This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

laptop very slow cant download hijackthis...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys im back with a new laptop and a new set of problems, recently the laptop has been behaving unusual yet avast says it is clear.
Firstly when avast tells me its downloaded new updates i get a screeching noise from the laptop which i cant turn down and have to press the off switch, everyday my windows or firefox are not responding, any program i am working on will just suddenly say its either not responding or has encountered a problem and i lose all my data. When i turn it on it can take up to 10mins for it to actually be ready to go online, and to top it all it wont let me download hi jack this.
Any help is gratefully appreciated…i have been able to download OTL so here are my logs…
OTL logfile created on: 8/26/2010 7:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Learner\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

766.00 Mb Total Physical Memory | 258.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 129.51 Gb Total Space | 91.29 Gb Free Space | 70.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 1.89 Gb Total Space | 0.37 Gb Free Space | 19.48% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WINDOWS-PJITBEU
Current User Name: Learner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Learner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10i_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\lxdncoms.exe ( )
PRC - C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Learner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MotoConnect Service) – C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (lxdn_device) – C:\Windows\System32\lxdncoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (MpFilter) – C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (KMWDFILTERx86) – C:\Windows\System32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (MPFP) – C:\Windows\System32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.nextgenerationlearning.org.uk/ourhomeaccess
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/index.php?lh=78ab0a747ed08026042e8922eeccdc8c&eu=Od4V-J9zttNc6bFGfShYlQ"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {eecba28f-b68b-4b3a-b501-6ce12e6b8696}:0.7.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.google.com.my/search?q="
FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/12 21:13:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/12 21:13:04 | 000,000,000 | —D | M]

[2010/04/23 18:05:48 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\mozilla\Extensions
[2010/08/25 14:18:10 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\mozilla\Firefox\Profiles\91v2xnty.default\extensions
[2010/05/26 19:11:08 | 000,000,000 | —D | M] (WOT) – C:\Users\Learner\AppData\Roaming\mozilla\Firefox\Profiles\91v2xnty.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/07/13 10:38:10 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Learner\AppData\Roaming\mozilla\Firefox\Profiles\91v2xnty.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/22 18:51:03 | 000,000,000 | —D | M] (ViewSourceWith) – C:\Users\Learner\AppData\Roaming\mozilla\Firefox\Profiles\91v2xnty.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}
[2010/07/28 10:44:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/09 16:08:27 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/28 10:45:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/28 10:44:38 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/12 21:12:53 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/12 21:12:53 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/12 21:12:53 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/12 21:12:53 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [O2Start] C:\Program Files\O2CM-CE\O2 Connection Manager\tscui.exe (O2)
O4 - HKLM..\Run: [Tupit2] c:\toshiba\preinst\tupit\tupitinst2.cmd File not found
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (Ulead Systems, Inc.)
O4 - HKLM..\Run: [XMA] C:\Program Files\XMA Ltd\Licenses.exe (XMA Ltd)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/m3/photoup…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0cb7dae7-4f36-11df-a314-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{0cb7dae7-4f36-11df-a314-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{12af8c15-6256-11df-a045-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{12af8c15-6256-11df-a045-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{33f71b1c-72dc-11df-8a07-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{33f71b1c-72dc-11df-8a07-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{5ef7f900-641b-11df-9220-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{5ef7f900-641b-11df-9220-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{86c1e4a5-4d23-11df-9cc6-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{86c1e4a5-4d23-11df-9cc6-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{8a3fd7d3-8813-11df-a3d3-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{8a3fd7d3-8813-11df-a3d3-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{8aa4ee66-50ba-11df-8a9a-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{8aa4ee66-50ba-11df-8a9a-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{b141d81b-7d42-11df-a67c-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{b141d81b-7d42-11df-a67c-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{c9cb4b0a-6451-11df-80ea-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{c9cb4b0a-6451-11df-80ea-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{e2889c2a-8a01-11df-b7f0-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{e2889c2a-8a01-11df-b7f0-705ab6796e28}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE – File not found
O33 - MountPoints2\{e705d61a-4e52-11df-90e5-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{e705d61a-4e52-11df-90e5-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O33 - MountPoints2\{f701a641-8a5d-11df-aa21-705ab6796e28}\Shell - "" = AutoRun
O33 - MountPoints2\{f701a641-8a5d-11df-aa21-705ab6796e28}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/26 19:21:03 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Learner\Desktop\OTL.exe
[2010/08/22 03:25:46 | 000,621,056 | —- | C] (DiBcom SA) – C:\Windows\System32\drivers\mod7700.sys
[2010/08/22 03:25:46 | 000,103,168 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbfake.sys
[2010/08/22 03:25:46 | 000,101,120 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbmdm.sys
[2010/08/22 03:25:46 | 000,100,992 | —- | C] (Huawei Technologies Co., Ltd.) – C:\Windows\System32\drivers\ewusbnet.sys
[2010/08/22 03:25:46 | 000,024,448 | —- | C] (Huawei Tech. Co., Ltd.) – C:\Windows\System32\drivers\ewdcsc.sys
[2010/08/21 13:14:47 | 000,000,000 | —D | C] – C:\Users\Learner\AppData\Roaming\Ulead Systems
[2010/08/21 13:01:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ulead Systems
[2010/08/21 13:00:24 | 000,000,000 | —D | C] – C:\ProgramData\Ulead Systems
[2010/08/21 13:00:24 | 000,000,000 | —D | C] – C:\Program Files\Corel
[2010/08/21 12:50:47 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2010/08/20 21:38:35 | 000,000,000 | —D | C] – C:\Users\Learner\Documents\SnagIt
[2010/08/20 21:38:04 | 000,000,000 | —D | C] – C:\Users\Learner\AppData\Local\assembly
[2010/08/20 21:34:27 | 000,000,000 | —D | C] – C:\ProgramData\TechSmith
[2010/08/20 21:34:14 | 000,000,000 | —D | C] – C:\Users\Learner\AppData\Local\TechSmith
[2010/08/20 21:34:14 | 000,000,000 | —D | C] – C:\Program Files\TechSmith
[2010/08/19 17:19:46 | 000,000,000 | —D | C] – C:\Users\Learner\Documents\Textures
[2010/08/19 17:19:46 | 000,000,000 | —D | C] – C:\Users\Learner\Documents\FotoMix Projects
[2010/08/19 17:19:45 | 000,066,800 | —- | C] (Just Great Software) – C:\Windows\UnDeployV.exe
[2010/08/19 17:19:45 | 000,000,000 | —D | C] – C:\Program Files\Digital Photo Software
[2010/08/15 13:12:27 | 000,017,744 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/08/15 13:12:25 | 000,165,456 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/08/15 13:12:23 | 000,023,376 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/08/15 13:12:21 | 000,046,672 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/08/15 13:12:16 | 000,050,256 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/08/15 13:11:38 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\avastSS.scr
[2010/08/15 13:11:35 | 000,165,032 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/08/11 21:39:49 | 000,197,632 | —- | C] (Intel® Corporation) – C:\Windows\System32\ir32_32.dll
[2010/08/11 21:39:49 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2010/08/11 21:39:39 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2010/08/11 21:39:37 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/08/11 21:39:36 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/08/11 21:39:24 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/08/11 21:39:23 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/08/11 21:39:22 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/08/11 21:39:22 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/08/11 21:39:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/08/11 21:39:20 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/08/11 21:39:20 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/08/11 21:39:19 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/08/11 21:39:07 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/08/10 20:47:09 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/08/10 20:46:40 | 000,000,000 | —D | C] – C:\Users\Learner\AppData\Local\Google
[2010/08/08 19:41:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/07/30 16:06:11 | 000,000,000 | —D | C] – C:\Users\Learner\AppData\Local\ElevatedDiagnostics
[2010/07/28 10:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/07/28 10:45:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/28 10:44:54 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/07/28 10:44:54 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/07/28 10:44:54 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/07/28 10:44:54 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2009/10/20 17:59:04 | 000,409,600 | —- | C] ( ) – C:\Windows\System32\lxdncoin.dll
[2007/11/28 15:19:08 | 000,647,168 | —- | C] ( ) – C:\Windows\System32\lxdnpmui.dll
[2007/11/28 15:16:04 | 001,101,824 | —- | C] ( ) – C:\Windows\System32\lxdnserv.dll
[2007/11/28 15:13:38 | 000,569,344 | —- | C] ( ) – C:\Windows\System32\lxdnlmpm.dll
[2007/11/28 15:13:30 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdniesc.dll
[2007/11/28 15:13:22 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxdncomm.dll
[2007/11/28 15:12:26 | 000,663,552 | —- | C] ( ) – C:\Windows\System32\lxdnhbn3.dll
[2007/11/28 15:12:08 | 000,843,776 | —- | C] ( ) – C:\Windows\System32\lxdnusb1.dll
[2007/11/28 15:11:48 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxdncomc.dll
[2007/11/28 15:10:52 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\lxdnprox.dll
[2007/11/28 15:09:18 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxdninpa.dll
[23 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[23 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Learner\Documents\*.tmp files -> C:\Users\Learner\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/26 19:27:28 | 003,670,016 | -HS- | M] () – C:\Users\Learner\ntuser.dat
[2010/08/26 19:21:34 | 000,016,976 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 19:21:34 | 000,016,976 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/26 19:21:12 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Learner\Desktop\OTL.exe
[2010/08/26 19:13:58 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/26 19:13:34 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/26 19:12:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/26 19:12:47 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2010/08/26 18:52:01 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/25 20:54:54 | 004,125,039 | -H– | M] () – C:\Users\Learner\AppData\Local\IconCache.db
[2010/08/25 17:29:18 | 000,720,488 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/08/25 17:29:18 | 000,623,784 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/08/25 17:29:18 | 000,109,736 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/08/24 22:13:28 | 000,002,387 | —- | M] () – C:\Users\Learner\Desktop\BECTA How To Guide.lnk
[2010/08/24 18:11:59 | 000,010,216 | —- | M] () – C:\Users\Learner\Documents\dating a soldier.docx
[2010/08/22 03:06:00 | 000,434,960 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/21 13:46:20 | 000,121,760 | —- | M] () – C:\Users\Learner\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/21 13:06:38 | 000,001,990 | —- | M] () – C:\Users\Public\Desktop\PhotoImpact X3.lnk
[2010/08/21 10:42:18 | 000,010,292 | —- | M] () – C:\Users\Learner\Documents\Snack Menu.docx
[2010/08/20 21:35:03 | 000,002,082 | —- | M] () – C:\Users\Public\Desktop\Snagit 10 Editor.lnk
[2010/08/20 21:35:03 | 000,002,062 | —- | M] () – C:\Users\Learner\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk
[2010/08/20 21:35:03 | 000,002,038 | —- | M] () – C:\Users\Public\Desktop\Snagit 10.lnk
[2010/08/19 21:10:25 | 000,021,593 | —- | M] () – C:\Users\Learner\Documents\307.2.docx
[2010/08/19 17:19:47 | 000,001,237 | —- | M] () – C:\Users\Public\Desktop\FotoMix.lnk
[2010/08/18 00:28:18 | 000,020,945 | —- | M] () – C:\Users\Learner\Documents\307.1.docx
[2010/08/17 18:24:28 | 000,001,259 | —- | M] () – C:\Users\Learner\Desktop\Paint.NET.lnk
[2010/08/17 18:24:27 | 000,001,453 | —- | M] () – C:\Users\Learner\Desktop\Know IT All For Parents.lnk
[2010/08/17 18:24:27 | 000,001,142 | —- | M] () – C:\Users\Learner\Desktop\iZoom.lnk
[2010/08/17 17:55:36 | 000,000,162 | -H– | M] () – C:\Users\Learner\Documents\~$307.2.docx
[2010/08/17 15:35:43 | 000,001,559 | —- | M] () – C:\Users\Learner\Desktop\DivX Movies.lnk
[2010/08/17 15:34:47 | 000,001,092 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/08/17 15:34:30 | 000,001,132 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/08/17 15:32:51 | 000,002,222 | —- | M] () – C:\Users\Public\Desktop\EA Download Manager.lnk
[2010/08/15 13:12:29 | 000,002,015 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/15 13:12:15 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/08/13 22:48:51 | 000,019,926 | —- | M] () – C:\Users\Learner\Documents\During an afternoon session - Copy.docx
[2010/08/12 23:12:27 | 000,011,613 | —- | M] () – C:\Users\Learner\Documents\CIVVY FRIENDS.docx
[2010/08/10 21:31:12 | 000,033,274 | —- | M] () – C:\Users\Learner\Documents\cv.docx
[2010/08/08 19:43:01 | 000,001,990 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/30 16:05:59 | 000,000,382 | —- | M] () – C:\Users\Public\Desktop\Complete Installation of Lexmark 2600 Series.LNK
[2010/07/30 11:32:35 | 000,013,434 | —- | M] () – C:\Windows\System32\LexFiles.ulf
[2010/07/29 11:29:42 | 000,000,162 | -H– | M] () – C:\Users\Learner\Documents\~$semount House Lisa Lomas.docx
[2010/07/29 11:28:18 | 000,012,872 | —- | M] () – C:\Users\Learner\Documents\metropoliton Lisa Lomas.docx
[2010/07/29 11:24:46 | 000,000,162 | -H– | M] () – C:\Users\Learner\Documents\~$tropoliton Lisa Lomas.docx
[2010/07/29 07:30:49 | 000,197,632 | —- | M] (Intel® Corporation) – C:\Windows\System32\ir32_32.dll
[2010/07/29 07:30:34 | 000,082,944 | —- | M] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2010/07/28 15:03:17 | 000,524,288 | -HS- | M] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TMContainer00000000000000000002.regtrans-ms
[2010/07/28 15:03:17 | 000,524,288 | -HS- | M] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TMContainer00000000000000000001.regtrans-ms
[2010/07/28 15:03:17 | 000,065,536 | -HS- | M] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TM.blf
[2010/07/28 10:44:35 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/07/28 10:44:35 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/07/28 10:44:35 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/07/28 10:44:35 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[23 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[23 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Learner\Documents\*.tmp files -> C:\Users\Learner\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/24 18:11:55 | 000,010,216 | —- | C] () – C:\Users\Learner\Documents\dating a soldier.docx
[2010/08/21 13:06:38 | 000,001,990 | —- | C] () – C:\Users\Public\Desktop\PhotoImpact X3.lnk
[2010/08/21 10:42:14 | 000,010,292 | —- | C] () – C:\Users\Learner\Documents\Snack Menu.docx
[2010/08/20 21:35:03 | 000,002,082 | —- | C] () – C:\Users\Public\Desktop\Snagit 10 Editor.lnk
[2010/08/20 21:35:03 | 000,002,062 | —- | C] () – C:\Users\Learner\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk
[2010/08/20 21:35:03 | 000,002,038 | —- | C] () – C:\Users\Public\Desktop\Snagit 10.lnk
[2010/08/19 17:19:47 | 000,001,237 | —- | C] () – C:\Users\Public\Desktop\FotoMix.lnk
[2010/08/17 17:55:36 | 000,000,162 | -H– | C] () – C:\Users\Learner\Documents\~$307.2.docx
[2010/08/17 15:32:50 | 000,002,222 | —- | C] () – C:\Users\Public\Desktop\EA Download Manager.lnk
[2010/08/15 22:59:08 | 000,021,593 | —- | C] () – C:\Users\Learner\Documents\307.2.docx
[2010/08/15 22:16:43 | 000,019,926 | —- | C] () – C:\Users\Learner\Documents\During an afternoon session - Copy.docx
[2010/08/15 13:12:29 | 000,002,015 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/12 23:12:26 | 000,011,613 | —- | C] () – C:\Users\Learner\Documents\CIVVY FRIENDS.docx
[2010/08/10 20:47:47 | 000,000,888 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/10 20:47:38 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/10 00:22:18 | 000,033,274 | —- | C] () – C:\Users\Learner\Documents\cv.docx
[2010/08/08 19:41:30 | 000,001,990 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/06 22:29:57 | 000,020,945 | —- | C] () – C:\Users\Learner\Documents\307.1.docx
[2010/07/30 16:05:59 | 000,000,382 | —- | C] () – C:\Users\Public\Desktop\Complete Installation of Lexmark 2600 Series.LNK
[2010/07/29 11:29:42 | 000,000,162 | -H– | C] () – C:\Users\Learner\Documents\~$semount House Lisa Lomas.docx
[2010/07/29 11:24:46 | 000,000,162 | -H– | C] () – C:\Users\Learner\Documents\~$tropoliton Lisa Lomas.docx
[2010/07/28 10:25:20 | 000,524,288 | -HS- | C] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TMContainer00000000000000000002.regtrans-ms
[2010/07/28 10:25:20 | 000,524,288 | -HS- | C] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TMContainer00000000000000000001.regtrans-ms
[2010/07/28 10:25:20 | 000,065,536 | -HS- | C] () – C:\Users\Learner\ntuser.dat{377aca5a-9a27-11df-a3f3-705ab6796e28}.TM.blf
[2010/06/17 21:29:09 | 000,010,240 | —- | C] () – C:\Users\Learner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/21 11:00:56 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/04/22 09:15:26 | 000,045,056 | —- | C] () – C:\Windows\System32\LXF3PMON.DLL
[2010/04/22 09:15:26 | 000,032,768 | —- | C] () – C:\Windows\System32\LXF3FXPU.DLL
[2010/04/22 09:15:06 | 000,053,248 | —- | C] () – C:\Windows\System32\lxf3oem.dll
[2010/04/22 09:15:06 | 000,012,288 | —- | C] () – C:\Windows\System32\LXF3PMRC.DLL
[2009/09/08 14:34:56 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/23 19:49:04 | 000,782,336 | —- | C] () – C:\Windows\System32\lxdndrs.dll
[2009/07/14 09:02:58 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdngrd.dll
[2009/07/14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/05/14 13:46:40 | 000,081,920 | —- | C] () – C:\Windows\System32\lxdncaps.dll
[2008/03/31 19:47:44 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdnvs.dll
[2007/10/02 14:51:10 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdncnv4.dll
[2007/06/29 10:25:12 | 000,033,664 | —- | C] () – C:\Windows\System32\drivers\TsWlan.sys
[2002/03/17 01:00:00 | 000,007,420 | —- | C] () – C:\Windows\UA000091.DLL

========== LOP Check ==========

[2010/04/21 10:20:22 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\Issist
[2010/05/02 21:24:28 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\Lexmark Productivity Studio
[2010/04/23 23:19:26 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\Tatara Systems
[2010/04/27 19:16:58 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\Texthelp Systems
[2010/08/21 13:14:47 | 000,000,000 | —D | M] – C:\Users\Learner\AppData\Roaming\Ulead Systems
[2010/07/09 00:15:28 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/21 23:31:42 | 000,003,920 | —- | M] () – C:\2364_2504_20100421233142.DAT
[2010/04/21 23:32:42 | 000,001,360 | —- | M] () – C:\2364_2504_20100421233242.DAT
[2010/04/21 23:33:42 | 000,002,152 | —- | M] () – C:\2364_2504_20100421233342.DAT
[2010/04/21 23:34:42 | 000,001,728 | —- | M] () – C:\2364_2504_20100421233442.DAT
[2010/04/21 23:35:42 | 000,001,728 | —- | M] () – C:\2364_2504_20100421233542.DAT
[2010/04/21 23:36:42 | 000,002,128 | —- | M] () – C:\2364_2504_20100421233642.DAT
[2010/04/21 23:37:43 | 000,002,128 | —- | M] () – C:\2364_2504_20100421233743.DAT
[2010/04/21 23:38:43 | 000,002,128 | —- | M] () – C:\2364_2504_20100421233843.DAT
[2010/04/21 23:39:43 | 000,002,128 | —- | M] () – C:\2364_2504_20100421233943.DAT
[2010/04/21 23:40:43 | 000,002,552 | —- | M] () – C:\2364_2504_20100421234043.DAT
[2010/04/21 23:41:43 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234143.DAT
[2010/04/21 23:42:43 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234243.DAT
[2010/04/21 23:43:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234344.DAT
[2010/04/21 23:44:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234444.DAT
[2010/04/21 23:45:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234544.DAT
[2010/04/21 23:46:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234644.DAT
[2010/04/21 23:47:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234744.DAT
[2010/04/21 23:48:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234844.DAT
[2010/04/21 23:49:44 | 000,002,128 | —- | M] () – C:\2364_2504_20100421234944.DAT
[2010/04/21 23:50:45 | 000,002,960 | —- | M] () – C:\2364_2504_20100421235045.DAT
[2010/04/21 23:51:45 | 000,002,592 | —- | M] () – C:\2364_2504_20100421235145.DAT
[2010/04/21 23:52:45 | 000,002,192 | —- | M] () – C:\2364_2504_20100421235245.DAT
[2010/04/21 23:53:45 | 000,002,176 | —- | M] () – C:\2364_2504_20100421235345.DAT
[2010/04/21 23:54:45 | 000,001,760 | —- | M] () – C:\2364_2504_20100421235445.DAT
[2010/04/21 23:55:45 | 000,003,184 | —- | M] () – C:\2364_2504_20100421235545.DAT
[2010/04/21 23:56:46 | 000,003,360 | —- | M] () – C:\2364_2504_20100421235646.DAT
[2010/04/21 23:57:46 | 000,003,968 | —- | M] () – C:\2364_2504_20100421235746.DAT
[2010/04/21 23:58:46 | 000,002,136 | —- | M] () – C:\2364_2504_20100421235846.DAT
[2010/04/21 23:59:46 | 000,002,736 | —- | M] () – C:\2364_2504_20100421235946.DAT
[2010/04/22 00:00:46 | 000,003,480 | —- | M] () – C:\2364_2504_20100422000046.DAT
[2010/04/22 00:01:46 | 000,002,576 | —- | M] () – C:\2364_2504_20100422000146.DAT
[2010/04/22 00:02:46 | 000,003,008 | —- | M] () – C:\2364_2504_20100422000246.DAT
[2010/04/22 00:03:47 | 000,001,760 | —- | M] () – C:\2364_2504_20100422000347.DAT
[2010/04/22 00:04:47 | 000,001,760 | —- | M] () – C:\2364_2504_20100422000447.DAT
[2010/04/22 00:05:47 | 000,002,176 | —- | M] () – C:\2364_2504_20100422000547.DAT
[2010/04/22 00:06:48 | 000,001,976 | —- | M] () – C:\2364_2504_20100422000648.DAT
[2010/04/22 00:07:48 | 000,002,192 | —- | M] () – C:\2364_2504_20100422000748.DAT
[2010/04/22 00:08:48 | 000,001,928 | —- | M] () – C:\2364_2504_20100422000848.DAT
[2010/04/22 00:09:48 | 000,002,152 | —- | M] () – C:\2364_2504_20100422000948.DAT
[2010/04/22 00:10:48 | 000,001,360 | —- | M] () – C:\2364_2504_20100422001048.DAT
[2010/04/22 00:11:48 | 000,002,112 | —- | M] () – C:\2364_2504_20100422001148.DAT
[2010/04/22 00:12:48 | 000,002,584 | —- | M] () – C:\2364_2504_20100422001248.DAT
[2010/04/22 00:13:48 | 000,001,960 | —- | M] () – C:\2364_2504_20100422001348.DAT
[2010/04/22 00:14:49 | 000,002,176 | —- | M] () – C:\2364_2504_20100422001449.DAT
[2010/04/22 00:15:49 | 000,001,744 | —- | M] () – C:\2364_2504_20100422001549.DAT
[2010/04/22 00:16:49 | 000,002,336 | —- | M] () – C:\2364_2504_20100422001649.DAT
[2010/04/22 00:17:49 | 000,002,120 | —- | M] () – C:\2364_2504_20100422001749.DAT
[2010/04/22 00:18:49 | 000,001,736 | —- | M] () – C:\2364_2504_20100422001849.DAT
[2010/04/22 00:19:50 | 000,001,736 | —- | M] () – C:\2364_2504_20100422001950.DAT
[2010/04/22 00:20:50 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002050.DAT
[2010/04/22 00:21:50 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002150.DAT
[2010/04/22 00:22:50 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002250.DAT
[2010/04/22 00:23:50 | 000,001,520 | —- | M] () – C:\2364_2504_20100422002350.DAT
[2010/04/22 00:24:50 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002450.DAT
[2010/04/22 00:25:51 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002551.DAT
[2010/04/22 00:26:51 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002651.DAT
[2010/04/22 00:27:51 | 000,001,520 | —- | M] () – C:\2364_2504_20100422002751.DAT
[2010/04/22 00:28:51 | 000,001,736 | —- | M] () – C:\2364_2504_20100422002851.DAT
[2010/04/22 00:29:52 | 000,001,952 | —- | M] () – C:\2364_2504_20100422002952.DAT
[2010/04/22 00:30:52 | 000,002,936 | —- | M] () – C:\2364_2504_20100422003052.DAT
[2010/04/22 00:31:52 | 000,002,168 | —- | M] () – C:\2364_2504_20100422003152.DAT
[2010/04/22 00:32:52 | 000,001,960 | —- | M] () – C:\2364_2504_20100422003252.DAT
[2010/04/22 00:33:52 | 000,001,744 | —- | M] () – C:\2364_2504_20100422003352.DAT
[2010/04/22 00:34:52 | 000,001,960 | —- | M] () – C:\2364_2504_20100422003452.DAT
[2010/04/22 00:35:53 | 000,001,744 | —- | M] () – C:\2364_2504_20100422003553.DAT
[2010/04/22 00:36:53 | 000,001,744 | —- | M] () – C:\2364_2504_20100422003653.DAT
[2010/04/22 00:37:53 | 000,001,944 | —- | M] () – C:\2364_2504_20100422003753.DAT
[2010/04/22 00:38:53 | 000,002,712 | —- | M] () – C:\2364_2504_20100422003853.DAT
[2010/04/22 00:39:53 | 000,002,752 | —- | M] () – C:\2364_2504_20100422003953.DAT
[2010/04/22 00:40:53 | 000,001,736 | —- | M] () – C:\2364_2504_20100422004053.DAT
[2010/04/22 00:41:53 | 000,002,344 | —- | M] () – C:\2364_2504_20100422004153.DAT
[2010/04/22 00:42:54 | 000,001,960 | —- | M] () – C:\2364_2504_20100422004254.DAT
[2010/04/22 00:43:54 | 000,002,176 | —- | M] () – C:\2364_2504_20100422004354.DAT
[2010/04/22 00:44:54 | 000,002,712 | —- | M] () – C:\2364_2504_20100422004454.DAT
[2010/04/22 00:45:54 | 000,002,536 | —- | M] () – C:\2364_2504_20100422004554.DAT
[2010/04/22 00:46:54 | 000,002,336 | —- | M] () – C:\2364_2504_20100422004654.DAT
[2010/04/22 00:47:54 | 000,002,336 | —- | M] () – C:\2364_2504_20100422004754.DAT
[2010/04/22 00:48:54 | 000,001,744 | —- | M] () – C:\2364_2504_20100422004854.DAT
[2010/04/22 00:49:54 | 000,001,960 | —- | M] () – C:\2364_2504_20100422004954.DAT
[2010/04/22 00:50:55 | 000,001,960 | —- | M] () – C:\2364_2504_20100422005055.DAT
[2010/04/22 00:51:55 | 000,001,744 | —- | M] () – C:\2364_2504_20100422005155.DAT
[2010/04/22 00:52:55 | 000,001,744 | —- | M] () – C:\2364_2504_20100422005255.DAT
[2010/04/22 00:53:55 | 000,001,736 | —- | M] () – C:\2364_2504_20100422005355.DAT
[2010/04/22 00:54:55 | 000,001,736 | —- | M] () – C:\2364_2504_20100422005455.DAT
[2010/04/22 00:55:55 | 000,001,744 | —- | M] () – C:\2364_2504_20100422005555.DAT
[2010/04/22 00:56:56 | 000,001,744 | —- | M] () – C:\2364_2504_20100422005656.DAT
[2010/04/22 00:57:56 | 000,001,744 | —- | M] () – C:\2364_2504_20100422005756.DAT
[2010/04/22 00:58:56 | 000,001,520 | —- | M] () – C:\2364_2504_20100422005856.DAT
[2010/04/22 00:59:56 | 000,001,520 | —- | M] () – C:\2364_2504_20100422005956.DAT
[2010/04/22 01:00:56 | 000,001,520 | —- | M] () – C:\2364_2504_20100422010056.DAT
[2010/04/22 01:01:56 | 000,001,520 | —- | M] () – C:\2364_2504_20100422010156.DAT
[2010/04/22 01:02:56 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010256.DAT
[2010/04/22 01:03:56 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010356.DAT
[2010/04/22 01:04:56 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010456.DAT
[2010/04/22 01:05:57 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010557.DAT
[2010/04/22 01:06:57 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010657.DAT
[2010/04/22 01:07:57 | 000,001,856 | —- | M] () – C:\2364_2504_20100422010757.DAT
[2010/04/22 01:08:57 | 000,002,064 | —- | M] () – C:\2364_2504_20100422010857.DAT
[2010/04/22 01:09:57 | 000,002,168 | —- | M] () – C:\2364_2504_20100422010957.DAT
[2010/04/22 01:10:57 | 000,002,400 | —- | M] () – C:\2364_2504_20100422011057.DAT
[2010/04/22 01:11:57 | 000,001,344 | —- | M] () – C:\2364_2504_20100422011157.DAT
[2010/04/22 01:12:57 | 000,001,360 | —- | M] () – C:\2364_2504_20100422011257.DAT
[2010/04/22 01:13:58 | 000,001,360 | —- | M] () – C:\2364_2504_20100422011358.DAT
[2010/04/22 01:14:58 | 000,001,576 | —- | M] () – C:\2364_2504_20100422011458.DAT
[2010/04/22 01:15:58 | 000,001,576 | —- | M] () – C:\2364_2504_20100422011558.DAT
[2010/04/22 01:16:58 | 000,002,176 | —- | M] () – C:\2364_2504_20100422011658.DAT
[2010/04/22 01:17:58 | 000,002,976 | —- | M] () – C:\2364_2504_20100422011758.DAT
[2010/04/22 01:18:59 | 000,002,160 | —- | M] () – C:\2364_2504_20100422011859.DAT
[2010/04/22 01:19:59 | 000,001,744 | —- | M] () – C:\2364_2504_20100422011959.DAT
[2010/04/22 01:20:59 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012059.DAT
[2010/04/22 01:21:59 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012159.DAT
[2010/04/22 01:22:59 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012259.DAT
[2010/04/22 01:24:00 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012400.DAT
[2010/04/22 01:25:00 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012500.DAT
[2010/04/22 01:26:00 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012600.DAT
[2010/04/22 01:27:00 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012700.DAT
[2010/04/22 01:28:00 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012800.DAT
[2010/04/22 01:29:01 | 000,001,744 | —- | M] () – C:\2364_2504_20100422012901.DAT
[2010/04/22 01:30:01 | 000,001,736 | —- | M] () – C:\2364_2504_20100422013001.DAT
[2010/04/22 01:31:01 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013101.DAT
[2010/04/22 01:32:01 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013201.DAT
[2010/04/22 01:33:01 | 000,001,736 | —- | M] () – C:\2364_2504_20100422013301.DAT
[2010/04/22 01:34:01 | 000,001,736 | —- | M] () – C:\2364_2504_20100422013401.DAT
[2010/04/22 01:35:01 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013501.DAT
[2010/04/22 01:36:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013601.DAT
[2010/04/22 01:37:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013702.DAT
[2010/04/22 01:38:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013802.DAT
[2010/04/22 01:39:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422013902.DAT
[2010/04/22 01:40:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014002.DAT
[2010/04/22 01:41:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014102.DAT
[2010/04/22 01:42:02 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014202.DAT
[2010/04/22 01:43:03 | 000,001,736 | —- | M] () – C:\2364_2504_20100422014303.DAT
[2010/04/22 01:44:03 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014403.DAT
[2010/04/22 01:45:03 | 000,002,160 | —- | M] () – C:\2364_2504_20100422014503.DAT
[2010/04/22 01:46:03 | 000,001,960 | —- | M] () – C:\2364_2504_20100422014603.DAT
[2010/04/22 01:47:03 | 000,001,960 | —- | M] () – C:\2364_2504_20100422014703.DAT
[2010/04/22 01:48:04 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014804.DAT
[2010/04/22 01:49:04 | 000,001,744 | —- | M] () – C:\2364_2504_20100422014904.DAT
[2010/04/22 01:50:04 | 000,002,944 | —- | M] () – C:\2364_2504_20100422015004.DAT
[2010/04/22 01:51:04 | 000,003,304 | —- | M] () – C:\2364_2504_20100422015104.DAT
[2010/04/22 01:52:04 | 000,003,488 | —- | M] () – C:\2364_2504_20100422015204.DAT
[2010/04/22 01:53:04 | 000,001,744 | —- | M] () – C:\2364_2504_20100422015304.DAT
[2010/04/22 01:54:04 | 000,002,176 | —- | M] () – C:\2364_2504_20100422015404.DAT
[2010/04/22 01:55:05 | 000,001,744 | —- | M] () – C:\2364_2504_20100422015505.DAT
[2010/04/22 01:56:05 | 000,001,736 | —- | M] () – C:\2364_2504_20100422015605.DAT
[2010/04/22 01:57:05 | 000,001,952 | —- | M] () – C:\2364_2504_20100422015705.DAT
[2010/04/22 01:58:05 | 000,001,736 | —- | M] () – C:\2364_2504_20100422015805.DAT
[2010/04/22 01:59:05 | 000,002,160 | —- | M] () – C:\2364_2504_20100422015905.DAT
[2010/04/22 02:00:05 | 000,002,160 | —- | M] () – C:\2364_2504_20100422020005.DAT
[2010/04/22 02:01:06 | 000,001,960 | —- | M] () – C:\2364_2504_20100422020106.DAT
[2010/04/22 02:01:44 | 000,001,008 | —- | M] () – C:\2364_2504_20100422020144.DAT
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 15:44:36 | 003,170,304 | -H– | M] () – C:\boot.sdi
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/04/15 22:45:30 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/26 19:12:47 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2010/07/05 14:45:28 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/29 13:05:14 | 000,000,078 | —- | M] () – C:\lxdn.log
[2010/07/05 14:45:28 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/26 19:12:49 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2009/12/18 12:27:38 | 000,008,068 | -H– | M] () – C:\SetAutoFailover.cmd
[2009/09/23 08:07:44 | 000,000,123 | -H– | M] () – C:\SWSTAMP.TXT
[2009/12/09 19:32:56 | 144,838,785 | -H– | M] () – C:\winRE.wim

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/08/13 12:02:22 | 000,147,968 | —- | M] () – C:\Windows\System32\spool\prtprocs\w32x86\lxdndrpp.dll
[2006/10/26 20:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/06/28 21:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\avastSS.scr
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/21 09:59:48 | 000,000,221 | -HS- | M] () – C:\Users\Learner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/08/26 19:21:12 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Learner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 08:16:13

< End of report >




OTL Extras logfile created on: 8/26/2010 7:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Learner\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

766.00 Mb Total Physical Memory | 258.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 129.51 Gb Total Space | 91.29 Gb Free Space | 70.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 1.89 Gb Total Space | 0.37 Gb Free Space | 19.48% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WINDOWS-PJITBEU
Current User Name: Learner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15803703-25FA-4C01-A062-3F4A59937E87}" = PhotoImpact X3
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1EBEC42C-5E3F-4077-933B-411E33A0C3A4}" = Motorola Driver Installation 4.6.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10
"{5C08784B-D955-4BB4-8C70-43C89A738F58}" = Motorola Phone Tools
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75AE638F-750A-11DF-96D5-005056806466}" = Google Earth Plug-in
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARD_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARD_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARD_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B39B512-1E22-45B6-9561-83DBFEA00A33}" = BECTA Home Access Activation Tool
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}" = Motorola Phone Tools
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE562EB7-1EF6-428D-9092-13296236C2DF}" = O2 Connection Manager
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E17141A6-211D-5854-61D9-69827A430D82}" = EA Download Manager UI
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD0}" = Paint.NET v3.5.5
"{F3B899DB-B138-4698-BE99-A4271BCA47A4}" = MatchWare MindView 3.0 Home Access
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"avast5" = avast! Free Antivirus
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"DivX Setup.divx.com" = DivX Setup
"EA Download Manager" = EA Download Manager
"FotoMix" = Digital Photo Software FotoMix 7.4
"InstallShield_{15803703-25FA-4C01-A062-3F4A59937E87}" = PhotoImpact X3
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"McAfee Security Scan" = McAfee Security Scan Plus
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"STANDARD" = Microsoft Office Standard 2007
"The Sims" = The Sims
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation) PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) How many anti-virus programs are you running?
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Microsoft Security Essentials
McAfee Security Scan


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and please describe how your computer behaves at the moment.
that seems to have speeded things dramatically not had any not responding messagesa either which would have normally happened straight away
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4503 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 29/08/2010 22:02:35 mbam-log-2010-08-29 (22-02-35).txt Scan type: Quick scan Objects scanned: 168924 Time elapsed: 14 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Comps still running ok, this report is good news isnt it

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI