This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan horse Cryptic.ASR can't get rid of it!

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I'm running win 7 64-bit, I just did a clean install about a month ago. Somehow I got this virus, I do use keygens for my cadd software but i've used these before with no issues. I proly got it from a movie torrent…not sure. Anyway i keep moving it to the vault with AVG Free. I've tried several spyware programs, and they found alot of stuff but and removed them, but this one keeps coming back. I need help!!! I use my comp for school and this is killing me! Thanks!
Here are some scan results from OTL:

OTL logfile created on: 8/12/2010 10:47:01 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = E:\Users\Scott\Desktop\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 66.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 231.02 Gb Free Space | 77.50% Space Free | Partition Type: NTFS
Drive D: | 7.46 Gb Total Space | 6.81 Gb Free Space | 91.30% Space Free | Partition Type: FAT32
Drive E: | 931.51 Gb Total Space | 783.63 Gb Free Space | 84.12% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 232.88 Gb Total Space | 197.93 Gb Free Space | 84.99% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SCOTT-PC
Current User Name: Scott
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - E:\Users\Scott\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - E:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - E:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - E:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - E:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - E:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - E:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk)
PRC - E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe (Autodesk)


========== Modules (SafeList) ==========

MOD - E:\Users\Scott\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - E:\Program Files\CheckPoint\ZAForceField\WOW64\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - E:\Windows\SysWOW64\wintrust.dll (Microsoft Corporation)
MOD - E:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - E:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - E:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)
MOD - E:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcp80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (FLEXnet Licensing Service 64) – E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (!SASCORE) – E:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (IswSvc) – E:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV:64bit: - (LBTServ) – E:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (CoordinatorServiceHost) – E:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV:64bit: - (AMD External Events Utility) – E:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmRdpService) – E:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – E:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – E:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – E:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – E:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (avg9emc) – E:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Autodesk Licensing Service) – E:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (FLEXnet Licensing Service) – E:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SolidWorks Licensing Service) – E:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (avg9wd) – E:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (vsmon) – E:\Windows\SysWOW64\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (Autodesk Data Management Job Dispatch) – E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk)
SRV - (Autodesk EDM Server) – E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe (Autodesk)
SRV - (Microsoft Office Groove Audit Service) – E:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (sptd) – E:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (AvgTdiA) – E:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – E:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – E:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (ISWKL) – E:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV:64bit: - (Vsdatant) – E:\Windows\SysNative\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (epmntdrv) – E:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (EuGdiDrv) – E:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (LMouFilt) – E:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – E:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (SASDIFSV) – E:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – E:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (Revoflt) – E:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (athr) – E:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (atikmdag) – E:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdsata) – E:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – E:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – E:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – E:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – E:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – E:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – E:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – E:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – E:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – E:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – E:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – E:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – E:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – E:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – E:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – E:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – E:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – E:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RTL8167) – E:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (RimVSerPort) – E:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (RimUsb) – E:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (PxHlpa64) – E:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV - (epmntdrv) – E:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (EuGdiDrv) – E:\Windows\SysWOW64\EuGdiDrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = E:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C7 6E 80 DA BA 2D CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.ca"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: [removed]:2.0.6
FF - prefs.js..extensions.enabledItems: [removed]:3.6.20100626
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0.6
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:4.6
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: [removed]:3.5.2
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.5
FF - prefs.js..extensions.enabledItems: {cc85cd4e-5a5b-4eda-a25c-bdaffa93b406}:0.4.5
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.4.7amo
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..extensions.enabledItems: [removed]:4.1.6
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.227.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: E:\Program Files (x86)\AVG\AVG9\Firefox [2010/07/28 08:18:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: E:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2010/08/10 12:17:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components [2010/07/27 11:40:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/03 11:50:19 | 000,000,000 | —D | M]

[2010/07/27 11:40:36 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Extensions
[2010/08/12 10:35:47 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions
[2010/08/10 09:24:15 | 000,000,000 | —D | M] (Stylish) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/08/10 09:24:13 | 000,000,000 | —D | M] (Firefox Showcase) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2010/08/10 09:24:12 | 000,000,000 | —D | M] (DownloadHelper) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/10 09:24:13 | 000,000,000 | —D | M] (Google Redesigned) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{cc85cd4e-5a5b-4eda-a25c-bdaffa93b406}
[2010/08/10 09:24:13 | 000,000,000 | —D | M] (Adblock Plus) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/10 09:24:23 | 000,000,000 | —D | M] (SearchPreview) – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/08/10 09:24:13 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\[removed]
[2010/08/10 09:24:13 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\[removed]
[2010/08/10 09:24:15 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\[removed]
[2010/08/09 21:25:08 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\[removed]
[2010/08/10 09:24:12 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\SkipScreen@SkipScreen
[2010/08/10 09:24:11 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\extensions\[removed]
[2010/07/27 12:15:24 | 000,002,059 | —- | M] () – E:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\3bwwvibj.default\searchplugins\daemon-search.xml
[2010/07/27 11:40:29 | 000,000,000 | —D | M] – E:\Program Files (x86)\Mozilla Firefox\extensions
[2009/10/14 17:21:24 | 000,155,648 | —- | M] (Dassault Systèmes SolidWorks Corp.) – E:\Program Files (x86)\Mozilla Firefox\plugins\npEModelPlugin.dll

O1 HOSTS File: ([2010/08/01 10:57:23 | 000,001,306 | —- | M]) - E:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - E:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - E:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - E:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - E:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4:64bit: - HKLM..\Run: [EvtMgr6] E:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [ISW] E:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] E:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [GrooveMonitor] E:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] E:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [ISUSPM] E:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: E:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = E:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append to existing PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to existing PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_04)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_04)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - E:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - E:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (acaptuser64.dll) - E:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (acaptuser32.dll) - E:\Windows\SysWow64\acaptuser32.dll (Adobe Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - e:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/12 09:34:23 | 000,000,000 | —D | M] - C:\AutoCad Install files – [ NTFS ]
O33 - MountPoints2\{074ee5db-99ac-11df-bce8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{074ee5db-99ac-11df-bce8-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - E:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/12 09:14:32 | 000,000,000 | —D | C] – E:\Windows\Minidump
[2010/08/10 18:30:52 | 000,082,944 | —- | C] (Radius Inc.) – E:\Windows\SysWow64\iccvid.dll
[2010/08/10 18:30:48 | 000,256,000 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\iepeers.dll
[2010/08/10 18:30:48 | 000,185,856 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\iepeers.dll
[2010/08/10 18:30:47 | 000,247,808 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\ieui.dll
[2010/08/10 18:30:47 | 000,176,640 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\ieui.dll
[2010/08/10 18:30:47 | 000,012,800 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\msfeedssync.exe
[2010/08/10 18:30:47 | 000,012,288 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\msfeedssync.exe
[2010/08/10 18:30:45 | 005,507,968 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\ntoskrnl.exe
[2010/08/10 18:30:44 | 003,955,080 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\ntkrnlpa.exe
[2010/08/10 18:30:44 | 003,899,784 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\ntoskrnl.exe
[2010/08/10 18:30:20 | 000,052,224 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\rtutils.dll
[2010/08/10 18:30:20 | 000,037,376 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\rtutils.dll
[2010/08/10 12:17:49 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\ForceField Shared Files
[2010/08/10 12:17:49 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\CheckPoint
[2010/08/10 12:17:20 | 000,000,000 | —D | C] – E:\Program Files (x86)\ZoneAlarm
[2010/08/10 12:17:20 | 000,000,000 | —D | C] – E:\Program Files (x86)\Conduit
[2010/08/10 12:17:06 | 000,000,000 | —D | C] – E:\Program Files\CheckPoint
[2010/08/10 12:17:00 | 000,058,368 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsregexp.dll
[2010/08/10 12:16:35 | 000,374,664 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\drivers\netio.sys
[2010/08/10 12:16:09 | 000,103,936 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\zlcommdb.dll
[2010/08/10 12:16:09 | 000,069,120 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\zlcomm.dll
[2010/08/10 12:16:06 | 000,043,008 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vswmi.dll
[2010/08/10 12:16:05 | 001,238,528 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\zpeng25.dll
[2010/08/10 12:16:05 | 000,302,592 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vspubapi.dll
[2010/08/10 12:16:05 | 000,110,080 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsxml.dll
[2010/08/10 12:16:05 | 000,108,032 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsmonapi.dll
[2010/08/10 12:16:05 | 000,000,000 | —D | C] – E:\Windows\SysWow64\ZoneLabs
[2010/08/10 12:16:04 | 000,112,128 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsdata.dll
[2010/08/10 12:16:00 | 000,458,840 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysNative\drivers\vsdatant.sys
[2010/08/10 12:15:26 | 000,713,728 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsutil.dll
[2010/08/10 12:15:26 | 000,228,864 | —- | C] (Check Point Software Technologies LTD) – E:\Windows\SysWow64\vsinit.dll
[2010/08/10 12:13:01 | 000,000,000 | —D | C] – E:\Program Files (x86)\Zone Labs
[2010/08/10 12:13:01 | 000,000,000 | —D | C] – E:\ProgramData\CheckPoint
[2010/08/10 12:09:10 | 000,000,000 | —D | C] – E:\Windows\Internet Logs
[2010/08/10 10:38:41 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/10 10:38:41 | 000,000,000 | —D | C] – E:\ProgramData\SUPERAntiSpyware.com
[2010/08/10 10:38:37 | 000,000,000 | —D | C] – E:\ProgramData\!SASCORE
[2010/08/10 10:38:35 | 000,000,000 | —D | C] – E:\Program Files\SUPERAntiSpyware
[2010/08/09 21:47:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – E:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/09 21:47:58 | 000,000,000 | —D | C] – E:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/09 21:00:08 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Malwarebytes
[2010/08/09 21:00:03 | 000,024,664 | —- | C] (Malwarebytes Corporation) – E:\Windows\SysNative\drivers\mbam.sys
[2010/08/09 21:00:03 | 000,000,000 | —D | C] – E:\ProgramData\Malwarebytes
[2010/08/09 20:47:53 | 000,000,000 | -H-D | C] – E:\$AVG
[2010/08/03 11:50:09 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft Works
[2010/08/03 11:49:53 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft Visual Studio
[2010/08/03 11:48:28 | 000,000,000 | —D | C] – E:\Program Files\Microsoft Office
[2010/08/03 11:45:31 | 000,000,000 | RH-D | C] – E:\MSOCache
[2010/08/03 11:27:29 | 000,000,000 | —D | C] – E:\ProgramData\Logitech
[2010/08/03 11:27:09 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Leadertech
[2010/08/03 11:27:06 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\LogiShrd
[2010/08/03 11:26:45 | 000,018,960 | —- | C] (Logitech, Inc.) – E:\Windows\SysNative\drivers\LNonPnP.sys
[2010/08/03 11:26:27 | 000,000,000 | —D | C] – E:\Users\Public\Documents\LogiShrd
[2010/08/03 11:26:08 | 000,000,000 | —D | C] – E:\ProgramData\Logishrd
[2010/08/03 11:26:05 | 000,000,000 | —D | C] – E:\Program Files\Logitech
[2010/08/03 11:25:51 | 000,000,000 | —D | C] – E:\Program Files\Common Files\LogiShrd
[2010/08/03 11:25:41 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Logitech
[2010/08/03 11:25:41 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Logishrd
[2010/08/03 11:06:06 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Research In Motion
[2010/08/03 10:50:46 | 000,000,000 | —D | C] – E:\Program Files\Roxio
[2010/08/03 10:50:41 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\InstallShield
[2010/08/03 10:50:39 | 000,000,000 | —D | C] – E:\ProgramData\InstallShield
[2010/08/03 10:50:38 | 000,052,856 | —- | C] (Sonic Solutions) – E:\Windows\SysNative\drivers\PxHlpa64.sys
[2010/08/03 10:50:35 | 000,000,000 | —D | C] – E:\ProgramData\Sonic
[2010/08/03 10:50:12 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Programs
[2010/08/03 10:49:20 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\PX Storage Engine
[2010/08/03 10:49:08 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Sonic Shared
[2010/08/03 10:49:08 | 000,000,000 | —D | C] – E:\ProgramData\Roxio
[2010/08/03 10:49:08 | 000,000,000 | —D | C] – E:\Program Files (x86)\Roxio
[2010/08/03 10:45:27 | 000,031,744 | —- | C] (Research in Motion Ltd) – E:\Windows\SysNative\drivers\RimSerial_AMD64.sys
[2010/08/03 10:45:06 | 000,000,000 | —D | C] – E:\ProgramData\Research In Motion
[2010/08/03 10:45:05 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Roxio Shared
[2010/08/03 10:45:02 | 000,000,000 | —D | C] – E:\Program Files (x86)\Research In Motion
[2010/08/03 10:45:02 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Research In Motion
[2010/08/03 10:01:04 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\VS Revo Group
[2010/08/03 10:01:02 | 000,031,800 | —- | C] (VS Revo Group) – E:\Windows\SysNative\drivers\revoflt.sys
[2010/08/03 10:01:01 | 000,000,000 | —D | C] – E:\Program Files\VS Revo Group
[2010/08/01 10:54:15 | 000,052,568 | R— | C] (Adobe Systems Inc) – E:\Windows\SysNative\AdobePDF.dll
[2010/08/01 10:54:15 | 000,024,416 | R— | C] (Adobe Systems Inc.) – E:\Windows\SysNative\AdobePDFUI.dll
[2010/08/01 10:29:03 | 000,111,992 | —- | C] (Adobe Systems, Inc.) – E:\Windows\SysWow64\acaptuser32.dll
[2010/08/01 10:19:28 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Adobe
[2010/08/01 10:16:27 | 000,000,000 | —D | C] – E:\ProgramData\Adobe
[2010/08/01 10:16:27 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Adobe
[2010/08/01 10:16:27 | 000,000,000 | —D | C] – E:\Program Files (x86)\Adobe
[2010/08/01 09:22:56 | 000,000,000 | R–D | C] – E:\Users\Scott\Downloads
[2010/07/30 21:31:55 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\Learning Autocad
[2010/07/30 21:31:33 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\AcadFiles
[2010/07/30 07:52:16 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Apps
[2010/07/29 21:33:35 | 000,000,000 | -H-D | C] – E:\Program Files (x86)\InstallShield Installation Information
[2010/07/29 21:33:35 | 000,000,000 | —D | C] – E:\Program Files (x86)\EASEUS
[2010/07/29 21:32:37 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\InstallShield
[2010/07/29 21:00:43 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Mael
[2010/07/28 19:52:53 | 000,000,000 | —D | C] – E:\Windows\pss
[2010/07/28 11:43:14 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\vlc
[2010/07/28 11:42:26 | 000,000,000 | —D | C] – E:\Program Files (x86)\VideoLAN
[2010/07/28 11:06:47 | 000,000,000 | —D | C] – E:\Program Files (x86)\CCleaner
[2010/07/28 11:06:17 | 000,000,000 | —D | C] – E:\Program Files (x86)\SIW
[2010/07/28 08:21:29 | 000,000,000 | —D | C] – E:\Program Files (x86)\MSXML 4.0
[2010/07/28 08:17:19 | 000,000,000 | —D | C] – E:\Windows\SysWow64\drivers\avg
[2010/07/28 07:47:39 | 000,000,000 | —D | C] – E:\Windows\SysNative\appmgmt
[2010/07/28 07:39:26 | 000,513,544 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\XAudio2_2.dll
[2010/07/28 07:39:26 | 000,509,448 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\XAudio2_2.dll
[2010/07/28 07:39:26 | 000,072,200 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\XAPOFX1_1.dll
[2010/07/28 07:39:26 | 000,068,616 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\XAPOFX1_1.dll
[2010/07/28 07:39:25 | 000,238,088 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\xactengine3_2.dll
[2010/07/28 07:39:25 | 000,177,672 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\xactengine3_2.dll
[2010/07/28 07:39:18 | 001,942,552 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DCompiler_39.dll
[2010/07/28 07:39:18 | 001,493,528 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DCompiler_39.dll
[2010/07/28 07:39:18 | 000,540,688 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx10_39.dll
[2010/07/28 07:39:18 | 000,467,984 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx10_39.dll
[2010/07/28 07:39:17 | 004,992,520 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DX9_39.dll
[2010/07/28 07:39:17 | 003,851,784 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DX9_39.dll
[2010/07/28 07:39:17 | 001,401,200 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DCompiler_34.dll
[2010/07/28 07:39:17 | 001,124,720 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DCompiler_34.dll
[2010/07/28 07:39:17 | 000,506,728 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx10_34.dll
[2010/07/28 07:39:17 | 000,443,752 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx10_34.dll
[2010/07/28 07:39:16 | 004,496,232 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx9_34.dll
[2010/07/28 07:39:16 | 003,497,832 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx9_34.dll
[2010/07/28 07:39:16 | 000,469,264 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx10.dll
[2010/07/28 07:39:16 | 000,440,080 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx10.dll
[2010/07/28 07:38:58 | 004,398,360 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx9_32.dll
[2010/07/28 07:38:58 | 003,426,072 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx9_32.dll
[2010/07/28 07:38:54 | 003,977,496 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx9_31.dll
[2010/07/28 07:38:54 | 002,414,360 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx9_31.dll
[2010/07/28 07:30:24 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Macromedia
[2010/07/28 07:30:24 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Adobe
[2010/07/28 07:30:19 | 000,000,000 | —D | C] – E:\Windows\SysWow64\Macromed
[2010/07/27 23:35:22 | 000,000,000 | —D | C] – E:\Users\Scott\Desktop\AutoCad Architecture Program files
[2010/07/27 23:25:27 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\Autodesk
[2010/07/27 23:04:37 | 000,000,000 | —D | C] – E:\Users\Scott\Desktop\AutoCad Inventor program files
[2010/07/27 23:02:33 | 000,000,000 | —D | C] – E:\Users\Scott\Desktop\SolidWorks 2010 program files
[2010/07/27 23:01:55 | 000,000,000 | —D | C] – E:\Users\Scott\Desktop\AutoCad 2011 programs
[2010/07/27 22:48:00 | 005,425,496 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DX9_41.dll
[2010/07/27 22:48:00 | 004,178,264 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DX9_41.dll
[2010/07/27 22:48:00 | 002,430,312 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DCompiler_41.dll
[2010/07/27 22:48:00 | 001,846,632 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DCompiler_41.dll
[2010/07/27 22:48:00 | 000,520,544 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx10_41.dll
[2010/07/27 22:48:00 | 000,453,456 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx10_41.dll
[2010/07/27 22:47:38 | 003,927,248 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx9_30.dll
[2010/07/27 22:47:38 | 002,388,176 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx9_30.dll
[2010/07/27 22:42:29 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Ansys
[2010/07/27 22:40:13 | 000,000,000 | R–D | C] – E:\Users\Scott\Documents\Adlm
[2010/07/27 22:17:36 | 000,000,000 | —D | C] – E:\Users\Scott\Desktop\Quick start
[2010/07/27 22:16:46 | 000,000,000 | —D | C] – E:\Windows\PCHEALTH
[2010/07/27 22:16:36 | 000,000,000 | —D | C] – E:\Program Files\Microsoft SQL Server
[2010/07/27 22:16:33 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft SQL Server
[2010/07/27 22:09:31 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\Inventor
[2010/07/27 22:09:31 | 000,000,000 | —D | C] – E:\ProgramData\Autodesk, Inc
[2010/07/27 22:09:31 | 000,000,000 | —D | C] – E:\Users\Public\Documents\Autodesk
[2010/07/27 22:09:31 | 000,000,000 | —D | C] – E:\Program Files\Autodesk
[2010/07/27 22:07:31 | 000,000,000 | —D | C] – E:\Program Files\AOEMView 2009
[2010/07/27 22:06:40 | 000,000,000 | —D | C] – E:\Program Files\DWG TrueView 2009
[2010/07/27 22:06:40 | 000,000,000 | —D | C] – E:\Program Files\Common Files\Autodesk Shared
[2010/07/27 22:06:40 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Autodesk
[2010/07/27 22:06:23 | 001,985,904 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\D3DCompiler_35.dll
[2010/07/27 22:06:23 | 001,358,192 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\D3DCompiler_35.dll
[2010/07/27 22:06:23 | 000,508,264 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx10_35.dll
[2010/07/27 22:06:23 | 000,444,776 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx10_35.dll
[2010/07/27 22:06:08 | 005,073,256 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\d3dx9_35.dll
[2010/07/27 18:24:55 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft WSE
[2010/07/27 18:20:46 | 003,727,720 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\d3dx9_35.dll
[2010/07/27 18:20:02 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Autodesk Shared
[2010/07/27 18:20:02 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Autodesk
[2010/07/27 18:12:48 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Sun
[2010/07/27 18:12:47 | 000,061,555 | —- | C] (Sun Microsystems) – E:\Windows\SysWow64\jpicpl32.cpl
[2010/07/27 18:12:20 | 000,000,000 | —D | C] – E:\Program Files (x86)\Java
[2010/07/27 18:12:20 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Java
[2010/07/27 18:12:16 | 000,000,000 | —D | C] – E:\Program Files (x86)\Autodesk
[2010/07/27 18:12:11 | 000,000,000 | —D | C] – E:\ProgramData\Autodesk
[2010/07/27 18:12:07 | 000,000,000 | —D | C] – E:\Program Files (x86)\Autodesk Network License Manager
[2010/07/27 18:04:18 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\TempSWBackupDirectory
[2010/07/27 17:58:05 | 000,000,000 | —D | C] – E:\ProgramData\FLEXnet
[2010/07/27 17:48:27 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Macrovision Shared
[2010/07/27 17:47:47 | 000,000,000 | —D | C] – E:\Program Files (x86)\SolidWorks Corp
[2010/07/27 17:47:25 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\SolidWorks Visual Studio Tools for Applications
[2010/07/27 17:46:19 | 000,000,000 | —D | C] – E:\Program Files\Common Files\Macrovision Shared
[2010/07/27 17:45:22 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\SolidWorks Shared
[2010/07/27 17:44:42 | 000,000,000 | —D | C] – E:\Program Files (x86)\SolidWorksx86
[2010/07/27 17:44:29 | 000,000,000 | —D | C] – E:\Program Files (x86)\AGEIA Technologies
[2010/07/27 17:44:28 | 000,000,000 | —D | C] – E:\Program Files\Common Files\SolidWorks Shared
[2010/07/27 17:44:28 | 000,000,000 | —D | C] – E:\Program Files\SolidWorks Corp
[2010/07/27 17:44:28 | 000,000,000 | —D | C] – E:\ProgramData\SolidWorks
[2010/07/27 17:43:51 | 000,000,000 | —D | C] – E:\Program Files\Microsoft Visual Studio 8
[2010/07/27 17:43:46 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\Visual Studio 2005
[2010/07/27 17:43:41 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Microsoft Help
[2010/07/27 17:43:27 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\Designer
[2010/07/27 17:43:23 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft Visual Studio 8
[2010/07/27 17:43:22 | 000,000,000 | —D | C] – E:\ProgramData\Microsoft Help
[2010/07/27 17:43:04 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft.NET
[2010/07/27 17:43:04 | 000,000,000 | —D | C] – E:\Program Files (x86)\Microsoft Office
[2010/07/27 17:43:02 | 000,000,000 | —D | C] – E:\Program Files (x86)\MSECache
[2010/07/27 17:41:40 | 000,000,000 | —D | C] – E:\SolidWorks Data
[2010/07/27 17:41:21 | 000,000,000 | —D | C] – E:\Program Files (x86)\Common Files\SolidWorks Installation Manager
[2010/07/27 17:40:32 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\WinRAR
[2010/07/27 17:40:16 | 000,000,000 | —D | C] – E:\Program Files\WinRAR
[2010/07/27 17:39:14 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\ElevatedDiagnostics
[2010/07/27 17:38:59 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Diagnostics
[2010/07/27 17:36:04 | 000,000,000 | —D | C] – E:\Users\Scott\Documents\SolidWorks Downloads
[2010/07/27 17:36:04 | 000,000,000 | —D | C] – E:\Windows\SolidWorks
[2010/07/27 17:36:03 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\SolidWorks
[2010/07/27 17:32:44 | 000,000,000 | —D | C] – E:\Program Files (x86)\uTorrent
[2010/07/27 17:32:19 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\uTorrent
[2010/07/27 12:22:43 | 000,000,000 | —D | C] – E:\Windows\Panther
[2010/07/27 12:14:13 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\DAEMON Tools Lite
[2010/07/27 12:12:20 | 000,000,000 | —D | C] – E:\ProgramData\DAEMON Tools Lite
[2010/07/27 11:58:25 | 001,942,856 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\dfshim.dll
[2010/07/27 11:58:25 | 001,130,824 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\dfshim.dll
[2010/07/27 11:58:25 | 000,320,352 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\PresentationHost.exe
[2010/07/27 11:58:25 | 000,295,264 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\PresentationHost.exe
[2010/07/27 11:58:25 | 000,109,912 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\PresentationHostProxy.dll
[2010/07/27 11:58:25 | 000,099,176 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\PresentationHostProxy.dll
[2010/07/27 11:58:25 | 000,049,472 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\netfxperf.dll
[2010/07/27 11:58:25 | 000,048,960 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\netfxperf.dll
[2010/07/27 11:53:33 | 000,424,960 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\secproc.dll
[2010/07/27 11:53:33 | 000,422,912 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\secproc_isv.dll
[2010/07/27 11:53:33 | 000,369,152 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\secproc.dll
[2010/07/27 11:53:33 | 000,365,568 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\secproc_isv.dll
[2010/07/27 11:53:33 | 000,357,888 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\RMActivate_isv.exe
[2010/07/27 11:53:33 | 000,356,352 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\RMActivate.exe
[2010/07/27 11:53:33 | 000,306,688 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\RMActivate_ssp.exe
[2010/07/27 11:53:33 | 000,305,152 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/07/27 11:53:32 | 000,324,608 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\RMActivate_isv.exe
[2010/07/27 11:53:32 | 000,320,512 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\RMActivate.exe
[2010/07/27 11:53:32 | 000,121,856 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\secproc_ssp_isv.dll
[2010/07/27 11:53:32 | 000,121,856 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\secproc_ssp.dll
[2010/07/27 11:53:32 | 000,085,504 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/07/27 11:53:32 | 000,085,504 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\secproc_ssp.dll
[2010/07/27 11:53:31 | 000,280,064 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\RMActivate_ssp.exe
[2010/07/27 11:53:31 | 000,277,504 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/07/27 11:53:28 | 014,629,376 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\wmp.dll
[2010/07/27 11:53:26 | 011,406,336 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\wmp.dll
[2010/07/27 11:53:26 | 001,975,296 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\CertEnroll.dll
[2010/07/27 11:53:25 | 001,320,960 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\CertEnroll.dll
[2010/07/27 11:53:24 | 012,625,920 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\wmploc.DLL
[2010/07/27 11:53:24 | 012,625,408 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\wmploc.DLL
[2010/07/27 11:53:21 | 001,572,352 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\quartz.dll
[2010/07/27 11:53:21 | 001,328,640 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\quartz.dll
[2010/07/27 11:53:21 | 000,091,648 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\avifil32.dll
[2010/07/27 11:53:21 | 000,084,480 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\mciavi32.dll
[2010/07/27 11:52:40 | 001,446,912 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\lsasrv.dll
[2010/07/27 11:52:29 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – E:\Windows\SysNative\atmfd.dll
[2010/07/27 11:52:29 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – E:\Windows\SysWow64\atmfd.dll
[2010/07/27 11:52:29 | 000,100,864 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\fontsub.dll
[2010/07/27 11:52:29 | 000,070,656 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\fontsub.dll
[2010/07/27 11:52:29 | 000,046,080 | —- | C] (Adobe Systems) – E:\Windows\SysNative\atmlib.dll
[2010/07/27 11:52:29 | 000,034,304 | —- | C] (Adobe Systems) – E:\Windows\SysWow64\atmlib.dll
[2010/07/27 11:52:22 | 000,961,024 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\CPFilters.dll
[2010/07/27 11:52:22 | 000,641,536 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\CPFilters.dll
[2010/07/27 11:52:22 | 000,613,888 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\psisdecd.dll
[2010/07/27 11:52:22 | 000,552,960 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\msdri.dll
[2010/07/27 11:52:22 | 000,288,256 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\MSNP.ax
[2010/07/27 11:52:22 | 000,258,560 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\mpg2splt.ax
[2010/07/27 11:52:22 | 000,204,288 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\MSNP.ax
[2010/07/27 11:52:21 | 000,465,408 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\psisdecd.dll
[2010/07/27 11:52:21 | 000,199,680 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\mpg2splt.ax
[2010/07/27 11:52:08 | 000,852,480 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\jscript.dll
[2010/07/27 11:52:08 | 000,716,800 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\jscript.dll
[2010/07/27 11:52:02 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\avgrssta.dll
[2010/07/27 11:52:01 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/27 11:52:00 | 001,736,608 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\ntdll.dll
[2010/07/27 11:51:58 | 002,870,272 | —- | C] (Microsoft Corporation) – E:\Windows\explorer.exe
[2010/07/27 11:51:58 | 002,614,272 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\explorer.exe
[2010/07/27 11:51:58 | 000,389,632 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\winlogon.exe
[2010/07/27 11:51:57 | 000,144,384 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\cdd.dll
[2010/07/27 11:51:56 | 000,269,904 | —- | C] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/27 11:51:56 | 000,148,480 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\t2embed.dll
[2010/07/27 11:51:56 | 000,108,544 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\t2embed.dll
[2010/07/27 11:51:55 | 000,243,200 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\wow64.dll
[2010/07/27 11:51:55 | 000,035,536 | —- | C] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/27 11:51:55 | 000,025,600 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\setup16.exe
[2010/07/27 11:51:55 | 000,014,336 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\ntvdm64.dll
[2010/07/27 11:51:55 | 000,007,680 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\instnm.exe
[2010/07/27 11:51:55 | 000,005,120 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\wow32.dll
[2010/07/27 11:51:55 | 000,002,048 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\user.exe
[2010/07/27 11:51:54 | 000,139,264 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\cabview.dll
[2010/07/27 11:51:54 | 000,132,608 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\cabview.dll
[2010/07/27 11:51:54 | 000,046,592 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\msasn1.dll
[2010/07/27 11:51:54 | 000,000,000 | —D | C] – E:\Windows\SysNative\drivers\Avg
[2010/07/27 11:51:52 | 000,612,352 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\vbscript.dll
[2010/07/27 11:51:52 | 000,220,672 | —- | C] (Microsoft Corporation) – E:\Windows\SysNative\wintrust.dll
[2010/07/27 11:51:52 | 000,172,032 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\wintrust.dll
[2010/07/27 11:51:51 | 000,427,520 | —- | C] (Microsoft Corporation) – E:\Windows\SysWow64\vbscript.dll
[2010/07/27 11:48:29 | 000,000,000 | —D | C] – E:\Program Files (x86)\AVG
[2010/07/27 11:48:14 | 000,000,000 | —D | C] – E:\ProgramData\avg9
[2010/07/27 11:47:29 | 000,000,000 | -HSD | C] – E:\Windows\Installer
[2010/07/27 11:40:32 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Mozilla
[2010/07/27 11:40:32 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Mozilla
[2010/07/27 11:40:28 | 000,000,000 | —D | C] – E:\Program Files (x86)\Mozilla Firefox
[2010/07/27 11:36:38 | 000,000,000 | —D | C] – E:\Windows\SoftwareDistribution
[2010/07/27 11:34:56 | 000,000,000 | R–D | C] – E:\Users\Scott\Searches
[2010/07/27 11:34:56 | 000,000,000 | -H-D | C] – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/07/27 11:34:48 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Identities
[2010/07/27 11:34:46 | 000,000,000 | R–D | C] – E:\Users\Scott\Contacts
[2010/07/27 11:34:44 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\VirtualStore
[2010/07/27 11:34:30 | 000,000,000 | –SD | C] – E:\Users\Scott\AppData\Roaming\Microsoft
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Videos
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Saved Games
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Pictures
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Music
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Links
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Favorites
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Desktop\Downloads
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\My Documents
[2010/07/27 11:34:30 | 000,000,000 | R–D | C] – E:\Users\Scott\Desktop
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\AppData\Local\Temporary Internet Files
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Templates
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Start Menu
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\SendTo
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Recent
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\PrintHood
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\NetHood
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Documents\My Videos
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Documents\My Pictures
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Documents\My Music
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\My Documents
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Local Settings
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\AppData\Local\History
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Cookies
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\Application Data
[2010/07/27 11:34:30 | 000,000,000 | -HSD | C] – E:\Users\Scott\AppData\Local\Application Data
[2010/07/27 11:34:30 | 000,000,000 | -H-D | C] – E:\Users\Scott\AppData
[2010/07/27 11:34:30 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Temp
[2010/07/27 11:34:30 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Local\Microsoft
[2010/07/27 11:34:30 | 000,000,000 | —D | C] – E:\Users\Scott\AppData\Roaming\Media Center Programs
[2010/07/27 11:31:49 | 000,000,000 | -HSD | C] – E:\Recovery
[2010/07/27 11:23:50 | 000,000,000 | —D | C] – E:\Windows\Prefetch
[2010/07/27 11:23:25 | 000,000,000 | -HSD | C] – E:\System Volume Information
[1 E:\Windows\SysNative\drivers\*.tmp files -> E:\Windows\SysNative\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/12 10:48:20 | 002,621,440 | -HS- | M] () – E:\Users\Scott\NTUSER.DAT
[2010/08/12 10:26:39 | 000,779,882 | —- | M] () – E:\Windows\SysNative\PerfStringBackup.INI
[2010/08/12 10:26:39 | 000,665,914 | —- | M] () – E:\Windows\SysNative\perfh009.dat
[2010/08/12 10:26:39 | 000,125,210 | —- | M] () – E:\Windows\SysNative\perfc009.dat
[2010/08/12 09:20:18 | 000,013,536 | -H– | M] () – E:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/12 09:20:18 | 000,013,536 | -H– | M] () – E:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/12 09:14:42 | 000,000,006 | -H– | M] () – E:\Windows\tasks\SA.DAT
[2010/08/12 09:14:32 | 000,067,584 | –S- | M] () – E:\Windows\bootstat.dat
[2010/08/12 09:14:26 | 534,896,639 | -HS- | M] () – E:\hiberfil.sys
[2010/08/12 08:59:31 | 063,318,828 | —- | M] () – E:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/08/10 21:00:00 | 000,000,372 | —- | M] () – E:\Windows\tasks\At1.job
[2010/08/10 18:54:25 | 000,593,688 | —- | M] () – E:\Windows\SysNative\FNTCACHE.DAT
[2010/08/10 18:46:18 | 000,000,374 | —- | M] () – E:\Windows\tasks\At3.job
[2010/08/10 18:46:18 | 000,000,374 | —- | M] () – E:\Windows\tasks\At2.job
[2010/08/10 12:18:01 | 000,420,800 | —- | M] () – E:\Windows\SysNative\drivers\vsconfig.xml
[2010/08/10 09:05:17 | 000,001,825 | —- | M] () – E:\Users\Scott\Desktop\Microsoft Office - Shortcut.lnk
[2010/08/05 07:29:49 | 000,001,523 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\EASEUS Partition Master 6.0.1 Professional Edition.lnk
[2010/08/04 16:56:40 | 000,018,960 | —- | M] (Logitech, Inc.) – E:\Windows\SysNative\drivers\LNonPnP.sys
[2010/08/03 12:52:12 | 000,187,496 | —- | M] () – E:\Users\Scott\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/03 11:47:20 | 000,000,478 | —- | M] () – E:\Windows\win.ini
[2010/08/03 11:27:55 | 000,001,367 | —- | M] () – E:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/08/03 10:01:02 | 000,001,006 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2010/07/31 19:38:25 | 000,007,622 | —- | M] () – E:\Users\Scott\AppData\Local\Resmon.ResmonCfg
[2010/07/28 23:30:34 | 000,082,944 | —- | M] (Radius Inc.) – E:\Windows\SysWow64\iccvid.dll
[2010/07/27 22:33:06 | 000,788,376 | —- | M] () – E:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/27 17:48:49 | 000,002,691 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks Explorer 2010.lnk
[2010/07/27 17:48:49 | 000,002,141 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/27 17:47:53 | 000,000,000 | —- | M] () – E:\Windows\eDrawingOfficeAutomator.INI
[2010/07/27 17:47:09 | 000,000,023 | -H– | M] () – E:\Windows\yacht.xws
[2010/07/27 17:46:05 | 000,002,635 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2010 x64 Edition.lnk
[2010/07/27 17:32:46 | 000,000,981 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/07/27 12:14:46 | 000,834,544 | —- | M] () – E:\Windows\SysNative\drivers\sptd.sys
[2010/07/27 12:08:41 | 000,524,288 | -HS- | M] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/07/27 12:08:41 | 000,524,288 | -HS- | M] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/07/27 12:08:41 | 000,065,536 | -HS- | M] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/07/27 11:52:04 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\avgrssta.dll
[2010/07/27 11:52:02 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/27 11:51:56 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/27 11:51:56 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) – E:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/27 11:51:55 | 000,113,461 | —- | M] () – E:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/27 11:40:30 | 000,001,977 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/27 11:38:04 | 000,001,451 | —- | M] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/27 11:34:30 | 000,000,020 | -HS- | M] () – E:\Users\Scott\ntuser.ini
[2010/07/27 11:27:25 | 000,042,045 | —- | M] () – E:\Windows\SysWow64\license.rtf
[2010/07/27 11:27:25 | 000,042,045 | —- | M] () – E:\Windows\SysNative\license.rtf
[2010/07/27 11:25:34 | 000,000,000 | —- | M] () – E:\Windows\ativpsrm.bin
[2010/07/27 11:25:12 | 000,000,000 | -H– | M] () – E:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[1 E:\Windows\SysNative\drivers\*.tmp files -> E:\Windows\SysNative\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/10 12:16:04 | 000,420,800 | —- | C] () – E:\Windows\SysNative\drivers\vsconfig.xml
[2010/08/10 12:11:07 | 000,000,374 | —- | C] () – E:\Windows\tasks\At3.job
[2010/08/10 12:09:02 | 000,000,374 | —- | C] () – E:\Windows\tasks\At2.job
[2010/08/10 09:05:17 | 000,001,825 | —- | C] () – E:\Users\Scott\Desktop\Microsoft Office - Shortcut.lnk
[2010/08/05 07:29:49 | 000,001,523 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\EASEUS Partition Master 6.0.1 Professional Edition.lnk
[2010/08/05 07:29:46 | 002,209,920 | —- | C] () – E:\Windows\SysNative\BootMan.exe
[2010/08/05 07:29:46 | 001,774,720 | —- | C] () – E:\Windows\SysWow64\BootMan.exe
[2010/08/05 07:29:46 | 000,100,232 | —- | C] () – E:\Windows\SysNative\setupempdrvx64.exe
[2010/08/05 07:29:46 | 000,086,408 | —- | C] () – E:\Windows\SysWow64\setupempdrv03.exe
[2010/08/05 07:29:46 | 000,016,776 | —- | C] () – E:\Windows\SysNative\epmntdrv.sys
[2010/08/05 07:29:46 | 000,014,848 | —- | C] () – E:\Windows\SysWow64\EuEpmGdi.dll
[2010/08/05 07:29:46 | 000,014,216 | —- | C] () – E:\Windows\SysWow64\epmntdrv.sys
[2010/08/05 07:29:46 | 000,011,264 | —- | C] () – E:\Windows\SysNative\EuEpmGdi.dll
[2010/08/05 07:29:46 | 000,009,096 | —- | C] () – E:\Windows\SysNative\EuGdiDrv.sys
[2010/08/05 07:29:46 | 000,008,456 | —- | C] () – E:\Windows\SysWow64\EuGdiDrv.sys
[2010/08/05 07:29:05 | 000,000,372 | —- | C] () – E:\Windows\tasks\At1.job
[2010/08/03 11:27:55 | 000,001,367 | —- | C] () – E:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2010/08/03 10:01:02 | 000,001,006 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2010/07/31 19:38:25 | 000,007,622 | —- | C] () – E:\Users\Scott\AppData\Local\Resmon.ResmonCfg
[2010/07/27 22:16:30 | 000,788,376 | —- | C] () – E:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/27 18:12:47 | 000,028,779 | —- | C] () – E:\Windows\SysWow64\javaw.exe
[2010/07/27 18:12:47 | 000,024,681 | —- | C] () – E:\Windows\SysWow64\java.exe
[2010/07/27 17:48:49 | 000,002,691 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks Explorer 2010.lnk
[2010/07/27 17:47:53 | 000,000,000 | —- | C] () – E:\Windows\eDrawingOfficeAutomator.INI
[2010/07/27 17:47:49 | 000,002,141 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2010/07/27 17:47:09 | 000,000,023 | -H– | C] () – E:\Windows\yacht.xws
[2010/07/27 17:46:05 | 000,002,635 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2010 x64 Edition.lnk
[2010/07/27 17:32:46 | 000,000,981 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/07/27 12:14:45 | 000,834,544 | —- | C] () – E:\Windows\SysNative\drivers\sptd.sys
[2010/07/27 11:51:54 | 063,318,828 | —- | C] () – E:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/27 11:51:54 | 000,113,461 | —- | C] () – E:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/27 11:40:30 | 000,001,977 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/27 11:38:04 | 000,001,451 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/27 11:34:30 | 002,621,440 | -HS- | C] () – E:\Users\Scott\NTUSER.DAT
[2010/07/27 11:34:30 | 000,524,288 | -HS- | C] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/07/27 11:34:30 | 000,524,288 | -HS- | C] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/07/27 11:34:30 | 000,262,144 | -HS- | C] () – E:\Users\Scott\ntuser.dat.LOG1
[2010/07/27 11:34:30 | 000,065,536 | -HS- | C] () – E:\Users\Scott\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/07/27 11:34:30 | 000,000,290 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/07/27 11:34:30 | 000,000,272 | —- | C] () – E:\Users\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/07/27 11:34:30 | 000,000,020 | -HS- | C] () – E:\Users\Scott\ntuser.ini
[2010/07/27 11:34:30 | 000,000,000 | -HS- | C] () – E:\Users\Scott\ntuser.dat.LOG2
[2010/07/27 11:25:34 | 000,000,000 | —- | C] () – E:\Windows\ativpsrm.bin
[2010/07/27 11:25:12 | 000,000,000 | -H– | C] () – E:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/07/27 11:23:25 | 534,896,639 | -HS- | C] () – E:\hiberfil.sys
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – E:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – E:\Windows\SysWow64\msjetoledb40.dll
[2007/08/21 20:46:34 | 000,059,160 | —- | C] () – E:\Windows\SysWow64\zlib.dll

========== LOP Check ==========

[2010/07/27 22:42:29 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Ansys
[2010/08/12 09:34:23 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Autodesk
[2010/08/10 12:17:49 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\CheckPoint
[2010/07/27 17:35:39 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\DAEMON Tools Lite
[2010/08/03 11:27:09 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Leadertech
[2010/07/29 21:00:43 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Mael
[2010/08/03 11:18:59 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\Research In Motion
[2010/08/12 09:34:27 | 000,000,000 | —D | M] – E:\Users\Scott\AppData\Roaming\uTorrent
[2010/08/10 21:00:00 | 000,000,372 | —- | M] () – E:\Windows\Tasks\At1.job
[2010/08/10 18:46:18 | 000,000,374 | —- | M] () – E:\Windows\Tasks\At2.job
[2010/08/10 18:46:18 | 000,000,374 | —- | M] () – E:\Windows\Tasks\At3.job
[2009/07/13 22:08:49 | 000,008,960 | —- | M] () – E:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – E:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – E:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – E:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – E:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – E:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – E:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – E:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – E:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – E:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – E:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 18:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – E:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – E:\Windows\SysWOW64\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – E:\Windows\SysWOW64\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – E:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – E:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – E:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – E:\Windows\SysWOW64\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – E:\Windows\SysWOW64\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – E:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 18:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – E:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >

———————————————————————————————————————————————————————————————————————–
Here is the extras file log:

OTL Extras logfile created on: 8/12/2010 10:47:01 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = E:\Users\Scott\Desktop\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 66.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 298.09 Gb Total Space | 231.02 Gb Free Space | 77.50% Space Free | Partition Type: NTFS
Drive D: | 7.46 Gb Total Space | 6.81 Gb Free Space | 91.30% Space Free | Partition Type: FAT32
Drive E: | 931.51 Gb Total Space | 783.63 Gb Free Space | 84.12% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 232.88 Gb Total Space | 197.93 Gb Free Space | 84.99% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SCOTT-PC
Current User Name: Scott
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – E:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – E:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "E:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "E:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "E:\Windows\System32\rundll32.exe" "E:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "E:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – E:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "E:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "E:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "E:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "E:\Windows\System32\rundll32.exe" "E:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "E:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – E:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "E:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst
"{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}" = SolidWorks Explorer 2010 SP0 x64 Edition
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{50822200-2E95-4E62-A8D8-41C3B308DF5E}" = Microsoft SQL Server VSS Writer
"{542DDF04-9F91-4F36-B2F4-2638B788A4C8}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{5473360E-2990-4134-A38B-5575A76C8620}" = AOEMView 2009
"{5783F2D6-7028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2009
"{5783F2D7-9001-0409-0102-0060B0CE6BBA}" = AutoCAD 2011 - English
"{5783F2D7-9001-0409-1102-0060B0CE6BBA}" = AutoCAD 2011 Language Pack - English
"{5783F2D7-9004-0409-0102-0060B0CE6BBA}" = AutoCAD Architecture 2011 - English
"{5783F2D7-9004-0409-1102-0060B0CE6BBA}" = AutoCAD Architecture 2011 Language Pack - English
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.3
"{6E740973-8E71-42F9-A910-C18452E60450}" = Microsoft SQL Server Native Client
"{7F4DD591-1300-0409-0000-7107D70F3DB4}" = Autodesk Inventor Professional 2009
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{AC76BA86-1033-0000-0064-0003D0000004}" = Adobe Acrobat 9 Pro Extended 64-bit Add-On
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{E9173A5F-22A6-4152-848E-45851DB99162}" = SolidWorks 2010 x64 Edition SP0
"AOEMView 2009" = AOEMView 2009
"AutoCAD 2011 - English" = AutoCAD 2011 - English
"AutoCAD Architecture 2011 - English" = AutoCAD Architecture 2011 - English
"Autodesk Inventor Professional 2009" = Autodesk Inventor Professional 2009
"DWG TrueView 2009" = DWG TrueView 2009
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"SP6" = Logitech SetPoint 6.15
"WinRAR archiver" = WinRAR archiver
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{1959101B-E34C-4266-8915-20F23B5BCF43}" = SolidWorks eDrawings 2010
"{1965C9BB-9114-4A50-AEC7-E62414BB117B}" = EASEUS Data Recovery Wizard Professional 4.3.6
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (AUTODESKVAULT)
"{2B290B14-7013-0409-99B1-354B2D5D1D1E}" = Autodesk Inventor 2009 Network License Activation Utility
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3360D505-B0AA-4284-92DF-F872AF90A448}" = BlackBerry Device Software Updater
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{56DCD20A-E558-4396-AF59-14D15AA737BB}" = DWGeditor
"{5783F2D7-0111-0409-0010-0060B0CE6BBA}" = Autodesk CAD Manager Tools
"{7148F0A8-6813-11D6-A77B-00B0D0142040}" = Java 2 Runtime Environment, SE v1.4.2_04
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736D2DAD-3D87-4CAA-8646-83D238AD68E0}" = PhotoView 360
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{975951E7-14D0-49AF-A630-89680D12D7F6}" = Autodesk Material Library 2011 Medium Image library
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.07.14
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}_920" = Adobe Acrobat 9.2.0 - CPSID_50026
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{BB9FF67B-1A16-491B-81C5-272B145FEAB7}" = Autodesk Data Management Server 2009
"{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{FE2F2589-96A6-4F38-98F5-DDAC34BD41B9}" = Autodesk Network License Manager
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Autodesk Data Management Server 2009" = Autodesk Data Management Server 2009
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"AVG9Uninstall" = AVG Free 9.0
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"CCleaner" = CCleaner
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 6.0.1 Professional
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"SolidWorks Installation Manager 20100-40000-1100-100" = SolidWorks 2010 x64 Edition SP0
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.1
"ZoneAlarm" = ZoneAlarm

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/10/2010 1:38:38 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 1:38:38 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 3:09:01 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 3:09:01 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 3:23:09 PM | Computer Name = Scott-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.2.3855 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 13ec Start
Time: 01cb38c1435b4be2 Termination Time: 47 Application Path: E:\Program Files (x86)\Mozilla
Firefox\firefox.exe Report Id: b2a5ac7f-a4b4-11df-81a1-00241d2b2a17

Error - 8/10/2010 9:57:18 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 9:57:42 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/10/2010 9:57:42 PM | Computer Name = Scott-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "E:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: E:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
Component
2: E:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

Error - 8/11/2010 2:12:42 AM | Computer Name = Scott-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WSCommCntr1.exe, version: 17.2.56.0, time
stamp: 0x47ae8d9e Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0xe88 Faulting application
start time: 0x01cb390160a770c0 Faulting application path: E:\Program Files (x86)\Common
Files\Autodesk Shared\WSCommCntr1.exe Faulting module path: unknown Report Id: 72c870ab-a50f-11df-8759-00241d2b2a17

Error - 8/12/2010 12:20:55 PM | Computer Name = Scott-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WSCommCntr2.exe, version: 3.0.267.0, time
stamp: 0x4b71796a Faulting module name: ntdll.dll, version: 6.1.7600.16559, time
stamp: 0x4ba9b802 Exception code: 0xc0000005 Fault offset: 0x000000000004cf54 Faulting
process id: 0x598 Faulting application start time: 0x01cb3a3a562da4d9 Faulting application
path: E:\Program Files\Common Files\Autodesk Shared\WSCommCntr\lib\WSCommCntr2.exe
Faulting
module path: E:\Windows\SYSTEM32\ntdll.dll Report Id: 94b2ccf2-a62d-11df-a083-00241d2b2a17

[ System Events ]
Error - 8/12/2010 1:43:45 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:44:07 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:44:27 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:44:38 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:44:43 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:45:36 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:48:05 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:48:42 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:49:24 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/12/2010 1:49:39 PM | Computer Name = Scott-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.


< End of report >
———————————————————————————————————————————————————-
Hijack this log file:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:00:28 AM, on 12/08/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
E:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
E:\Program Files (x86)\AVG\AVG9\avgtray.exe
E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
E:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
E:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
E:\Users\Scott\Desktop\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = E:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - E:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - E:\Program Files (x86)\ZoneAlarm\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - E:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [AVG9_TRAY] E:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "E:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "E:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ISUSPM] "E:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Logitech . Product Registration.lnk = E:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O8 - Extra context menu item: Append to existing PDF - res://E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files (x86)\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - E:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - E:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - E:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - E:\Program Files (x86)\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - E:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - E:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - E:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - E:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - E:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - E:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - E:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - E:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - E:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - E:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - E:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - E:\Windows\system32\lsass.exe (file missing)
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - E:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - E:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - E:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - E:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - E:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - E:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - E:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - E:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - E:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - E:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - E:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - E:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - E:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - E:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - E:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - E:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - E:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - E:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - E:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11327 bytes
—————————————————————————————————————————–
I can't run the dds file as I have Autocad installed and it relates it to that, it just opens a bunch of letters and symbols in notepad…….


Thanks!
65 views to the topic and no one has a reply or any ideas? I need help people….PLEASE! There is someone out there that can help, just throw ideas out there, i'll try anything. Thanks! There are alot of "Crypitc" trojans out there but none I can find with the ".ASR" extension…so I'm stumped.
Cracks, Keygens and Warez

We don't provide help for those using any form of cracked software or Operating Systems.

In doing the crack, the 'cracker' has broken the 'End User Licence Agreement' (EULA) of the product.
The distribution and use of cracked copies is illegal in almost every developed country.
They are also one of the biggest causes of infection. If we where to help you it could be construed in the eyes of the law as aiding and abetting a crime.

This applies to Cracks, Keygens and Warez

In the future I strongly suggest you stay away from using cracks and/or Keygens.



Using the Torrents or any type of P2P programs are also guaranteed to get you infected

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI