here are the results as you had asked
1.rku
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows 7
Version 6.1.7600
Number of processors #2
==============================================
>Drivers
==============================================
0x9162C000 C:\Windows\system32\DRIVERS\igdkmd32.sys 5230592 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x82E4C000 C:\Windows\system32\ntkrnlpa.exe 4259840 bytes (Microsoft Corporation, NT Kernel & System)
0x82E4C000 PnpManager 4259840 bytes
0x82E4C000 RAW 4259840 bytes
0x82E4C000 WMIxWDM 4259840 bytes
0x98E50000 Win32k 2400256 bytes
0x98E50000 C:\Windows\System32\win32k.sys 2400256 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8B628000 C:\Windows\System32\drivers\tcpip.sys 1347584 bytes (Microsoft Corporation, TCP/IP Driver)
0x8B218000 C:\Windows\System32\Drivers\Ntfs.sys 1241088 bytes (Microsoft Corporation, NT File System Driver)
0x90A28000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1146880 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)
0x9203B000 C:\Windows\system32\DRIVERS\VSTDPV3.SYS 1056768 bytes (Conexant Systems, Inc., HSF_DP driver)
0x91B29000 C:\Windows\System32\drivers\dxgkrnl.sys 749568 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8B403000 C:\Windows\system32\drivers\ndis.sys 749568 bytes (Microsoft Corporation, NDIS 6.20 driver)
0x9213D000 C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 741376 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0x838FD000 C:\Windows\system32\CI.dll 700416 bytes (Microsoft Corporation, Code Integrity Module)
0x9C26E000 C:\Windows\system32\drivers\peauth.sys 618496 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x9A427000 C:\Windows\system32\drivers\HTTP.sys 544768 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8382A000 C:\Windows\system32\mcupdate_GenuineIntel.dll 491520 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x83A24000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0x99428000 C:\Windows\System32\Drivers\bthport.sys 409600 bytes (Microsoft Corporation, Bluetooth Bus Driver)
0x90C23000 C:\Windows\system32\drivers\csc.sys 409600 bytes (Microsoft Corporation, Windows Client Side Caching Driver)
0x8B385000 C:\Windows\System32\Drivers\cng.sys 380928 bytes (Microsoft Corporation, Kernel Cryptography, Next Generation)
0x8FECB000 C:\Windows\system32\drivers\afd.sys 368640 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x9C205000 C:\Windows\System32\DRIVERS\srv.sys 331776 bytes (Microsoft Corporation, Server driver)
0x90F2C000 C:\Windows\system32\drivers\HdAudio.sys 327680 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x90D9E000 C:\Windows\system32\DRIVERS\yk62x86.sys 327680 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)
0x9A592000 C:\Windows\System32\DRIVERS\srv2.sys 323584 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x99100000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0x90D53000 C:\Windows\system32\DRIVERS\USBPORT.SYS 307200 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x83B65000 C:\Windows\System32\drivers\volmgrx.sys 307200 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x83AA3000 C:\Windows\system32\DRIVERS\ACPI.sys 294912 bytes (Microsoft Corporation, ACPI Driver for NT)
0x99576000 C:\Windows\system32\DRIVERS\nwifi.sys 286720 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x90E9A000 C:\Windows\system32\DRIVERS\usbhub.sys 278528 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x838BB000 C:\Windows\system32\CLFS.SYS 270336 bytes (Microsoft Corporation, Common Log File System Driver)
0x8FF8D000 C:\Windows\system32\DRIVERS\rdbss.sys 266240 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8B7AB000 C:\Windows\system32\DRIVERS\volsnap.sys 258048 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8B4BA000 C:\Windows\system32\drivers\NETIO.SYS 253952 bytes (Microsoft Corporation, Network I/O Subsystem)
0x90EEF000 C:\Windows\system32\DRIVERS\VSTAZL3.SYS 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0x9A53C000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 241664 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8FE5F000 C:\Windows\System32\Drivers\avgtdix.sys 237568 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)
0x90D1A000 C:\Windows\System32\drivers\dxgmms1.sys 233472 bytes (Microsoft Corporation, DirectX Graphics MMS)
0x82E15000 ACPI_HAL 225280 bytes
0x82E15000 C:\Windows\system32\halmacpi.dll 225280 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x90CB3000 C:\Windows\System32\Drivers\avgldx86.sys 212992 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)
0x839A8000 C:\Windows\system32\drivers\fltmgr.sys 212992 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90E58000 C:\Windows\system32\DRIVERS\ks.sys 212992 bytes (Microsoft Corporation, Kernel CSA Library)
0x8B54A000 C:\Windows\System32\DRIVERS\fvevol.sys 204800 bytes (Microsoft Corporation, BitLocker Drive Encryption Driver)
0x8FE99000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8B771000 C:\Windows\System32\drivers\fwpkclnt.sys 200704 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x92000000 C:\Windows\system32\drivers\portcls.sys 192512 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x8B51D000 C:\Windows\System32\drivers\rdyboost.sys 184320 bytes (Microsoft Corporation, ReadyBoost Driver)
0x90B4A000 C:\Windows\system32\DRIVERS\1394ohci.sys 180224 bytes (Microsoft Corporation, 1394 OpenHCI Driver)
0x8B347000 C:\Windows\System32\Drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x83AFC000 C:\Windows\system32\DRIVERS\pci.sys 172032 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x8B58D000 C:\Windows\system32\DRIVERS\CLASSPNP.SYS 151552 bytes (Microsoft Corporation, SCSI Class System Dll)
0x8B4F8000 C:\Windows\System32\Drivers\ksecpkg.sys 151552 bytes (Microsoft Corporation, Kernel Security Support Provider Interface Packages)
0x9948C000 C:\Windows\system32\DRIVERS\rfcomm.sys 147456 bytes (Microsoft Corporation, Bluetooth RFCOMM Driver)
0x90FAC000 C:\Windows\System32\Drivers\usbvideo.sys 147456 bytes (Microsoft Corporation, USB Video Class Driver)
0x83A00000 C:\Windows\system32\DRIVERS\ataport.SYS 143360 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9A519000 C:\Windows\system32\DRIVERS\mrxsmb.sys 143360 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x90C00000 C:\Windows\system32\DRIVERS\ndiswan.sys 139264 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x9A4F8000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x9A4AC000 C:\Windows\System32\DRIVERS\srvnet.sys 135168 bytes (Microsoft Corporation, Server Network driver)
0x90CE7000 C:\Windows\system32\DRIVERS\tunnel.sys 135168 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x83800000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x8B5CD000 C:\Windows\system32\DRIVERS\cdrom.sys 126976 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x91600000 C:\Windows\system32\DRIVERS\HDAudBus.sys 126976 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x8FF2C000 C:\Windows\system32\DRIVERS\pacer.sys 126976 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x990E0000 C:\Windows\System32\cdd.dll 122880 bytes (Microsoft Corporation, Canonical Display Driver)
0x994BD000 C:\Windows\system32\DRIVERS\bthpan.sys 110592 bytes (Microsoft Corporation, Bluetooth Personal Area Networking)
0x99531000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x9A577000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 110592 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x9954C000 C:\Windows\system32\drivers\WudfPf.sys 106496 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x9A4CD000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x90F7C000 C:\Windows\system32\drivers\drmk.sys 102400 bytes (Microsoft Corporation, Microsoft Trusted Audio Drivers)
0x90B76000 C:\Windows\system32\DRIVERS\sdbus.sys 102400 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0x90C87000 C:\Windows\System32\Drivers\dfsc.sys 98304 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x90B8F000 C:\Windows\system32\DRIVERS\i8042prt.sys 98304 bytes (Microsoft Corporation, i8042 Port Driver)
0x90A00000 C:\Windows\system32\DRIVERS\rasl2tp.sys 98304 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x8FE00000 C:\Windows\system32\DRIVERS\raspppoe.sys 98304 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x90E1E000 C:\Windows\system32\DRIVERS\raspptp.sys 94208 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x90E35000 C:\Windows\system32\DRIVERS\rassstp.sys 94208 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8FE3D000 C:\Windows\system32\DRIVERS\tdx.sys 94208 bytes (Microsoft Corporation, TDI Translation Driver)
0x90F95000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0x83BC5000 C:\Windows\System32\drivers\mountmgr.sys 90112 bytes (Microsoft Corporation, Mount Point Manager)
0x994F5000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 77824 bytes (Microsoft Corporation, Hid Class Library)
0x8B372000 C:\Windows\System32\Drivers\ksecdd.sys 77824 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x995CC000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8FF6A000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x90BDE000 C:\Windows\system32\DRIVERS\AgileVpn.sys 73728 bytes (Microsoft Corporation, RAS Agile Vpn Miniport Call Manager)
0x994D8000 C:\Windows\system32\DRIVERS\bthmodem.sys 73728 bytes (Microsoft Corporation, Bluetooth Communications Driver)
0x90E0A000 C:\Windows\System32\Drivers\BTHUSB.sys 73728 bytes (Microsoft Corporation, Bluetooth Miniport Driver)
0x90D08000 C:\Windows\system32\DRIVERS\intelppm.sys 73728 bytes (Microsoft Corporation, Processor Device Driver)
0x9A4E6000 C:\Windows\System32\drivers\mpsdrv.sys 73728 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8B57C000 C:\Windows\system32\DRIVERS\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x90FE8000 C:\Windows\System32\Drivers\dump_dumpfve.sys 69632 bytes
0x839DC000 C:\Windows\system32\drivers\fileinfo.sys 69632 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x90EDE000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x83B31000 C:\Windows\System32\drivers\partmgr.sys 69632 bytes (Microsoft Corporation, Partition Management Driver)
0x838A2000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x8FF4B000 C:\Windows\system32\DRIVERS\vwififlt.sys 69632 bytes (Microsoft Corporation, Virtual WiFi Filter Driver)
0x99566000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x8B600000 C:\Windows\System32\Drivers\mup.sys 65536 bytes (Microsoft Corporation, Multiple UNC Provider Driver)
0x995BC000 C:\Windows\system32\DRIVERS\ndisuio.sys 65536 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8FF7D000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Remote Desktop Server Driver)
0x83B55000 C:\Windows\system32\DRIVERS\volmgr.sys 65536 bytes (Microsoft Corporation, Volume Manager Driver)
0x91BEB000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x90C9F000 C:\Windows\system32\DRIVERS\blbdrive.sys 57344 bytes (Microsoft Corporation, BLB Drive Driver)
0x8FF5C000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8FE2F000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x83BB7000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8B3E2000 C:\Windows\System32\drivers\pcw.sys 57344 bytes (Microsoft Corporation, Performance Counters for Windows Driver)
0x90E8C000 C:\Windows\system32\DRIVERS\umbus.sys 57344 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x83A95000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0x994B0000 C:\Windows\system32\DRIVERS\BthEnum.sys 53248 bytes (Microsoft Corporation, Bluetooth Bus Extender)
0x90BD1000 C:\Windows\system32\DRIVERS\CompositeBus.sys 53248 bytes (Microsoft Corporation, Multi-Transport Composite Bus Enumerator)
0x90FD0000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x90BB4000 C:\Windows\system32\DRIVERS\kbdclass.sys 53248 bytes (Microsoft Corporation, Keyboard Class Driver)
0x921F2000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x90BA7000 C:\Windows\system32\DRIVERS\mouclass.sys 53248 bytes (Microsoft Corporation, Mouse Class Driver)
0x9C379000 C:\Windows\System32\drivers\tcpipreg.sys 53248 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x839ED000 C:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver)
0x8FFE2000 C:\Windows\System32\drivers\discache.sys 49152 bytes (Microsoft Corporation, System Indexer/Cache Driver)
0x9950F000 C:\Windows\system32\DRIVERS\kbdhid.sys 49152 bytes (Microsoft Corporation, HID Keyboard Filter Driver)
0x8B200000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x83B4A000 C:\Windows\system32\DRIVERS\BATTC.SYS 45056 bytes (Microsoft Corporation, Battery Class Driver)
0x90FDD000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x994EA000 C:\Windows\system32\DRIVERS\hidusb.sys 45056 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x99526000 C:\Windows\system32\DRIVERS\monitor.sys 45056 bytes (Microsoft Corporation, Monitor Driver)
0x9951B000 C:\Windows\system32\DRIVERS\mouhid.sys 45056 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0x8FE24000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x90A18000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8FE54000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x91BE0000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x83B26000 C:\Windows\system32\DRIVERS\vdrvroot.sys 45056 bytes (Microsoft Corporation, Virtual Drive Root Enumerator)
0x92031000 C:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x90E00000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x83BE4000 C:\Windows\system32\DRIVERS\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8FFD8000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x8FFCE000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x90E4C000 C:\Windows\system32\DRIVERS\rdpbus.sys 40960 bytes (Microsoft Corporation, Microsoft RDP Bus Device driver)
0x9C305000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x90B40000 C:\Windows\system32\DRIVERS\vwifibus.sys 40960 bytes (Microsoft Corporation, Virtual WiFi Bus Driver)
0x83BEE000 C:\Windows\system32\DRIVERS\amdxata.sys 36864 bytes (Advanced Micro Devices, Storage Filter Driver)
0x83BDB000 C:\Windows\system32\DRIVERS\atapi.sys 36864 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x8B3F0000 C:\Windows\System32\Drivers\Fs_Rec.sys 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x9C386000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x990B0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8B7A2000 C:\Windows\system32\DRIVERS\vmstorfl.sys 36864 bytes (Microsoft Corporation, Virtual Storage Filter Driver)
0x90BC8000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x83AEB000 C:\Windows\system32\DRIVERS\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x838B3000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x83B42000 C:\Windows\system32\DRIVERS\compbatt.sys 32768 bytes (Microsoft Corporation, Composite Battery Driver)
0x8B610000 C:\Windows\System32\drivers\hwpolicy.sys 32768 bytes (Microsoft Corporation, Hardware Policy Driver)
0x80BB8000 C:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Serial Kernel Debugger)
0x83AF4000 C:\Windows\system32\DRIVERS\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8B20C000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x83BF7000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Encoder Miniport)
0x83821000 C:\Windows\system32\drivers\rdprefmp.sys 32768 bytes (Microsoft Corporation, RDP Reflector Driver Miniport)
0x8B7EA000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8B5F3000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x99508000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x83BB0000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x8B5EC000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8FF25000 C:\Windows\system32\DRIVERS\wfplwf.sys 28672 bytes (Microsoft Corporation, WFP NDIS 6.20 Lightweight Filter Driver)
0x90CAD000 C:\Windows\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver)
0x90BC4000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x90BC1000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 12288 bytes (GEAR Software Inc., CD DVD Filter)
0x90E56000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x9202F000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
!!!!!!!!!!!Hidden driver: 0x8649C8C3 ?_empty_? 1853 bytes
0x8649CCA1 unknown_irp_handler 863 bytes
!!!!!!!!!!!Hidden driver: 0x866C8DE0 ?_empty_? 0 bytes
==============================================
>Stealth
==============================================
0x83BDB000 WARNING: suspicious driver modification [atapi.sys::0x8649C8C3]
0x003A0000 Hidden Image–>ANSYS.JobManager.dll [ EPROCESS 0x87C03588 ] PID: 320, 126976 bytes
0x00510000 Hidden Image–>ANSYS.ScriptEngine.dll [ EPROCESS 0x87B08030 ] PID: 900, 126976 bytes
0x008F0000 Hidden Image–>ANSYS.JobManager.Common.dll [ EPROCESS 0x87C03588 ] PID: 320, 36864 bytes
0x9C339F2E Unknown thread object [ ETHREAD 0x87D56220 ] , 600 bytes
==============================================
>Files
==============================================
==============================================
>Hooks
==============================================
[1180]svchost.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[1180]svchost.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[1180]svchost.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[1180]svchost.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77C6178C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77C617F0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77C61848–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77C617B8–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x77C61844–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>RegCreateKeyA, Type: IAT modification 0x00404014–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>advapi32.dll–>RegSetValueExA, Type: IAT modification 0x00404010–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x77B61154–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77B611E0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x77B6118C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77B611B8–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x00404030–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>CopyFileW, Type: IAT modification 0x738022B8–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>MoveFileExW, Type: IAT modification 0x73802240–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>shell32.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x7380228C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x77D11524–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77D114E0–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegCreateKeyExW, Type: IAT modification 0x77D114B4–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegOpenKeyExW, Type: IAT modification 0x77D11444–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>user32.dll–>kernel32.dll–>RegSetValueExW, Type: IAT modification 0x77D114AC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegCreateKeyExA, Type: IAT modification 0x71201284–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegCreateKeyExW, Type: IAT modification 0x712011D0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegDeleteValueA, Type: IAT modification 0x71201244–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegDeleteValueW, Type: IAT modification 0x712011D8–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegOpenKeyExA, Type: IAT modification 0x7120128C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegOpenKeyExW, Type: IAT modification 0x71201268–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegSetValueExA, Type: IAT modification 0x71201288–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>advapi32.dll–>RegSetValueExW, Type: IAT modification 0x712011DC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CopyFileA, Type: IAT modification 0x712012DC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CreateFileA, Type: IAT modification 0x712014CC–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>CreateFileW, Type: IAT modification 0x712014D0–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>DeleteFileA, Type: IAT modification 0x712014F4–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>DeleteFileW, Type: IAT modification 0x71201448–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7120144C–>00000000 [apphelp.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileA, Type: IAT modification 0x71201318–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileExA, Type: IAT modification 0x71201444–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileExW, Type: IAT modification 0x71201310–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>MoveFileW, Type: IAT modification 0x71201314–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>SetFileAttributesA, Type: IAT modification 0x7120132C–>00000000 [AcGenral.dll]
[284]GoogleUpdateBeta.exe–>wininet.dll–>kernel32.dll–>SetFileAttributesW, Type: IAT modification 0x71201400–>00000000 [AcGenral.dll]
[288]plugin-container.exe–>user32.dll–>TrackPopupMenu, Type: Inline - RelativeJump 0x75CF4B3B–>00000000 [xul.dll]
[2900]firefox.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[2900]firefox.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[2900]firefox.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7749F585–>00000000 [firefox.exe]
[2900]firefox.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[2900]firefox.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x74F32BBC–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x74F344B1–>00000000 [unknown_code_page]
[3124]explorer.exe–>mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x74F346B7–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77486448–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77485360–>00000000 [unknown_code_page]
[3124]explorer.exe–>ntdll.dll–>NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77485EE0–>00000000 [unknown_code_page]
——————————————————————————-
2.mbr
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron 1525
Logical Drives Mask: 0x000000bc
Kernel Drivers (total 170):
0x82E1D000 \SystemRoot\system32\ntkrnlpa.exe
0x8322D000 \SystemRoot\system32\halmacpi.dll
0x80BCE000 \SystemRoot\system32\kdcom.dll
0x83819000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x83891000 \SystemRoot\system32\PSHED.dll
0x838A2000 \SystemRoot\system32\BOOTVID.dll
0x838AA000 \SystemRoot\system32\CLFS.SYS
0x838EC000 \SystemRoot\system32\CI.dll
0x83A2C000 \SystemRoot\system32\drivers\Wdf01000.sys
0x83A9D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x83AAB000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x83AF3000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x83AFC000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x83B04000 \SystemRoot\system32\DRIVERS\pci.sys
0x83B2E000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x83B39000 \SystemRoot\System32\drivers\partmgr.sys
0x83B4A000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x83B52000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83B5D000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x83B6D000 \SystemRoot\System32\drivers\volmgrx.sys
0x83BB8000 \SystemRoot\system32\DRIVERS\intelide.sys
0x83BBF000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x83BCD000 \SystemRoot\System32\drivers\mountmgr.sys
0x83BE3000 \SystemRoot\system32\DRIVERS\atapi.sys
0x83A00000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x83BEC000 \SystemRoot\system32\DRIVERS\msahci.sys
0x83BF6000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x83997000 \SystemRoot\system32\drivers\fltmgr.sys
0x839CB000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B22E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B35D000 \SystemRoot\System32\Drivers\msrpc.sys
0x8B388000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B39B000 \SystemRoot\System32\Drivers\cng.sys
0x8B200000 \SystemRoot\System32\drivers\pcw.sys
0x8B20E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8B428000 \SystemRoot\system32\drivers\ndis.sys
0x8B4DF000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B51D000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8B61D000 \SystemRoot\System32\drivers\tcpip.sys
0x8B766000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B797000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8B7A0000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8B7DF000 \SystemRoot\System32\Drivers\spldr.sys
0x8B542000 \SystemRoot\System32\drivers\rdyboost.sys
0x8B7E7000 \SystemRoot\System32\Drivers\mup.sys
0x8B7F7000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8B56F000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8B600000 \SystemRoot\system32\DRIVERS\disk.sys
0x8B5A1000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8B400000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8B41F000 \SystemRoot\System32\Drivers\Null.SYS
0x8B5EE000 \SystemRoot\System32\Drivers\Beep.SYS
0x8B217000 \SystemRoot\System32\drivers\vga.sys
0x839DC000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x83800000 \SystemRoot\System32\drivers\watchdog.sys
0x8B5F5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8B223000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B3F8000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8380D000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90414000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90422000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90439000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x90444000 \SystemRoot\System32\Drivers\avgtdix.sys
0x9047E000 \SystemRoot\System32\DRIVERS\netbt.sys
0x904B0000 \SystemRoot\system32\drivers\afd.sys
0x9050A000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x90511000 \SystemRoot\system32\DRIVERS\pacer.sys
0x90530000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x90541000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9054F000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90562000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90572000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x905B3000 \SystemRoot\system32\drivers\nsiproxy.sys
0x905BD000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x905C7000 \SystemRoot\System32\drivers\discache.sys
0x90215000 \SystemRoot\system32\drivers\csc.sys
0x90279000 \SystemRoot\System32\Drivers\dfsc.sys
0x90291000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x9029F000 \SystemRoot\System32\Drivers\avgmfx86.sys
0x902A5000 \SystemRoot\System32\Drivers\avgldx86.sys
0x902D9000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x902FA000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x91625000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x91B22000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x9030C000 \SystemRoot\System32\drivers\dxgmms1.sys
0x91BD9000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x90345000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x91BE4000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x91600000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x90390000 \SystemRoot\system32\DRIVERS\yk62x86.sys
0x91200000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x91318000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x91322000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x9134E000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x91367000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x9137F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x9138C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x91399000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9139C000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x913A0000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x913A9000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x913B6000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x913C8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x913E0000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x905D3000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x903E0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x91E2C000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x91E43000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x91E5A000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x91E64000 \SystemRoot\system32\DRIVERS\swenum.sys
0x91E66000 \SystemRoot\system32\DRIVERS\ks.sys
0x91E9A000 \SystemRoot\system32\DRIVERS\umbus.sys
0x91EA8000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x91EEC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x91EFD000 \SystemRoot\system32\DRIVERS\VSTAZL3.SYS
0x91C3D000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS
0x91D3F000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS
0x91C00000 \SystemRoot\system32\drivers\modem.sys
0x91F3A000 \SystemRoot\system32\drivers\HdAudio.sys
0x91C0D000 \SystemRoot\system32\drivers\portcls.sys
0x91F8A000 \SystemRoot\system32\drivers\drmk.sys
0x91FA3000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x91DF4000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x91FBA000 \SystemRoot\System32\Drivers\usbvideo.sys
0x91FDE000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x91E00000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x8C62E000 \SystemRoot\System32\Drivers\bthport.sys
0x8C692000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x8C6B6000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0x8C6C3000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x8C6DE000 \SystemRoot\system32\DRIVERS\bthmodem.sys
0x8C6F0000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8C6FB000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8C70E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8C715000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8C721000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8C72C000 \SystemRoot\System32\Drivers\fastfat.SYS
0x8C756000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8C763000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8C76E000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x8C778000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x92A80000 \SystemRoot\System32\win32k.sys
0x8C789000 \SystemRoot\System32\drivers\Dxapi.sys
0x8C793000 \SystemRoot\system32\DRIVERS\monitor.sys
0x92CE0000 \SystemRoot\System32\TSDDD.dll
0x92D10000 \SystemRoot\System32\cdd.dll
0x8C79E000 \SystemRoot\system32\drivers\luafv.sys
0x8C7B9000 \SystemRoot\system32\drivers\WudfPf.sys
0x8C7D3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x97E26000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x97E6C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x97E7C000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x97E8F000 \SystemRoot\system32\drivers\HTTP.sys
0x97F14000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x97F35000 \SystemRoot\system32\DRIVERS\bowser.sys
0x97F4E000 \SystemRoot\System32\drivers\mpsdrv.sys
0x97F60000 \SystemRoot\system32\drivers\mrxdav.sys
0x97F81000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x97FA4000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x97FDF000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xAB239000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAB288000 \SystemRoot\System32\DRIVERS\srv.sys
0xAB2F1000 \SystemRoot\system32\drivers\peauth.sys
0xAB388000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAB200000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAB22E000 \SystemRoot\System32\Drivers\Normandy.SYS
0x77890000 \Windows\System32\ntdll.dll
0x47C70000 \Windows\System32\smss.exe
0x77AD0000 \Windows\System32\apisetschema.dll
0x00F00000 \Windows\System32\autochk.exe
Processes (total 63):
0 System Idle Process
4 System
248 C:\Windows\System32\smss.exe
344 csrss.exe
380 C:\Windows\System32\wininit.exe
392 csrss.exe
404 C:\Program Files\AVG\AVG9\avgchsvx.exe
420 C:\Program Files\AVG\AVG9\avgrsx.exe
464 C:\Windows\System32\winlogon.exe
480 C:\Windows\System32\services.exe
496 C:\Windows\System32\lsass.exe
504 C:\Windows\System32\lsm.exe
688 C:\Program Files\AVG\AVG9\avgcsrvx.exe
696 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1064 C:\Windows\System32\svchost.exe
1100 C:\Windows\System32\svchost.exe
1432 C:\Windows\System32\svchost.exe
1612 C:\Windows\System32\svchost.exe
1760 C:\Windows\System32\spoolsv.exe
1792 C:\Windows\System32\svchost.exe
1960 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\lmgrd.exe
1984 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1992 C:\Windows\System32\conhost.exe
2028 C:\Program Files\AVG\AVG9\avgwdsvc.exe
112 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\lmgrd.exe
280 C:\Program Files\Bonjour\mDNSResponder.exe
304 C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\intel\ansyslmd.exe
272 C:\Windows\System32\svchost.exe
500 C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe
1008 C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe
1364 C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe
2052 C:\Program Files\AVG\AVG9\avgnsx.exe
2124 C:\Windows\System32\svchost.exe
2556 C:\Windows\System32\svchost.exe
2884 C:\Windows\System32\taskhost.exe
2948 C:\Windows\System32\dwm.exe
3020 C:\Windows\explorer.exe
3240 C:\Program Files\iTunes\iTunesHelper.exe
3252 C:\Program Files\AVG\AVG9\avgtray.exe
3264 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3336 C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
3356 C:\Users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
3368 C:\Program Files\LimeWire\LimeWire.exe
3388 C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
3708 C:\Program Files\iPod\bin\iPodService.exe
3780 C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
3920 C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
3960 C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
4008 C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
4076 C:\Windows\System32\SearchIndexer.exe
2900 C:\Program Files\Windows Media Player\wmpnetwk.exe
3344 C:\Program Files\Mozilla Firefox\firefox.exe
3540 C:\Windows\System32\svchost.exe
4328 C:\Program Files\Mozilla Firefox\plugin-container.exe
1244 C:\Windows\System32\audiodg.exe
6052 RKUnhookerLE.EXE
2372 C:\Windows\System32\SearchProtocolHost.exe
2680 C:\Windows\System32\SearchFilterHost.exe
5020 C:\Users\betson\Downloads\MBRCheck.exe
1140 C:\Windows\System32\conhost.exe
6036 C:\Windows\System32\dllhost.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000007`d0100000 (NTFS)
\\.\E: –> \\.\PhysicalDrive0 at offset 0x00000020`f5900000 (NTFS)
PhysicalDrive0 Model Number: WDCWD2500BEVS-75UST0, Rev: 01.01A01
Size Device Name MBR Status
——————————————–
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
———————————————————————————————————————————————————————-
3.otl
OTL logfile created on: 9/5/2010 10:09:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\betson\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 31.15 Gb Total Space | 1.12 Gb Free Space | 3.59% Space Free | Partition Type: NTFS
Drive D: | 100.59 Gb Total Space | 12.15 Gb Free Space | 12.08% Space Free | Partition Type: NTFS
Drive E: | 101.05 Gb Total Space | 1.19 Gb Free Space | 1.18% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 978.58 Mb Total Space | 309.96 Mb Free Space | 31.67% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: BETSON-PC
Current User Name: betson
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\betson\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe (Google Inc)
PRC - C:\Users\betson\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Nokia)
PRC - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe (Ansys, Inc)
PRC - C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe (Ansys, Inc.)
PRC - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\ansyslmd.exe ()
PRC - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe (Macrovision Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\betson\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (GoogleUpdateBeta) – C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe (Google Inc)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (osppsvc) – C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (JobManagerService110) – C:\Program Files\ANSYS Inc\v110\RSM\bin\JobManagerService.exe (Ansys, Inc)
SRV - (ScriptHostService110) – C:\Program Files\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe (Ansys, Inc.)
SRV - (ANSYS FLEXlm license manager) – C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe (Macrovision Corporation)
========== Driver Services (SafeList) ==========
DRV - (upperdev) – C:\Windows\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (SrvHsfV92) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfWinac) – C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfHDA) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=937811"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.732
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/14 11:19:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/07/31 23:31:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/02 01:34:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox 3 Beta 5\components [2010/08/17 23:22:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3 Beta 5\plugins [2010/09/04 00:35:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/18 19:59:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/04 00:35:24 | 000,000,000 | —D | M]
[2010/05/14 20:47:42 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Extensions
[2010/05/14 20:47:42 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/05 01:27:24 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Firefox\Profiles\wgcprptx.default\extensions
[2010/08/18 20:01:09 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Mozilla\Firefox\Profiles\wgcprptx.default\extensions\[removed]
[2010/08/18 19:59:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/06/11 03:09:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - Startup: C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 03:12:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{f2c74a43-6ed0-11df-96ab-001fe2ddaedd}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/04 21:57:47 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle_files
[2010/09/04 21:57:41 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle_files
[2010/09/04 21:44:04 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs_files
[2010/09/04 02:10:14 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/03 20:42:54 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\mcse
[2010/09/03 00:23:54 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/09/03 00:23:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/09/03 00:22:10 | 000,000,000 | —D | C] – C:\Program Files\Trojan Remover
[2010/09/03 00:22:10 | 000,000,000 | —D | C] – C:\ProgramData\Simply Super Software
[2010/09/02 01:34:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PCSuite
[2010/09/02 01:34:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010/09/02 01:33:38 | 000,000,000 | —D | C] – C:\Program Files\PC Connectivity Solution
[2010/09/01 01:04:32 | 000,000,000 | —D | C] – C:\Program Files\Wise Registry Cleaner 3
[2010/09/01 00:59:27 | 000,000,000 | —D | C] – C:\Program Files\Instant Player
[2010/08/29 15:20:50 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\quizlexia
[2010/08/25 00:35:47 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/08/25 00:35:37 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Roaming\uTorrent
[2010/08/23 21:19:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/08/23 21:13:45 | 000,000,000 | —D | C] – C:\Program Files\SonicShack
[2010/08/20 18:45:09 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\proj
[2010/08/20 03:20:24 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\techtatva
[2010/08/19 23:17:49 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\TEE
[2010/08/18 19:59:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/08/15 21:54:18 | 000,000,000 | —D | C] – C:\Users\betson\.mnemosyne
[2010/08/15 21:53:54 | 000,000,000 | —D | C] – C:\Program Files\Mnemosyne
[2010/08/14 23:03:43 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Local\Apps
[2010/08/14 23:03:41 | 000,000,000 | —D | C] – C:\Users\betson\AppData\Local\Deployment
[2010/08/14 10:15:01 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/08/13 22:14:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/13 22:13:57 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/08/13 22:13:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/08/13 22:13:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/08/09 21:34:22 | 000,000,000 | —D | C] – C:\Users\betson\Desktop\New Folder
========== Files - Modified Within 30 Days ==========
[2010/09/05 10:11:22 | 003,145,728 | -HS- | M] () – C:\Users\betson\ntuser.dat
[2010/09/05 10:10:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001UA.job
[2010/09/05 09:38:58 | 064,319,035 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/09/05 09:38:09 | 000,010,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/05 09:38:09 | 000,010,016 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/05 09:33:06 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/05 09:32:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/05 09:32:35 | 2408,087,552 | -HS- | M] () – C:\hiberfil.sys
[2010/09/05 02:28:31 | 000,233,151 | —- | M] () – C:\Users\betson\Desktop\p275_chap1.pdf
[2010/09/05 00:48:57 | 000,693,124 | —- | M] () – C:\Windows\System32\perfh00C.dat
[2010/09/05 00:48:57 | 000,692,170 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2010/09/05 00:48:57 | 000,689,526 | —- | M] () – C:\Windows\System32\perfh013.dat
[2010/09/05 00:48:57 | 000,688,180 | —- | M] () – C:\Windows\System32\perfh010.dat
[2010/09/05 00:48:57 | 000,674,902 | —- | M] () – C:\Windows\System32\perfh019.dat
[2010/09/05 00:48:57 | 000,641,706 | —- | M] () – C:\Windows\System32\perfh007.dat
[2010/09/05 00:48:57 | 000,617,436 | —- | M] () – C:\Windows\System32\perfh01D.dat
[2010/09/05 00:48:57 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/05 00:48:57 | 000,461,294 | —- | M] () – C:\Windows\System32\perfh006.dat
[2010/09/05 00:48:57 | 000,448,222 | —- | M] () – C:\Windows\System32\perfh014.dat
[2010/09/05 00:48:57 | 000,433,070 | —- | M] () – C:\Windows\System32\perfh00B.dat
[2010/09/05 00:48:57 | 000,133,838 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2010/09/05 00:48:57 | 000,129,742 | —- | M] () – C:\Windows\System32\perfc013.dat
[2010/09/05 00:48:57 | 000,129,026 | —- | M] () – C:\Windows\System32\perfc019.dat
[2010/09/05 00:48:57 | 000,127,204 | —- | M] () – C:\Windows\System32\perfc00C.dat
[2010/09/05 00:48:57 | 000,126,062 | —- | M] () – C:\Windows\System32\perfc007.dat
[2010/09/05 00:48:57 | 000,124,140 | —- | M] () – C:\Windows\System32\perfc010.dat
[2010/09/05 00:48:57 | 000,120,782 | —- | M] () – C:\Windows\System32\perfc01D.dat
[2010/09/05 00:48:57 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/05 00:48:57 | 000,078,724 | —- | M] () – C:\Windows\System32\perfc00B.dat
[2010/09/05 00:48:57 | 000,076,754 | —- | M] () – C:\Windows\System32\perfc006.dat
[2010/09/05 00:48:57 | 000,074,136 | —- | M] () – C:\Windows\System32\perfc014.dat
[2010/09/05 00:48:56 | 007,770,798 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/04 23:10:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001Core.job
[2010/09/04 22:47:22 | 001,309,499 | —- | M] () – C:\Users\betson\Desktop\(PNG Image, 1280x546 pixels) - Scaled (98%).png
[2010/09/04 21:57:48 | 000,119,690 | —- | M] () – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle.html
[2010/09/04 21:57:43 | 000,113,676 | —- | M] () – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle.html
[2010/09/04 21:44:06 | 000,058,061 | —- | M] () – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs.htm
[2010/09/04 15:19:59 | 002,049,323 | -H– | M] () – C:\Users\betson\AppData\Local\IconCache.db
[2010/09/04 02:10:14 | 000,002,969 | —- | M] () – C:\Users\betson\Desktop\HiJackThis.lnk
[2010/09/04 01:51:04 | 001,832,198 | —- | M] () – C:\Users\betson\Documents\nano_erasmus_mundus.pdf
[2010/09/04 01:50:57 | 000,236,960 | —- | M] () – C:\Users\betson\Documents\Electrical.pdf
[2010/09/04 01:50:18 | 001,874,524 | —- | M] () – C:\Users\betson\Documents\UNIVERSITYOFLEUVEN.pdf
[2010/09/04 01:50:05 | 001,278,016 | —- | M] () – C:\Users\betson\Documents\studying.pdf
[2010/09/04 01:48:11 | 004,424,200 | —- | M] () – C:\Users\betson\Documents\internationalprogrammes.pdf
[2010/09/03 12:34:17 | 002,027,366 | —- | M] () – C:\Users\betson\Documents\videoplayback.mp41.mp4
[2010/09/03 12:29:14 | 005,484,067 | —- | M] () – C:\Users\betson\Documents\Eye movement controled servo made by AGH MSIB student.mp4
[2010/09/03 12:25:43 | 001,738,251 | —- | M] () – C:\Users\betson\Documents\EOG - human computer interface.mp4
[2010/09/03 01:05:10 | 194,178,381 | —- | M] () – C:\Users\betson\Desktop\Lecture 5 Pixels Relationships II.mp4
[2010/09/02 21:51:30 | 000,392,677 | —- | M] () – C:\Users\betson\Documents\NSEWQuiz2007.pdf
[2010/09/02 10:01:51 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010/08/31 20:28:44 | 000,294,248 | —- | M] () – C:\Users\betson\Documents\germany.docx
[2010/08/30 23:05:38 | 000,856,990 | —- | M] () – C:\Users\betson\Documents\sports_guide_2010-2011.pdf
[2010/08/30 22:38:17 | 000,888,057 | —- | M] () – C:\Users\betson\Documents\Masterstudyplan_SC_cours.pdf
[2010/08/30 22:32:04 | 000,965,160 | —- | M] () – C:\Users\betson\Documents\Masterstudyplan_EL.pdf
[2010/08/30 22:28:42 | 000,032,699 | —- | M] () – C:\Users\betson\Documents\en1_costofliving.pdf
[2010/08/29 02:38:44 | 212,997,495 | —- | M] () – C:\Users\betson\Desktop\Lecture 3 image digitization part-2.mp4
[2010/08/29 02:22:27 | 202,511,285 | —- | M] () – C:\Users\betson\Desktop\lecture 4_pixel relationships.mp4
[2010/08/28 18:58:51 | 000,037,809 | —- | M] () – C:\Users\betson\Documents\The PIC ,ads.docx
[2010/08/27 23:01:35 | 000,774,429 | —- | M] () – C:\Users\betson\Documents\Twenty19_smart_student_resume_guide.pdf
[2010/08/27 02:14:51 | 000,546,431 | —- | M] () – C:\Users\betson\Documents\firstonlinequizanswers-100823090543-phpapp02.pdf
[2010/08/27 02:11:25 | 001,652,343 | —- | M] () – C:\Users\betson\Documents\500wordsphrasesidiomsforthetoeflibtplustypingstrategies-100826015013-phpapp02.pdf
[2010/08/27 02:10:51 | 002,151,192 | —- | M] () – C:\Users\betson\Documents\quizzingunderthestarsaugust222010ccm2010prelaunchevent-100822011220-phpapp01.pdf
[2010/08/27 02:05:21 | 000,335,968 | —- | M] () – C:\Users\betson\Documents\bimtechprelims-quizzing-in-100319090235-phpapp02.pdf
[2010/08/27 02:02:18 | 001,071,014 | —- | M] () – C:\Users\betson\Documents\jack-kilby-science-and-technology-quiz-2009-prelims-091211230029-phpapp02.pdf
[2010/08/27 01:56:14 | 006,175,583 | —- | M] () – C:\Users\betson\Documents\generalquizwithoutanswers-100512050515-phpapp01.pdf
[2010/08/26 18:38:27 | 000,638,534 | —- | M] () – C:\Users\betson\Documents\Zulassungsbedingungen_e.pdf
[2010/08/25 07:25:20 | 000,026,432 | —- | M] () – C:\bootsqm.dat
[2010/08/25 02:05:58 | 212,664,463 | —- | M] () – C:\Users\betson\Desktop\Lecture 2 Image Digitization I.mp4
[2010/08/25 00:35:50 | 000,000,941 | —- | M] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/08/23 21:15:51 | 001,014,023 | —- | M] () – C:\Users\betson\Documents\casestudy.pdf
[2010/08/21 16:46:52 | 014,562,773 | —- | M] () – C:\Users\betson\Documents\videoplayback.mp4
[2010/08/19 22:49:05 | 000,262,025 | —- | M] () – C:\Users\betson\Desktop\TRI%20Grand%20Challenges.pdf
[2010/08/18 19:59:42 | 000,001,913 | —- | M] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/17 23:27:07 | 000,001,266 | —- | M] () – C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/14 23:26:27 | 105,074,293 | —- | M] () – C:\Users\betson\Documents\OK Go - This Too Shall Pass - Rube Goldberg Machine version - Official.mp4
[2010/08/14 22:45:10 | 029,473,902 | —- | M] () – C:\Users\betson\Documents\The Best Rube Goldberg EVER!!!!!!!!!!!!!!ever..mp4
[2010/08/14 22:35:47 | 002,844,236 | —- | M] () – C:\Users\betson\Documents\_Pythagoras Switch_ 2006_10_22.mp4
[2010/08/14 22:27:56 | 001,429,400 | —- | M] () – C:\Users\betson\Documents\Top 7 Japanese Rube Goldberg Machines #5.mp4
[2010/08/14 22:15:51 | 018,936,887 | —- | M] () – C:\Users\betson\Documents\4th Grade Science - Rube Goldberg using Simple Machines.mp4
[2010/08/14 10:15:02 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/08/14 10:15:01 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/08/14 10:15:01 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/08/14 10:14:26 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/08/13 23:48:00 | 000,696,545 | —- | M] () – C:\Users\betson\Documents\ece_news_fall08_FIMEngArt.pdf
[2010/08/13 22:47:36 | 011,920,193 | —- | M] () – C:\Users\betson\Documents\NJIT Undergraduate Research Project- Angioplasty.mp4
[2010/08/13 18:57:52 | 003,617,258 | —- | M] () – C:\Users\betson\Documents\Wireless Electricity & Wireless Communication ( dual purpose device ).mp4
[2010/08/13 18:37:04 | 000,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/08/13 17:58:20 | 005,669,694 | —- | M] () – C:\Users\betson\Documents\Renewable Energy projects.mp4
[2010/08/09 23:05:27 | 000,047,616 | —- | M] () – C:\Users\betson\Desktop\BETSON GEORGE-RESUME'.doc
========== Files Created - No Company Name ==========
[2010/09/05 02:28:31 | 000,233,151 | —- | C] () – C:\Users\betson\Desktop\p275_chap1.pdf
[2010/09/04 22:47:20 | 001,309,499 | —- | C] () – C:\Users\betson\Desktop\(PNG Image, 1280x546 pixels) - Scaled (98%).png
[2010/09/04 21:57:46 | 000,119,690 | —- | C] () – C:\Users\betson\Desktop\Buckyball-25th-anniversary-celebrated-by-interactive-Google-Doodle.html
[2010/09/04 21:57:40 | 000,113,676 | —- | C] () – C:\Users\betson\Desktop\Pac-Man-30th-anniversary-marked-by-Google-Doodle.html
[2010/09/04 21:44:04 | 000,058,061 | —- | C] () – C:\Users\betson\Desktop\hp.memristor_1_flash-memory-computer-memory-hp-labs.htm
[2010/09/04 02:10:14 | 000,002,969 | —- | C] () – C:\Users\betson\Desktop\HiJackThis.lnk
[2010/09/04 01:51:04 | 001,832,198 | —- | C] () – C:\Users\betson\Documents\nano_erasmus_mundus.pdf
[2010/09/04 01:50:57 | 000,236,960 | —- | C] () – C:\Users\betson\Documents\Electrical.pdf
[2010/09/04 01:50:18 | 001,874,524 | —- | C] () – C:\Users\betson\Documents\UNIVERSITYOFLEUVEN.pdf
[2010/09/04 01:50:05 | 001,278,016 | —- | C] () – C:\Users\betson\Documents\studying.pdf
[2010/09/04 01:48:11 | 004,424,200 | —- | C] () – C:\Users\betson\Documents\internationalprogrammes.pdf
[2010/09/03 12:34:17 | 002,027,366 | —- | C] () – C:\Users\betson\Documents\videoplayback.mp41.mp4
[2010/09/03 12:29:14 | 005,484,067 | —- | C] () – C:\Users\betson\Documents\Eye movement controled servo made by AGH MSIB student.mp4
[2010/09/03 12:25:42 | 001,738,251 | —- | C] () – C:\Users\betson\Documents\EOG - human computer interface.mp4
[2010/09/03 01:05:09 | 194,178,381 | —- | C] () – C:\Users\betson\Desktop\Lecture 5 Pixels Relationships II.mp4
[2010/09/02 21:51:30 | 000,392,677 | —- | C] () – C:\Users\betson\Documents\NSEWQuiz2007.pdf
[2010/09/02 10:01:51 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010/08/31 20:28:43 | 000,294,248 | —- | C] () – C:\Users\betson\Documents\germany.docx
[2010/08/30 23:05:38 | 000,856,990 | —- | C] () – C:\Users\betson\Documents\sports_guide_2010-2011.pdf
[2010/08/30 22:38:17 | 000,888,057 | —- | C] () – C:\Users\betson\Documents\Masterstudyplan_SC_cours.pdf
[2010/08/30 22:32:04 | 000,965,160 | —- | C] () – C:\Users\betson\Documents\Masterstudyplan_EL.pdf
[2010/08/30 22:28:42 | 000,032,699 | —- | C] () – C:\Users\betson\Documents\en1_costofliving.pdf
[2010/08/29 02:38:44 | 212,997,495 | —- | C] () – C:\Users\betson\Desktop\Lecture 3 image digitization part-2.mp4
[2010/08/29 02:22:26 | 202,511,285 | —- | C] () – C:\Users\betson\Desktop\lecture 4_pixel relationships.mp4
[2010/08/28 18:58:50 | 000,037,809 | —- | C] () – C:\Users\betson\Documents\The PIC ,ads.docx
[2010/08/27 23:01:35 | 000,774,429 | —- | C] () – C:\Users\betson\Documents\Twenty19_smart_student_resume_guide.pdf
[2010/08/27 02:14:51 | 000,546,431 | —- | C] () – C:\Users\betson\Documents\firstonlinequizanswers-100823090543-phpapp02.pdf
[2010/08/27 02:11:25 | 001,652,343 | —- | C] () – C:\Users\betson\Documents\500wordsphrasesidiomsforthetoeflibtplustypingstrategies-100826015013-phpapp02.pdf
[2010/08/27 02:10:51 | 002,151,192 | —- | C] () – C:\Users\betson\Documents\quizzingunderthestarsaugust222010ccm2010prelaunchevent-100822011220-phpapp01.pdf
[2010/08/27 02:05:21 | 000,335,968 | —- | C] () – C:\Users\betson\Documents\bimtechprelims-quizzing-in-100319090235-phpapp02.pdf
[2010/08/27 02:02:18 | 001,071,014 | —- | C] () – C:\Users\betson\Documents\jack-kilby-science-and-technology-quiz-2009-prelims-091211230029-phpapp02.pdf
[2010/08/27 01:56:13 | 006,175,583 | —- | C] () – C:\Users\betson\Documents\generalquizwithoutanswers-100512050515-phpapp01.pdf
[2010/08/26 18:38:27 | 000,638,534 | —- | C] () – C:\Users\betson\Documents\Zulassungsbedingungen_e.pdf
[2010/08/25 07:25:20 | 000,026,432 | —- | C] () – C:\bootsqm.dat
[2010/08/25 02:05:57 | 212,664,463 | —- | C] () – C:\Users\betson\Desktop\Lecture 2 Image Digitization I.mp4
[2010/08/25 00:35:50 | 000,000,941 | —- | C] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/08/23 21:15:51 | 001,014,023 | —- | C] () – C:\Users\betson\Documents\casestudy.pdf
[2010/08/21 16:46:52 | 014,562,773 | —- | C] () – C:\Users\betson\Documents\videoplayback.mp4
[2010/08/19 22:49:05 | 000,262,025 | —- | C] () – C:\Users\betson\Desktop\TRI%20Grand%20Challenges.pdf
[2010/08/18 19:59:42 | 000,001,913 | —- | C] () – C:\Users\betson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/17 23:27:07 | 000,001,266 | —- | C] () – C:\Users\betson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/14 23:26:25 | 105,074,293 | —- | C] () – C:\Users\betson\Documents\OK Go - This Too Shall Pass - Rube Goldberg Machine version - Official.mp4
[2010/08/14 23:05:09 | 000,000,912 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001UA.job
[2010/08/14 23:05:07 | 000,000,860 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1784918198-3613492867-1043733186-1001Core.job
[2010/08/14 22:45:09 | 029,473,902 | —- | C] () – C:\Users\betson\Documents\The Best Rube Goldberg EVER!!!!!!!!!!!!!!ever..mp4
[2010/08/14 22:35:47 | 002,844,236 | —- | C] () – C:\Users\betson\Documents\_Pythagoras Switch_ 2006_10_22.mp4
[2010/08/14 22:27:56 | 001,429,400 | —- | C] () – C:\Users\betson\Documents\Top 7 Japanese Rube Goldberg Machines #5.mp4
[2010/08/14 22:15:51 | 018,936,887 | —- | C] () – C:\Users\betson\Documents\4th Grade Science - Rube Goldberg using Simple Machines.mp4
[2010/08/13 23:48:00 | 000,696,545 | —- | C] () – C:\Users\betson\Documents\ece_news_fall08_FIMEngArt.pdf
[2010/08/13 22:47:36 | 011,920,193 | —- | C] () – C:\Users\betson\Documents\NJIT Undergraduate Research Project- Angioplasty.mp4
[2010/08/13 18:57:52 | 003,617,258 | —- | C] () – C:\Users\betson\Documents\Wireless Electricity & Wireless Communication ( dual purpose device ).mp4
[2010/08/13 17:58:20 | 005,669,694 | —- | C] () – C:\Users\betson\Documents\Renewable Energy projects.mp4
[2010/08/10 09:50:12 | 000,047,616 | —- | C] () – C:\Users\betson\Desktop\BETSON GEORGE-RESUME'.doc
[2009/12/07 10:16:00 | 000,007,358 | —- | C] () – C:\Program Files\logo_48x48.ico
[2009/07/14 05:21:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 05:12:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
========== LOP Check ==========
[2010/05/04 21:08:53 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Ansys
[2010/09/05 09:36:01 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\LimeWire
[2010/07/26 23:30:11 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\Nokia
[2010/06/19 12:38:45 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\PC Suite
[2010/08/25 07:18:31 | 000,000,000 | —D | M] – C:\Users\betson\AppData\Roaming\uTorrent
[2010/09/02 10:00:47 | 000,032,548 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 03:12:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/08/25 07:25:20 | 000,026,432 | —- | M] () – C:\bootsqm.dat
[2009/06/11 03:12:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/05 09:32:35 | 2408,087,552 | -HS- | M] () – C:\hiberfil.sys
[2010/06/17 17:12:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/17 17:12:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/05 09:32:35 | 3210,784,768 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 10:22:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 10:22:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 10:22:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 10:22:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 03:01:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 06:45:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 06:46:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 10:11:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2009/12/07 10:16:00 | 000,007,358 | —- | M] () – C:\Program Files\logo_48x48.ico
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/25 17:10:11 | 000,000,221 | -HS- | M] () – C:\Users\betson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/11 02:50:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/04/25 16:06:56 | 000,000,402 | -HS- | M] () – C:\Users\betson\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %USERPROFILE%\Templates\*.* >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 9/5/2010 10:09:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\betson\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 31.15 Gb Total Space | 1.12 Gb Free Space | 3.59% Space Free | Partition Type: NTFS
Drive D: | 100.59 Gb Total Space | 12.15 Gb Free Space | 12.08% Space Free | Partition Type: NTFS
Drive E: | 101.05 Gb Total Space | 1.19 Gb Free Space | 1.18% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 978.58 Mb Total Space | 309.96 Mb Free Space | 31.67% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: BETSON-PC
Current User Name: betson
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{127F1FD7-43BB-4428-8B2A-70539F4B6F1F}" = ANSYS Products 11.0 SP1
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.6
"{1B611B02-BCB6-4D2C-AD7C-F7370B272853}" = ANSYS Remote Solve Manager (RSM) 11.0
"{1B9B5B3B-28E7-4E59-A80D-D670AA984514}" = Nokia Connectivity Cable Driver
"{20140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 (Beta)
"{20140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 (Beta)
"{20140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 (Beta)
"{20140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 (Beta)
"{20140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 (Beta)
"{20140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 (Beta)
"{20140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 (Beta)
"{20140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 (Beta)
"{20140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 (Beta)
"{20140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 (Beta)
"{20140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 (Beta)
"{20140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 (Beta)
"{20140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 (Beta)
"{20140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 (Beta)
"{20140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 (Beta)
"{20140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 (Beta)
"{20140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 (Beta)
"{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 21
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}" = Apple Mobile Device Support
"{EA418519-2160-43A0-AABD-6608DDD8D87F}" = iTunes
"34EA302E7F4CBD17A19E33BBCB72363234956D7E" = Windows Driver Package - Nokia Modem (06/09/2010 4.5)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner (remove only)
"EEEE705096F837B7907659F100C9FE6DA001970F" = Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.7)
"LimeWire" = LimeWire PRO 5.3.6
"Mnemosyne_is1" = Mnemosyne 1.2.2
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nokia PC Suite" = Nokia PC Suite
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"SonicShack Design Studio_is1" = SonicShack Designer Adobe AIR version
"VLC media player" = VideoLAN VLC media player 0.8.6h
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/4/2010 4:27:57 AM | Computer Name = betson-PC | Source = VSS | ID = 8193
Description =
Error - 9/4/2010 5:00:40 AM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 11:41:43 AM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 12:13:29 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 1:14:25 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 2:14:32 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 3:03:33 PM | Computer Name = betson-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 1.9.2.3855, time
stamp: 0x4c48d5ce Faulting module name: js3250.dll, version: 0.0.0.0, time stamp:
0x4c48cd1a Exception code: 0xc0000005 Fault offset: 0x000518c9 Faulting process id:
0x1688 Faulting application start time: 0x01cb4c47f9acf4d6 Faulting application path:
C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla
Firefox\js3250.dll Report Id: 1c840753-b857-11df-8cbf-001fe2ddaedd
Error - 9/4/2010 3:12:32 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 4:04:04 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 9/4/2010 5:00:56 PM | Computer Name = betson-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
[ Media Center Events ]
Error - 7/21/2010 12:53:43 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 10:23:42 PM - Error connecting to the internet. 10:23:42 PM - Unable
to contact server..
Error - 7/23/2010 12:56:23 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 10:26:23 PM - Error connecting to the internet. 10:26:23 PM - Unable
to contact server..
Error - 7/26/2010 1:40:38 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:10:38 PM - Error connecting to the internet. 11:10:38 PM - Unable
to contact server..
Error - 7/28/2010 10:08:10 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 7:38:10 AM - Error connecting to the internet. 7:38:10 AM - Unable
to contact server..
Error - 7/30/2010 5:35:44 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 3:05:44 PM - Error connecting to the internet. 3:05:44 PM - Unable
to contact server..
Error - 8/1/2010 1:39:47 PM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:09:47 PM - Error connecting to the internet. 11:09:47 PM - Unable
to contact server..
Error - 8/3/2010 1:33:42 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 11:03:42 AM - Error connecting to the internet. 11:03:42 AM - Unable
to contact server..
Error - 8/7/2010 3:43:57 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 1:13:57 PM - Error connecting to the internet. 1:13:57 PM - Unable
to contact server..
Error - 8/9/2010 9:40:26 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 7:10:26 PM - Error connecting to the internet. 7:10:26 PM - Unable
to contact server..
Error - 8/11/2010 8:51:38 AM | Computer Name = betson-PC | Source = MCUpdate | ID = 0
Description = 6:21:37 PM - Error connecting to the internet. 6:21:38 PM - Unable
to contact server..
[ System Events ]
Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:09:19 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:14:37 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:14:45 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:28:45 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 4:28:46 AM | Computer Name = betson-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume \Device\HarddiskVolume2.
Error - 9/4/2010 11:36:36 AM | Computer Name = betson-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Audio service failed to start due to the following error:
%%776
Error - 9/4/2010 11:40:17 AM | Computer Name = betson-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 9/4/2010 3:15:52 PM | Computer Name = betson-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \…\DR2.
< End of report >