001,224 | —- | C] () – C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk
[2010/05/04 19:21:40 | 000,001,042 | —- | C] () – C:\Users\Adam\Desktop\Dropbox.lnk
[2010/05/03 11:28:52 | 000,010,555 | —- | C] () – C:\Users\Adam\Documents\Map to Naguru Vale.docx
[2010/04/30 15:49:42 | 000,016,896 | —- | C] () – C:\Users\Adam\Desktop\Baby_Group_Apr'10.xls
[2010/04/20 14:53:54 | 000,148,529 | —- | C] () – C:\Users\Adam\Documents\title screen.pptx
[2010/04/13 16:30:38 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$nce floor fillers.docx
[2010/04/13 11:45:38 | 000,002,100 | —- | C] () – C:\Windows\SysWow64\BioPdf.PdfWriter.Lib.tlb
[2010/04/11 17:34:03 | 000,000,902 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001UA.job
[2010/04/11 17:34:03 | 000,000,850 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1897899420-3886255029-2469466402-1001Core.job
[2010/04/07 13:33:30 | 000,000,162 | -H– | C] () – C:\Users\Adam\Desktop\~$NGS FOR ALICE PARTY.docx
[2010/04/06 16:21:26 | 000,012,800 | -HS- | C] () – C:\Users\Adam\Thumbs.db
[2010/04/05 14:29:25 | 000,010,524 | —- | C] () – C:\Users\Adam\Desktop\Colourful.docx
[2010/03/28 11:55:24 | 000,016,479 | —- | C] () – C:\Users\Adam\Documents\Woodstock 1969 Lineup.docx
[2010/03/22 19:08:30 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2010/03/22 19:08:16 | 000,227,328 | RHS- | C] () – C:\Windows\SysWow64\ac3DX.ax
[2010/03/22 19:08:16 | 000,175,104 | RHS- | C] () – C:\Windows\SysWow64\CoreAAC.ax
[2010/03/22 19:08:16 | 000,120,832 | RHS- | C] () – C:\Windows\SysWow64\MPCDx.ax
[2010/03/22 19:08:16 | 000,107,520 | RHS- | C] () – C:\Windows\SysWow64\RLMPCDec.ax
[2010/03/22 19:08:16 | 000,097,280 | RHS- | C] () – C:\Windows\SysWow64\FLACDX.ax
[2010/03/22 19:08:16 | 000,081,920 | RHS- | C] () – C:\Windows\SysWow64\aac_parser.ax
[2010/03/22 19:08:16 | 000,070,656 | RHS- | C] () – C:\Windows\SysWow64\RLAPEDec.ax
[2010/03/22 19:08:16 | 000,051,712 | RHS- | C] () – C:\Windows\SysWow64\RLSpeexDec.ax
[2010/03/22 16:29:07 | 000,001,159 | —- | C] () – C:\Users\Adam\Desktop\PrintFolders.lnk
[2010/03/20 10:17:18 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/03/20 10:17:18 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/03/20 10:17:18 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\xvid.ax
[2009/07/14 02:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 00:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2004/01/12 23:53:52 | 000,172,032 | —- | C] () – C:\Windows\SysWow64\lame_enc.dll
========== LOP Check ==========
[2010/05/08 20:02:53 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Azureus
[2010/05/21 10:36:40 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Dropbox
[2010/06/14 08:15:33 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\FileZilla
[2009/11/13 19:49:59 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\ImgBurn
[2010/06/03 08:19:37 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\InternetEverywhere
[2010/04/13 11:47:34 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\PDF Writer
[2010/05/13 18:21:18 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\SoftwareDownload
[2010/04/17 18:12:59 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\SoundSpectrum
[2010/04/03 14:43:08 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\TeamViewer
[2010/06/02 14:10:12 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\Temp
[2010/02/10 16:39:26 | 000,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\TheSage
[2010/05/13 19:39:05 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >