This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

File causing Windows exporer.exe to refresh!

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok so when i was writing files from dvds to my external hard drive. Ive noticed that my external drive would suddenly refresh windows explorer.exe. When i was in a certain folder renaming some of my media files. I found out the root of the problem and its a single media mp4 file that is causing the issue, because when i click on it, instantly it refreshed. I tried rebooting like 4 times. Then clicking on that exact same file in my external hard drive and it happens every single time. So then i carefully and quickly tried to drag and drop the media file to my desktop so it was in my root C drive. Now every 4 seconds approx, windows explorer.exe is refreshing. Every time i reboot with out even going to my external hard drive. So evidently the file that cased the issue, some how launched something on my C drive that is now causing my windows explorer to be non responsive continuously. I have tried a number of things, i have tried rebooting to safe mode and then deleting the file, still does the same thing. I have tried repair recovery console, still no good. The only thing that seemed to work was "last known good configuration". Which apparently stopped the windows explorer.exe from refreshing but the file i can't seem to delete off of my external or my desktop. It is just like automatically stuck on there and when i try to play, it plays bout the first 3 seconds and then stops. Any ideas on how to permanently delete this file as i think this is what is causing my issue with windows.
Ok it started doing it again so this time i went back to ""last known good configuration" but this time how ever it didn't seem to solve the problem with the refreshes. The only thing i tried this time was using windows recovery console. I simply restored the computer to an earlier time now its not causing issues with the windows explorer.exe any more. How ever the file still remains to be located both on my external hard drive and on my C: desktop. I am not going to try and mess with the files right now as that could trigger the non responsive explorer.exe issue again so im going to leave it alone untill i get a reply back from you. I need these files completely erased from my pc. I also hope this didn't launch some kind of maleware agent on my computer.
Hi jeff matthews,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I can't tell a thing without a log.. so let's get one.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Just a note before i post these logs. The program seemed to not respond twice as i was scanning, is that normal? But it did seem to complete sucussfully with out to much trouble.

Also the "file" that is causing this problem. I know the exact name of it and im not sure if that would help but ill give the file name. Its a media file called "FFVII_dirge_ of_cerberus_CG_Movies" It is a mp4 video file. I am almost certain that is what is causing this issue because like i said before this problem only arised when ever i opened my external hard drive. Now its consistently happening the moment i copied that file from my external drive directly into my C drive.

Any ways here is the logs.



OTL logfile created on: 1/12/2011 11:44:24 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\Jeff\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 17.92 Gb Free Space | 12.02% Space Free | Partition Type: NTFS
Drive D: | 39.07 Gb Total Space | 30.11 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
Drive E: | 35.46 Gb Total Space | 5.55 Gb Free Space | 15.65% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 330.41 Gb Free Space | 35.47% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 163.52 Gb Free Space | 8.78% Space Free | Partition Type: NTFS
Drive J: | 1.64 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 17.59 Mb Total Space | 17.32 Mb Free Space | 98.44% Space Free | Partition Type: FAT
Drive O: | 1016.16 Mb Total Space | 943.03 Mb Free Space | 92.80% Space Free | Partition Type: NTFS
Drive P: | 148.05 Gb Total Space | 61.45 Gb Free Space | 41.51% Space Free | Partition Type: NTFS
Drive Q: | 1863.01 Gb Total Space | 516.79 Gb Free Space | 27.74% Space Free | Partition Type: NTFS

Computer Name: JEFF-PC | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jeff\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Codebox\BitMeter\BitMeter2.exe ( )
PRC - C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Jeff\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper.dll File not found
SRV - (TVersityMediaServer) – C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (CrossLoopService) – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (uvnc_service) – C:\Users\Jeff\AppData\Local\CrossLoop\winvnc.exe (UltraVNC)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PS3 Media Server) – C:\Program Files\PS3 Media Server\win32\service\wrapper.exe ()
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (nlsX86cc) – C:\Windows\System32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys File not found
DRV - (catchme) – C:\Users\Jeff\AppData\Local\Temp\catchme.sys File not found
DRV - (ALSysIO) – C:\Users\Jeff\AppData\Local\Temp\ALSysIO.sys File not found
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (cpuz133) – C:\Windows\System32\drivers\cpuz133_x32.sys (Windows ® Win 7 DDK provider)
DRV - (ivusb) – C:\Windows\System32\drivers\ivusb.sys (Initio Corporation)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (mv61xx) – C:\Windows\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (cpuz132) – C:\Windows\System32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (RivaTuner32) – C:\Program Files\RivaTuner v2.24\RivaTuner32.sys ()
DRV - (ASPI32) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC 0C AE 38 72 92 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/14 13:53:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/28 20:11:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/28 20:11:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/12 11:16:21 | 000,000,000 | —D | M]

[2010/07/10 01:29:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions
[2011/01/12 11:37:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions
[2010/09/16 21:57:42 | 000,000,000 | —D | M] (WOT) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/12/24 15:37:32 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/11/10 09:36:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/10 22:38:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/05 12:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/10 09:36:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/12 11:16:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/12/28 20:11:19 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/04 15:21:18 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cdloader] C:\Users\Jeff\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [CrossLoop] C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009/06/10 13:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/07/02 13:32:34 | 000,000,000 | R–D | M] - H:\autorun – [ NTFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,027,992 | R— | M] (magicJack L.P.) - J:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,016,158 | R— | M] () - J:\autorun.ico – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,000,308 | R— | M] () - J:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,728,816 | R— | M] (magicJack L.P.) - J:\autorunu.exe – [ CDFS ]
O32 - AutoRun File - [2009/08/01 16:17:00 | 000,000,270 | —- | M] () - K:\autorun.inf – [ FAT ]
O32 - AutoRun File - [2010/07/02 13:30:52 | 000,000,000 | R–D | M] - Q:\autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)


========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 11:43:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2011/01/08 17:35:20 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\DVDFab
[2011/01/07 13:09:06 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
[2011/01/07 13:06:59 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Deployment
[2011/01/06 15:36:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
[2011/01/06 11:15:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
[2011/01/06 11:15:37 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\mIRC
[2011/01/06 11:15:36 | 000,000,000 | —D | C] – C:\Program Files\mIRC
[2011/01/06 11:12:03 | 002,079,752 | —- | C] (mIRC Co. Ltd.) – C:\Users\Jeff\Desktop\mirc717.exe
[2011/01/06 11:04:55 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\AddOns
[2011/01/06 11:04:14 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\WTF
[2011/01/06 11:04:03 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\WTF.20100824-182143
[2011/01/06 11:02:50 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\Screenshots
[2010/12/31 18:18:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDneXtCOPY 4
[2010/12/31 18:18:21 | 000,000,000 | —D | C] – C:\Program Files\DVDneXtCOPY 4
[2010/12/31 17:34:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Machinist 2
[2010/12/31 17:34:30 | 000,000,000 | —D | C] – C:\Program Files\Machinist 2
[2010/12/31 17:30:51 | 000,000,000 | —D | C] – C:\ProgramData\DVDneXtCOPY
[2010/12/31 17:30:51 | 000,000,000 | —D | C] – C:\DVDneXtCOPY
[2010/12/31 17:28:29 | 014,783,188 | —- | C] (DVDneXtCOPY Inc.) – C:\Users\Jeff\Documents\dvdnextcopy_next_tech_setup.exe
[2010/12/31 17:18:57 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\My DVD Backups
[2010/12/31 17:18:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitRipper
[2010/12/31 17:18:45 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\bitRipper
[2010/12/31 17:18:45 | 000,000,000 | —D | C] – C:\Program Files\bitRipper
[2010/12/29 03:07:09 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\DVDFab
[2010/12/28 20:12:05 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Real
[2010/12/28 20:11:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2010/12/28 20:11:02 | 000,199,904 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2010/12/28 20:10:50 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2010/12/28 20:10:50 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2010/12/28 20:10:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2010/12/28 19:56:33 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\NVIDIA
[2010/12/28 19:56:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8
[2010/12/28 19:56:21 | 000,000,000 | —D | C] – C:\Program Files\DVDFab 8
[2010/12/28 19:48:40 | 014,917,520 | —- | C] (Fengtao Software Inc. ) – C:\Users\Jeff\Documents\DVDFab8065_avangate-675.exe
[2010/12/26 15:07:53 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\CyberLink
[2010/12/26 15:07:38 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\CyberLink
[2010/12/26 15:06:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2010/12/26 15:05:54 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2010/12/26 15:05:45 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2010/12/26 13:31:06 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVD Decrypter
[2010/12/26 13:31:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Decrypter
[2010/12/26 13:31:05 | 000,000,000 | —D | C] – C:\Program Files\DVD Decrypter
[2010/12/25 15:33:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
[2010/12/25 15:33:00 | 000,000,000 | —D | C] – C:\Program Files\DVD Shrink
[2010/12/24 14:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy DVD Shrink
[2010/12/24 14:28:33 | 000,000,000 | —D | C] – C:\Easy_DVD_Shrink 3.0.19
[2010/12/24 14:25:59 | 000,045,056 | —- | C] (Adaptec) – C:\Windows\System32\WNASPI32.DLL
[2010/12/24 14:25:59 | 000,025,244 | —- | C] (Adaptec) – C:\Windows\System32\drivers\ASPI32.SYS
[2010/12/24 14:25:59 | 000,005,600 | —- | C] (Adaptec) – C:\Windows\System\WINASPI.DLL
[2010/12/24 14:25:59 | 000,004,672 | —- | C] (Adaptec) – C:\Windows\System\WOWPOST.EXE
[2010/12/24 14:25:49 | 000,000,000 | —D | C] – C:\Program Files\EasyDVDShrink
[2010/12/16 16:09:33 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\vlc
[2010/12/16 16:09:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2010/12/15 03:53:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/15 03:53:17 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 03:53:15 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 03:53:15 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 03:53:15 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 03:53:15 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 03:53:15 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 03:53:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/15 03:53:15 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/15 03:53:15 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 03:53:15 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/15 03:53:15 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/15 03:53:05 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 03:53:05 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 03:53:05 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 03:53:05 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
[2010/12/15 03:52:59 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 03:52:59 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 03:52:57 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2010/12/15 03:52:56 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 03:51:26 | 002,327,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/07/14 11:42:07 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Jeff\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/01/12 11:43:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2011/01/12 11:29:07 | 000,023,200 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/12 11:29:07 | 000,023,200 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/12 11:18:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/01/12 11:17:37 | 2006,278,144 | -HS- | M] () – C:\hiberfil.sys
[2011/01/08 00:26:50 | 000,000,636 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/01/07 13:09:06 | 000,000,312 | —- | M] () – C:\Users\Jeff\Desktop\Curse Client.appref-ms
[2011/01/06 11:38:56 | 000,000,987 | —- | M] () – C:\Users\Jeff\Desktop\magicJack.lnk
[2011/01/06 11:15:38 | 000,000,909 | —- | M] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/01/06 11:12:22 | 002,079,752 | —- | M] (mIRC Co. Ltd.) – C:\Users\Jeff\Desktop\mirc717.exe
[2011/01/05 02:12:50 | 001,573,304 | —- | M] () – C:\Users\Jeff\Desktop\High PCSX2 shot.jpg
[2011/01/05 02:06:53 | 000,049,016 | —- | M] () – C:\Users\Jeff\Desktop\Low Res.jpg
[2011/01/04 05:30:56 | 000,067,272 | —- | M] () – C:\Users\Jeff\Documents\2F858BD6E084D53FEAE36FCC8DA5F35D18FC3D9E.torrent
[2011/01/01 17:34:57 | 000,196,351 | —- | M] () – C:\Users\Jeff\Documents\newyear09.jpg
[2011/01/01 16:59:28 | 000,352,031 | —- | M] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive (2).zip
[2011/01/01 16:59:21 | 000,378,538 | —- | M] () – C:\Users\Jeff\Documents\2011 Newsletter.odt
[2011/01/01 16:47:45 | 000,009,716 | —- | M] () – C:\Users\Jeff\Documents\longribbon.gif
[2011/01/01 16:47:38 | 000,012,332 | —- | M] () – C:\Users\Jeff\Documents\ribbonbar.gif
[2011/01/01 16:47:26 | 000,017,869 | —- | M] () – C:\Users\Jeff\Documents\ribbon.gif
[2011/01/01 16:37:18 | 000,069,927 | —- | M] () – C:\Users\Jeff\Documents\Happy-New-Year-Fireworks-1-800x600.jpg
[2011/01/01 16:36:33 | 000,164,757 | —- | M] () – C:\Users\Jeff\Documents\sydney-fireworks.jpg
[2011/01/01 16:36:09 | 000,242,158 | —- | M] () – C:\Users\Jeff\Documents\firecracker.jpg.bmp
[2011/01/01 16:35:56 | 000,065,909 | —- | M] () – C:\Users\Jeff\Documents\fireworks.jpg
[2011/01/01 16:35:44 | 002,294,114 | —- | M] () – C:\Users\Jeff\Documents\(Holiday - New Year) - Wallpapers4Desktop.com 001.jpg
[2011/01/01 16:33:41 | 000,014,084 | —- | M] () – C:\Users\Jeff\Documents\images2u.jpg
[2011/01/01 16:32:53 | 000,050,415 | —- | M] () – C:\Users\Jeff\Documents\Happy_New_Year_2011_Wallpapers7.jpg
[2011/01/01 16:31:48 | 000,167,713 | —- | M] () – C:\Users\Jeff\Documents\happy-new-year-2011-iphone.jpg
[2011/01/01 15:55:15 | 000,107,725 | —- | M] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive.zip
[2011/01/01 15:51:03 | 000,112,488 | —- | M] () – C:\Users\Jeff\Documents\mexican theme birthday celebration.odt
[2011/01/01 15:41:27 | 000,029,265 | —- | M] () – C:\Users\Jeff\Documents\PBANN-00138.jpg
[2011/01/01 15:41:07 | 000,018,541 | —- | M] () – C:\Users\Jeff\Documents\happy-18th-banner-qa258.jpg
[2011/01/01 15:14:29 | 000,019,545 | —- | M] () – C:\Users\Jeff\Documents\18-today-its-party-time-banner-qa104.jpg
[2011/01/01 15:13:02 | 000,043,328 | —- | M] () – C:\Users\Jeff\Documents\Party.Pug.JPEG
[2011/01/01 15:12:05 | 000,017,118 | —- | M] () – C:\Users\Jeff\Documents\mexican0.jpg
[2011/01/01 15:10:18 | 000,068,826 | —- | M] () – C:\Users\Jeff\Documents\MexicanFiestaSupplies-MAIN.jpg
[2010/12/31 18:18:24 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\DVDneXtCOPY 4.lnk
[2010/12/31 18:07:18 | 000,005,276 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_v4_0_2_8_Crack_Latest__RH.torrent
[2010/12/31 18:07:01 | 000,005,471 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_Edition_v4_2_6_3___Patch__TrT_TcT_.torrent
[2010/12/31 17:54:09 | 000,000,664 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_4_2_5_2____KeyGen___rar.torrent
[2010/12/31 17:30:28 | 014,783,188 | —- | M] (DVDneXtCOPY Inc.) – C:\Users\Jeff\Documents\dvdnextcopy_next_tech_setup.exe
[2010/12/31 17:18:10 | 001,178,319 | —- | M] () – C:\Users\Jeff\Documents\bitRipperSetup.exe
[2010/12/30 20:59:13 | 000,001,685 | —- | M] () – C:\Users\Jeff\Documents\msg0002.WAV
[2010/12/29 21:08:20 | 000,001,041 | —- | M] () – C:\Users\Jeff\AppData\Roaming\vso_ts_preview.xml
[2010/12/28 20:11:31 | 000,001,012 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2010/12/28 20:11:02 | 000,199,904 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2010/12/28 20:10:50 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2010/12/28 20:10:50 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2010/12/28 19:56:30 | 000,000,977 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2010/12/28 19:56:30 | 000,000,953 | —- | M] () – C:\Users\Jeff\Desktop\DVDFab 8.lnk
[2010/12/28 19:55:25 | 014,917,520 | —- | M] (Fengtao Software Inc. ) – C:\Users\Jeff\Documents\DVDFab8065_avangate-675.exe
[2010/12/26 17:09:29 | 000,091,136 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_6_Complete_S06_S06E01_S06E17_S06E00_ADreaNaL.torrent
[2010/12/26 17:05:12 | 000,028,265 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E07_VOSTFR_HDTV_XViD_avi.torrent
[2010/12/26 17:04:39 | 000,014,560 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E06_ITA_HDTVMux_NovaRip__CR_Bt_.torrent
[2010/12/26 17:03:59 | 000,015,619 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E05_This_Place_Is_Death_PROPER_HDTV_XviD_FQM__rarbg_.torrent
[2010/12/26 17:03:34 | 000,014,717 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E05_HDTV_XviD___XOR.torrent
[2010/12/26 17:02:18 | 000,028,475 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E16_E17_The_Incident_HDTV_XviD_FQM.torrent
[2010/12/26 17:02:01 | 000,014,479 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E15_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:45 | 000,006,815 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E14_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:18 | 000,014,533 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E13_HDTV_XviD_NoTV_eztv.torrent
[2010/12/26 17:01:01 | 000,015,046 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E12_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 17:00:47 | 000,014,552 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E11_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:33 | 000,014,552 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E10_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:08 | 000,014,760 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E09_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 16:59:53 | 000,014,670 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E08_HDTV_XviD_XOR.torrent
[2010/12/26 16:57:22 | 000,027,658 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E04_VOSTFR_XviD_avi.torrent
[2010/12/26 16:56:45 | 000,015,262 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E03_HDTV_XviD_XOR__rarbg_com_.torrent
[2010/12/26 16:56:28 | 000,015,896 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E02_The_Lie_HDTV_XviD_2HD_avi.torrent
[2010/12/26 16:54:09 | 000,016,545 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_5__Episodes_1_7_.torrent
[2010/12/26 16:53:04 | 000,015,556 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E01_HDTV_XviD_PusherCrew_avi.torrent
[2010/12/26 16:30:50 | 000,030,080 | —- | M] () – C:\Users\Jeff\Documents\Lost_S04E02__HDTV_XviD_ENG___SUB_ENG_ITA_.torrent
[2010/12/26 16:29:39 | 000,028,370 | —- | M] () – C:\Users\Jeff\Documents\Lost_S04E01_HDTV_XviD_XOR__eztv_.torrent
[2010/12/26 16:28:50 | 000,025,984 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_4_S04E01to_S04E13_14_complete.torrent
[2010/12/26 15:38:27 | 000,000,000 | —- | M] () – C:\Users\Jeff\Documents\PDVD_MediaDisc.PlayList
[2010/12/26 15:06:04 | 000,001,989 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2010/12/26 13:31:06 | 000,001,942 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk
[2010/12/26 13:31:06 | 000,001,918 | —- | M] () – C:\Users\Jeff\Desktop\DVD Decrypter.lnk
[2010/12/26 13:30:40 | 000,899,414 | —- | M] () – C:\Users\Jeff\Documents\SetupDVDDecrypter_3.5.4.0.exe
[2010/12/26 05:32:30 | 000,014,992 | —- | M] () – C:\Users\Jeff\Documents\[Vegapunk]_One_Piece_321_330_HD.torrent
[2010/12/25 15:33:01 | 000,000,953 | —- | M] () – C:\Users\Jeff\Desktop\DVD Shrink 3.2.lnk
[2010/12/25 14:43:34 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/25 14:43:34 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/25 14:43:17 | 001,094,021 | —- | M] () – C:\Users\Jeff\Documents\dvdshrink32setup1.zip
[2010/12/24 17:04:52 | 001,528,276 | —- | M] () – C:\Users\Jeff\Documents\haruhi_christmas.jpg
[2010/12/24 17:01:19 | 000,074,865 | —- | M] () – C:\Users\Jeff\Documents\TAC_MerryChristmas2007.jpg
[2010/12/24 16:59:58 | 000,018,345 | —- | M] () – C:\Users\Jeff\Documents\images4.jpg
[2010/12/24 16:48:30 | 000,097,591 | —- | M] () – C:\Users\Jeff\Documents\okami-the-movie-20070112041935217.jpg
[2010/12/24 16:46:05 | 000,420,513 | —- | M] () – C:\Users\Jeff\Documents\Death_Note_Christmas_by_yuumei.jpg
[2010/12/24 14:57:44 | 000,001,009 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy DVD Shrink.lnk
[2010/12/24 14:57:44 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\Easy DVD Shrink.lnk
[2010/12/24 14:56:47 | 003,137,120 | —- | M] () – C:\Users\Jeff\Documents\EasyDVDShrink.exe
[2010/12/24 14:30:52 | 000,002,799 | —- | M] () – C:\Users\Jeff\Documents\BurnerSoft_Easy_DVD_Shrink_v3_0_24_WinAll_Cracked_PALACE.torrent
[2010/12/24 14:27:18 | 000,000,677 | —- | M] () – C:\Users\Jeff\Documents\Easy_DVD_Shrink_3_0_19___crack.torrent
[2010/12/21 02:05:13 | 000,027,381 | —- | M] () – C:\Users\Jeff\Documents\rob lucci 12.jpg
[2010/12/20 13:35:13 | 000,030,990 | —- | M] () – C:\Users\Jeff\Documents\New VM (4) - 018 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/20 13:35:03 | 000,024,565 | —- | M] () – C:\Users\Jeff\Documents\msg0003.WAV
[2010/12/19 11:43:45 | 000,026,245 | —- | M] () – C:\Users\Jeff\Documents\New VM (2) - 016 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/19 00:07:44 | 000,160,095 | —- | M] () – C:\Users\Jeff\Documents\1292720334657.jpg
[2010/12/18 18:55:40 | 000,026,710 | —- | M] () – C:\Users\Jeff\Documents\msg0001.WAV
[2010/12/17 15:38:22 | 000,000,222 | —- | M] () – C:\Users\Jeff\Documents\payment debt owed in credit cards.rtf
[2010/12/16 16:09:26 | 000,001,024 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/12/16 16:08:39 | 019,985,265 | —- | M] () – C:\Users\Jeff\Documents\vlc-1.1.5-win32.exe
[2010/12/16 12:45:31 | 000,026,474 | —- | M] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___01__1280x720_h264___DABC2A44__mkv.torren
t
[2010/12/16 12:42:45 | 000,030,774 | —- | M] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 03 (1280x720 h264) [DA0E37C2].mkv.torrent
[2010/12/16 12:42:04 | 000,031,674 | —- | M] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 04 (1280x720 h264) [C47036F2].mkv.torrent
[2010/12/16 12:41:22 | 000,018,625 | —- | M] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___03__XviD___880C2A90__avi.torrent
[2010/12/16 12:41:01 | 000,032,430 | —- | M] () – C:\Users\Jeff\Documents\SS_Eclipse_Shakugan_no_Shana_S_02_1280x720_h264_29745873.torrent
[2010/12/16 03:20:00 | 000,292,496 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2011/01/11 18:50:11 | 576,200,490 | —- | C] () – C:\Users\Jeff\Desktop\[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4
[2011/01/07 13:09:06 | 000,000,312 | —- | C] () – C:\Users\Jeff\Desktop\Curse Client.appref-ms
[2011/01/06 14:40:29 | 000,000,636 | —- | C] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/01/06 11:15:38 | 000,000,909 | —- | C] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/01/05 02:12:05 | 001,573,304 | —- | C] () – C:\Users\Jeff\Desktop\High PCSX2 shot.jpg
[2011/01/05 02:06:49 | 000,049,016 | —- | C] () – C:\Users\Jeff\Desktop\Low Res.jpg
[2011/01/04 05:30:46 | 000,067,272 | —- | C] () – C:\Users\Jeff\Documents\2F858BD6E084D53FEAE36FCC8DA5F35D18FC3D9E.torrent
[2011/01/01 17:34:56 | 000,196,351 | —- | C] () – C:\Users\Jeff\Documents\newyear09.jpg
[2011/01/01 16:59:26 | 000,352,031 | —- | C] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive (2).zip
[2011/01/01 16:55:28 | 000,378,538 | —- | C] () – C:\Users\Jeff\Documents\2011 Newsletter.odt
[2011/01/01 16:47:45 | 000,009,716 | —- | C] () – C:\Users\Jeff\Documents\longribbon.gif
[2011/01/01 16:47:37 | 000,012,332 | —- | C] () – C:\Users\Jeff\Documents\ribbonbar.gif
[2011/01/01 16:47:25 | 000,017,869 | —- | C] () – C:\Users\Jeff\Documents\ribbon.gif
[2011/01/01 16:37:17 | 000,069,927 | —- | C] () – C:\Users\Jeff\Documents\Happy-New-Year-Fireworks-1-800x600.jpg
[2011/01/01 16:36:32 | 000,164,757 | —- | C] () – C:\Users\Jeff\Documents\sydney-fireworks.jpg
[2011/01/01 16:36:08 | 000,242,158 | —- | C] () – C:\Users\Jeff\Documents\firecracker.jpg.bmp
[2011/01/01 16:35:56 | 000,065,909 | —- | C] () – C:\Users\Jeff\Documents\fireworks.jpg
[2011/01/01 16:35:43 | 002,294,114 | —- | C] () – C:\Users\Jeff\Documents\(Holiday - New Year) - Wallpapers4Desktop.com 001.jpg
[2011/01/01 16:33:40 | 000,014,084 | —- | C] () – C:\Users\Jeff\Documents\images2u.jpg
[2011/01/01 16:32:52 | 000,050,415 | —- | C] () – C:\Users\Jeff\Documents\Happy_New_Year_2011_Wallpapers7.jpg
[2011/01/01 16:31:47 | 000,167,713 | —- | C] () – C:\Users\Jeff\Documents\happy-new-year-2011-iphone.jpg
[2011/01/01 15:55:12 | 000,107,725 | —- | C] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive.zip
[2011/01/01 15:51:01 | 000,112,488 | —- | C] () – C:\Users\Jeff\Documents\mexican theme birthday celebration.odt
[2011/01/01 15:41:26 | 000,029,265 | —- | C] () – C:\Users\Jeff\Documents\PBANN-00138.jpg
[2011/01/01 15:41:06 | 000,018,541 | —- | C] () – C:\Users\Jeff\Documents\happy-18th-banner-qa258.jpg
[2011/01/01 15:14:28 | 000,019,545 | —- | C] () – C:\Users\Jeff\Documents\18-today-its-party-time-banner-qa104.jpg
[2011/01/01 15:13:01 | 000,043,328 | —- | C] () – C:\Users\Jeff\Documents\Party.Pug.JPEG
[2011/01/01 15:12:04 | 000,017,118 | —- | C] () – C:\Users\Jeff\Documents\mexican0.jpg
[2011/01/01 15:10:15 | 000,068,826 | —- | C] () – C:\Users\Jeff\Documents\MexicanFiestaSupplies-MAIN.jpg
[2010/12/31 18:18:24 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\DVDneXtCOPY 4.lnk
[2010/12/31 18:07:18 | 000,005,276 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_v4_0_2_8_Crack_Latest__RH.torrent
[2010/12/31 18:06:59 | 000,005,471 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_Edition_v4_2_6_3___Patch__TrT_TcT_.torrent
[2010/12/31 17:54:00 | 000,000,664 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_4_2_5_2____KeyGen___rar.torrent
[2010/12/31 17:16:16 | 001,178,319 | —- | C] () – C:\Users\Jeff\Documents\bitRipperSetup.exe
[2010/12/30 20:59:07 | 000,001,685 | —- | C] () – C:\Users\Jeff\Documents\msg0002.WAV
[2010/12/28 20:11:31 | 000,001,012 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2010/12/28 19:56:30 | 000,000,977 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2010/12/28 19:56:30 | 000,000,953 | —- | C] () – C:\Users\Jeff\Desktop\DVDFab 8.lnk
[2010/12/26 17:09:26 | 000,091,136 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_6_Complete_S06_S06E01_S06E17_S06E00_ADreaNaL.torrent
[2010/12/26 17:05:12 | 000,028,265 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E07_VOSTFR_HDTV_XViD_avi.torrent
[2010/12/26 17:04:39 | 000,014,560 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E06_ITA_HDTVMux_NovaRip__CR_Bt_.torrent
[2010/12/26 17:03:58 | 000,015,619 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E05_This_Place_Is_Death_PROPER_HDTV_XviD_FQM__rarbg_.torrent
[2010/12/26 17:03:34 | 000,014,717 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E05_HDTV_XviD___XOR.torrent
[2010/12/26 17:02:18 | 000,028,475 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E16_E17_The_Incident_HDTV_XviD_FQM.torrent
[2010/12/26 17:02:01 | 000,014,479 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E15_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:45 | 000,006,815 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E14_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:17 | 000,014,533 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E13_HDTV_XviD_NoTV_eztv.torrent
[2010/12/26 17:01:01 | 000,015,046 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E12_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 17:00:46 | 000,014,552 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E11_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:32 | 000,014,552 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E10_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:07 | 000,014,760 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E09_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 16:59:52 | 000,014,670 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E08_HDTV_XviD_XOR.torrent
[2010/12/26 16:57:22 | 000,027,658 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E04_VOSTFR_XviD_avi.torrent
[2010/12/26 16:56:44 | 000,015,262 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E03_HDTV_XviD_XOR__rarbg_com_.torrent
[2010/12/26 16:56:28 | 000,015,896 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E02_The_Lie_HDTV_XviD_2HD_avi.torrent
[2010/12/26 16:54:09 | 000,016,545 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_5__Episodes_1_7_.torrent
[2010/12/26 16:53:04 | 000,015,556 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E01_HDTV_XviD_PusherCrew_avi.torrent
[2010/12/26 16:30:50 | 000,030,080 | —- | C] () – C:\Users\Jeff\Documents\Lost_S04E02__HDTV_XviD_ENG___SUB_ENG_ITA_.torrent
[2010/12/26 16:29:39 | 000,028,370 | —- | C] () – C:\Users\Jeff\Documents\Lost_S04E01_HDTV_XviD_XOR__eztv_.torrent
[2010/12/26 16:28:49 | 000,025,984 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_4_S04E01to_S04E13_14_complete.torrent
[2010/12/26 15:38:27 | 000,000,000 | —- | C] () – C:\Users\Jeff\Documents\PDVD_MediaDisc.PlayList
[2010/12/26 15:06:04 | 000,001,989 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2010/12/26 13:31:06 | 000,001,942 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk
[2010/12/26 13:31:06 | 000,001,918 | —- | C] () – C:\Users\Jeff\Desktop\DVD Decrypter.lnk
[2010/12/26 13:30:34 | 000,899,414 | —- | C] () – C:\Users\Jeff\Documents\SetupDVDDecrypter_3.5.4.0.exe
[2010/12/26 05:32:03 | 000,014,992 | —- | C] () – C:\Users\Jeff\Documents\[Vegapunk]_One_Piece_321_330_HD.torrent
[2010/12/25 15:33:01 | 000,000,953 | —- | C] () – C:\Users\Jeff\Desktop\DVD Shrink 3.2.lnk
[2010/12/25 14:43:15 | 001,094,021 | —- | C] () – C:\Users\Jeff\Documents\dvdshrink32setup1.zip
[2010/12/24 17:04:51 | 001,528,276 | —- | C] () – C:\Users\Jeff\Documents\haruhi_christmas.jpg
[2010/12/24 17:01:18 | 000,074,865 | —- | C] () – C:\Users\Jeff\Documents\TAC_MerryChristmas2007.jpg
[2010/12/24 16:59:57 | 000,018,345 | —- | C] () – C:\Users\Jeff\Documents\images4.jpg
[2010/12/24 16:48:28 | 000,097,591 | —- | C] () – C:\Users\Jeff\Documents\okami-the-movie-20070112041935217.jpg
[2010/12/24 16:46:02 | 000,420,513 | —- | C] () – C:\Users\Jeff\Documents\Death_Note_Christmas_by_yuumei.jpg
[2010/12/24 14:57:44 | 000,001,009 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy DVD Shrink.lnk
[2010/12/24 14:57:44 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\Easy DVD Shrink.lnk
[2010/12/24 14:56:22 | 003,137,120 | —- | C] () – C:\Users\Jeff\Documents\EasyDVDShrink.exe
[2010/12/24 14:30:51 | 000,002,799 | —- | C] () – C:\Users\Jeff\Documents\BurnerSoft_Easy_DVD_Shrink_v3_0_24_WinAll_Cracked_PALACE.torrent
[2010/12/24 14:27:17 | 000,000,677 | —- | C] () – C:\Users\Jeff\Documents\Easy_DVD_Shrink_3_0_19___crack.torrent
[2010/12/21 02:05:10 | 000,027,381 | —- | C] () – C:\Users\Jeff\Documents\rob lucci 12.jpg
[2010/12/20 13:35:13 | 000,030,990 | —- | C] () – C:\Users\Jeff\Documents\New VM (4) - 018 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/20 13:35:02 | 000,024,565 | —- | C] () – C:\Users\Jeff\Documents\msg0003.WAV
[2010/12/19 11:43:44 | 000,026,245 | —- | C] () – C:\Users\Jeff\Documents\New VM (2) - 016 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/19 00:07:40 | 000,160,095 | —- | C] () – C:\Users\Jeff\Documents\1292720334657.jpg
[2010/12/18 18:55:39 | 000,026,710 | —- | C] () – C:\Users\Jeff\Documents\msg0001.WAV
[2010/12/17 15:38:22 | 000,000,222 | —- | C] () – C:\Users\Jeff\Documents\payment debt owed in credit cards.rtf
[2010/12/16 16:09:26 | 000,001,024 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/12/16 16:06:34 | 019,985,265 | —- | C] () – C:\Users\Jeff\Documents\vlc-1.1.5-win32.exe
[2010/12/16 12:45:29 | 000,026,474 | —- | C] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___01__1280x720_h264___DABC2A44__mkv.torren
t
[2010/12/16 12:42:44 | 000,030,774 | —- | C] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 03 (1280x720 h264) [DA0E37C2].mkv.torrent
[2010/12/16 12:42:03 | 000,031,674 | —- | C] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 04 (1280x720 h264) [C47036F2].mkv.torrent
[2010/12/16 12:41:22 | 000,018,625 | —- | C] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___03__XviD___880C2A90__avi.torrent
[2010/12/16 12:41:00 | 000,032,430 | —- | C] () – C:\Users\Jeff\Documents\SS_Eclipse_Shakugan_no_Shana_S_02_1280x720_h264_29745873.torrent
[2010/11/29 22:39:04 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/10 13:16:12 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/07/18 15:23:50 | 000,000,017 | —- | C] () – C:\Users\Jeff\AppData\Local\resmon.resmoncfg
[2010/07/18 14:52:22 | 000,000,036 | —- | C] () – C:\Users\Jeff\AppData\Local\housecall.guid.cache
[2010/07/14 13:49:02 | 000,000,818 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/14 11:42:56 | 000,001,041 | —- | C] () – C:\Users\Jeff\AppData\Roaming\vso_ts_preview.xml
[2010/07/14 11:42:37 | 000,000,034 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.log
[2010/07/14 11:42:07 | 000,007,887 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.cat
[2010/07/14 11:42:07 | 000,001,144 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.inf
[2010/07/11 20:30:11 | 000,051,712 | —- | C] () – C:\Users\Jeff\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/23 12:59:34 | 000,059,924 | —- | C] () – C:\Windows\System32\libdvdcss-2.dll
[2009/12/20 11:05:52 | 000,086,016 | —- | C] () – C:\Windows\System32\Machinist2.dll
[2009/07/13 15:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2006/03/18 05:16:04 | 000,540,178 | —- | C] () – C:\Windows\System32\x264vfw.dll

========== LOP Check ==========

[2010/10/26 21:48:06 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Amazon
[2010/09/23 03:14:16 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Any Video Converter
[2010/07/24 13:42:42 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Auslogics
[2010/09/19 19:42:51 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\avidemux
[2010/12/10 12:31:51 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Bitmeter2
[2010/09/24 01:59:26 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\CometPlayer
[2010/12/29 03:07:09 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\DVDFab
[2010/07/28 12:38:45 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\KeePass
[2011/01/06 12:14:28 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Mal Updater
[2011/01/06 11:39:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\mjusbsp
[2010/07/14 11:52:45 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\OpenOffice.org
[2010/11/09 23:06:00 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PMS
[2011/01/05 17:05:32 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TigerPlayer
[2011/01/12 11:36:04 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\uTorrent
[2010/12/29 21:08:20 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Vso
[2010/11/15 22:26:07 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Windows Live Writer
[2009/07/13 20:53:46 | 000,012,432 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 13:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/09/09 02:40:12 | 000,000,293 | -H– | M] () – C:\Boot.BAK
[2009/09/09 10:03:20 | 000,000,295 | RHS- | M] () – C:\boot.ini
[2009/09/09 10:56:47 | 000,000,437 | RHS- | M] () – C:\Boot.ini.saved
[2009/07/13 17:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/09/09 10:56:49 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/12/04 15:29:20 | 000,014,274 | —- | M] () – C:\ComboFix.txt
[2009/06/10 13:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/07/10 00:41:44 | 000,203,836 | RHS- | M] () – C:\grldr
[2011/01/12 11:17:37 | 2006,278,144 | -HS- | M] () – C:\hiberfil.sys
[2009/05/28 08:21:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/08/01 14:55:02 | 000,000,884 | -H– | M] () – C:\IPH.PH
[2010/11/29 22:41:43 | 000,221,966 | —- | M] () – C:\matroskasplitter_20050310.7z
[2009/05/28 08:21:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 04:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/12 11:17:38 | 2675,040,256 | -HS- | M] () – C:\pagefile.sys
[2010/07/10 00:41:45 | 000,000,000 | RHS- | M] () – C:\winx.ld

< %systemroot%\Fonts\*.com >
[2009/07/13 20:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 20:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 20:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 20:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/10/17 13:55:18 | 000,321,536 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp696.dll
[2009/07/13 17:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/13 17:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/22 23:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 20:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-12 19:29:31

========== Alternate Data Streams ==========

@Alternate Data Stream - 191 bytes -> C:\ProgramData\TEMP:2CFDCA54
@Alternate Data Stream - 182 bytes -> C:\ProgramData\TEMP:6971CCC5
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:07BB519E

< End of report >







OTL Extras logfile created on: 1/12/2011 11:44:24 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\Jeff\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 17.92 Gb Free Space | 12.02% Space Free | Partition Type: NTFS
Drive D: | 39.07 Gb Total Space | 30.11 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
Drive E: | 35.46 Gb Total Space | 5.55 Gb Free Space | 15.65% Space Free | Partition Type: NTFS
Drive G: | 931.51 Gb Total Space | 330.41 Gb Free Space | 35.47% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 163.52 Gb Free Space | 8.78% Space Free | Partition Type: NTFS
Drive J: | 1.64 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 17.59 Mb Total Space | 17.32 Mb Free Space | 98.44% Space Free | Partition Type: FAT
Drive O: | 1016.16 Mb Total Space | 943.03 Mb Free Space | 92.80% Space Free | Partition Type: NTFS
Drive P: | 148.05 Gb Total Space | 61.45 Gb Free Space | 41.51% Space Free | Partition Type: NTFS
Drive Q: | 1863.01 Gb Total Space | 516.79 Gb Free Space | 27.74% Space Free | Partition Type: NTFS

Computer Name: JEFF-PC | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [TVersity] – "C:\ProgramData\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F93853-D9D3-4795-A89E-84CCBA0205C9}" = Microsoft IntelliPoint 8.0
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07E900C8-D1E3-4C24-AC9F-7FE3C1AE19A2}_is1" = Mal Updater 2.56
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20EFC9AA-BBC1-4DFD-81FF-99654F71CBF8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}" = mkv2vob
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{59E44523-0F0F-4454-9F37-E951BBA55B84}" = C309a
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{5F548A02-80BC-404D-BAE6-F05F9BF6B449}" = Nero DiscCopyGadget 10 Help (CHM)
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6B2C675E-8040-431B-99C4-137DF4FBF75A}" = Thermal Analysis Tool
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{71C4F928-136A-4222-A191-310E081FB96B}" = HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 5
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.0.0.1
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}" = Nero DiscCopy Gadget 10
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B28635AB-1DF3-4F07-BFEA-975D911B549B}" = hpphotosmartdisclabelplugin
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4F3A360-E1E2-479D-ADE7-9BE3B07F4539}" = NVIDIA PhysX
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9FB868B-2086-4EE2-BD4F-BFBA36B131F4}" = NCsoft Launcher
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D9D8F2CF-FE2D-4644-9762-01F916FE90A9}" = HPPhotoSmartDiscLabel_PaperLabel
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD0}" = Paint.NET v3.5.5
"{F2C4E6E0-EB78-4824-A212-6DF6AF0E8E82}" = FINAL FANTASY XIV
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{FA0E7183-6B11-4899-B25F-2C490543967E}" = PS_AIO_05_C309_Software_Min
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FB1AC1F1-8F47-4DCE-A1ED-0DFBA0F455B4}" = Driver Mender
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"AC3Filter" = AC3Filter (remove only)
"Active@ Partition Recovery Enterprise" = Active@ Partition Recovery Enterprise
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AllToAVI" = AllToAVI v4 r5394
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"Any Video Converter_is1" = Any Video Converter 2.7.3
"Avidemux 2.5" = Avidemux 2.5
"Belarc Advisor" = Belarc Advisor 8.1
"BitMeter" = BitMeter
"bitRipper" = bitRipper
"coreavc_is1" = CoreAVC Pro [removed]
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.54
"CrossLoop_is1" = CrossLoop 2.73
"DivX Setup.divx.com" = DivX Setup
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 8_is1" = DVDFab 8.0.6.5 (27/12/2010)
"DVDneXtCOPY 4 neXtTech" = DVDneXtCOPY 4 neXtTech
"Easy DVD Shrink" = Easy DVD Shrink
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.60
"EVGA E-LEET TUNING UTILITY_is1" = EVGA E-LEET TUNING UTILITY 1.06.0
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"HPOCR" = OCR Software by I.R.I.S. 14.0
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.12
"Machinist 2" = Machinist 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marvell Miniport Driver" = Marvell Miniport Driver
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"mIRC" = mIRC
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MpcStar" = MpcStar 4.9
"mv61xxDriver" = marvell 61xx
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Orb" = Orb
"PC Pitstop Exterminate2_is1" = PC Pitstop Exterminate2 2.0
"PS3 Media Server" = PS3 Media Server
"PS3 Video 9" = PS3 Video 9 2.25
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.3
"RivaTuner" = RivaTuner v2.24
"Shop for HP Supplies" = Shop for HP Supplies
"TVersity Codec Pack" = TVersity Codec Pack 1.4
"TVersity Media Server" = TVersity Media Server 1.9.3
"uTorrent" = µTorrent
"VirtualLab 5 Client_is1" = VirtualLab Client 5.7.5
"VLC media player" = VLC media player 1.1.5
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"magicJack" = magicJack

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/12/2011 9:31:10 AM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7600.16450,
time stamp: 0x4aeba271 Faulting module name: QuickTimeH264.qtx, version: 7.60.92.0,
time stamp: 0x49628b2f Exception code: 0xc0000005 Fault offset: 0x00058444 Faulting
process id: 0x1100 Faulting application start time: 0x01cbb25cf8c9296f Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\QuickTimeH264.qtx
Report
Id: 3751f282-1e50-11e0-be91-001fbc08a6b5

Error - 1/12/2011 9:31:17 AM | Computer Name = Jeff-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\real\realplayer\plugins\rmxrend.dll".
Dependent
Assembly Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 1/12/2011 9:31:18 AM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7600.16450,
time stamp: 0x4aeba271 Faulting module name: QuickTimeH264.qtx, version: 7.60.92.0,
time stamp: 0x49628b2f Exception code: 0xc0000005 Fault offset: 0x00058444 Faulting
process id: 0x10e0 Faulting application start time: 0x01cbb25cfd460a97 Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\QuickTimeH264.qtx
Report
Id: 3bcd7c58-1e50-11e0-be91-001fbc08a6b5

Error - 1/12/2011 9:31:25 AM | Computer Name = Jeff-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\real\realplayer\plugins\rmxrend.dll".
Dependent
Assembly Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 1/12/2011 9:31:25 AM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7600.16450,
time stamp: 0x4aeba271 Faulting module name: QuickTimeH264.qtx, version: 7.60.92.0,
time stamp: 0x49628b2f Exception code: 0xc0000005 Fault offset: 0x00058444 Faulting
process id: 0x5d8 Faulting application start time: 0x01cbb25d01c0fbd7 Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\QuickTimeH264.qtx
Report
Id: 402e33ba-1e50-11e0-be91-001fbc08a6b5

Error - 1/12/2011 9:31:32 AM | Computer Name = Jeff-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\real\realplayer\plugins\rmxrend.dll".
Dependent
Assembly Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 1/12/2011 9:31:32 AM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7600.16450,
time stamp: 0x4aeba271 Faulting module name: QuickTimeH264.qtx, version: 7.60.92.0,
time stamp: 0x49628b2f Exception code: 0xc0000005 Fault offset: 0x00058444 Faulting
process id: 0x1148 Faulting application start time: 0x01cbb25d062356d6 Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\QuickTimeH264.qtx
Report
Id: 449f4f46-1e50-11e0-be91-001fbc08a6b5

Error - 1/12/2011 10:18:55 AM | Computer Name = Jeff-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files\microsoft\search
enhancement pack\search box extension\SrchBxEx.dll".Error in manifest or policy
file "c:\program files\microsoft\search enhancement pack\search box extension\SrchBxEx.dll"
on line 2. Invalid Xml syntax.

Error - 1/12/2011 3:22:21 PM | Computer Name = Jeff-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\real\realplayer\plugins\rmxrend.dll".
Dependent
Assembly Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 1/12/2011 3:27:27 PM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: MediaServer.exe, version: 0.0.0.0, time
stamp: 0x4ced7696 Faulting module name: msvcrt.dll, version: 7.0.7600.16385, time
stamp: 0x4a5bda6f Exception code: 0x40000015 Fault offset: 0x00066804 Faulting process
id: 0xdc Faulting application start time: 0x01cbb28d73ccf0ad Faulting application
path: C:\ProgramData\TVersity\Media Server\MediaServer.exe Faulting module path:
C:\Windows\system32\msvcrt.dll Report Id: fcfd6930-1e81-11e0-9c4f-001fbc08a6b5

[ Media Center Events ]
Error - 7/29/2010 4:03:10 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 1:03:10 PM - Error connecting to the internet. 1:03:10 PM - Unable
to contact server..

Error - 7/29/2010 4:03:41 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 1:03:38 PM - Error connecting to the internet. 1:03:38 PM - Unable
to contact server..

Error - 7/29/2010 5:04:18 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 2:04:18 PM - Error connecting to the internet. 2:04:18 PM - Unable
to contact server..

Error - 7/29/2010 5:04:46 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 2:04:45 PM - Error connecting to the internet. 2:04:45 PM - Unable
to contact server..

Error - 7/29/2010 6:05:23 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 3:05:23 PM - Error connecting to the internet. 3:05:23 PM - Unable
to contact server..

Error - 7/29/2010 6:05:52 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 3:05:50 PM - Error connecting to the internet. 3:05:50 PM - Unable
to contact server..

Error - 7/29/2010 7:10:39 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:10:39 PM - Error connecting to the internet. 4:10:39 PM - Unable
to contact server..

Error - 7/29/2010 7:11:07 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:11:06 PM - Error connecting to the internet. 4:11:06 PM - Unable
to contact server..

Error - 10/12/2010 4:32:36 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 1:32:36 PM - Failed to retrieve Directory (Error: The underlying connection
was closed: An unexpected error occurred on a receive.)

[ System Events ]
Error - 1/12/2011 2:14:10 AM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2004
Description = %%861 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824

Error
Code: 0x80070002 Error description: The system cannot find the file specified. Signature
version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0

Error - 1/12/2011 2:35:25 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7034
Description = The TVersity Media Server service terminated unexpectedly. It has
done this 1 time(s).

Error - 1/12/2011 9:23:18 AM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2004
Description = %%861 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824

Error
Code: 0x80070002 Error description: The system cannot find the file specified. Signature
version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0

Error - 1/12/2011 3:18:09 PM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2004
Description = %%861 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824

Error
Code: 0x80070002 Error description: The system cannot find the file specified. Signature
version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0

Error - 1/12/2011 3:26:11 PM | Computer Name = Jeff-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8024200d: Update for Windows 7 (KB2454826).

Error - 1/12/2011 3:26:20 PM | Computer Name = Jeff-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8024200d: Security Update for Windows 7 (KB2419640).

Error - 1/12/2011 3:27:37 PM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7034
Description = The TVersity Media Server service terminated unexpectedly. It has
done this 1 time(s).

Error - 1/12/2011 3:29:11 PM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.95.3566.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6402.0 Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/12/2011 3:29:11 PM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.95.3566.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6402.0 Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 1/12/2011 3:29:11 PM | Computer Name = JEFF-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.95.3566.0 Update Source: %%859 Update Stage:
%%853 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6402.0 Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.


< End of report >
I just located it in the log. I will copy this file. [2011/01/11 18:50:11 | 576,200,490 | —- | C] () – C:\Users\Jeff\Desktop\[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4
Jeff, Your log shows that you have installed pirated software and kegens on your system. This type of activity virtually guarantees you will get infected and complicates my help. Per the terms of use here at WTT…. I need you to remove these from your system. Please do so and then run OTL again a post the log. There will only be one log this time.
Keygens?? What kind of keygens. I don't use anything like that, i do use a p2p sharing software application, i can uninstall that for the time being i guess. But i dont think that is causing any complications on my machine as i have not downloaded anything new in quite a while and this problem only just surfaced like a few days ago once i copied that file to my C root drive.

In any case i am not sure i really want to un install Utorrent. I have some settings on there that i really had to mess with to get desired results through my router and i don't want to accidentally reset those settings. It was kind of time consuming and challanging. Is there a way i can just like disable the program so its not running in the background or something
Maybe i can copy the root files of the program? To one of my external hard drives, then un install it from my C drive. So that when i install it again when i need to use it, i can just over write the directory of the program with the previous files.
Ok nmv, there is an option to keep settings well uninstalling so i uninstalled it. Now ill post the logs.


I used the same exact settings you wanted from my previous OTL log as to not confuse things.


OTL logfile created on: 1/12/2011 1:29:03 PM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Users\Jeff\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 48.00% Memory free
5.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 17.78 Gb Free Space | 11.93% Space Free | Partition Type: NTFS
Drive D: | 39.07 Gb Total Space | 30.11 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
Drive E: | 35.46 Gb Total Space | 5.55 Gb Free Space | 15.65% Space Free | Partition Type: NTFS
Drive F: | 4.20 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 931.51 Gb Total Space | 304.95 Gb Free Space | 32.74% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 163.73 Gb Free Space | 8.79% Space Free | Partition Type: NTFS
Drive J: | 1.64 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 17.59 Mb Total Space | 17.32 Mb Free Space | 98.44% Space Free | Partition Type: FAT
Drive O: | 1016.16 Mb Total Space | 943.03 Mb Free Space | 92.80% Space Free | Partition Type: NTFS
Drive P: | 148.05 Gb Total Space | 61.45 Gb Free Space | 41.51% Space Free | Partition Type: NTFS
Drive Q: | 1863.01 Gb Total Space | 516.79 Gb Free Space | 27.74% Space Free | Partition Type: NTFS

Computer Name: JEFF-PC | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jeff\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Codebox\BitMeter\BitMeter2.exe ( )
PRC - C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Jeff\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper.dll File not found
SRV - (TVersityMediaServer) – C:\ProgramData\TVersity\Media Server\MediaServer.exe ()
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (CrossLoopService) – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (uvnc_service) – C:\Users\Jeff\AppData\Local\CrossLoop\winvnc.exe (UltraVNC)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PS3 Media Server) – C:\Program Files\PS3 Media Server\win32\service\wrapper.exe ()
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (nlsX86cc) – C:\Windows\System32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys File not found
DRV - (catchme) – C:\Users\Jeff\AppData\Local\Temp\catchme.sys File not found
DRV - (ALSysIO) – C:\Users\Jeff\AppData\Local\Temp\ALSysIO.sys File not found
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (cpuz133) – C:\Windows\System32\drivers\cpuz133_x32.sys (Windows ® Win 7 DDK provider)
DRV - (ivusb) – C:\Windows\System32\drivers\ivusb.sys (Initio Corporation)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (mv61xx) – C:\Windows\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (cpuz132) – C:\Windows\System32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (RivaTuner32) – C:\Program Files\RivaTuner v2.24\RivaTuner32.sys ()
DRV - (ASPI32) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC 0C AE 38 72 92 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/14 13:53:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/28 20:11:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/28 20:11:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/12 11:16:21 | 000,000,000 | —D | M]

[2010/07/10 01:29:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions
[2011/01/12 11:37:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions
[2010/09/16 21:57:42 | 000,000,000 | —D | M] (WOT) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/12/24 15:37:32 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\wu8khyid.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/11/10 09:36:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/10 22:38:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/05 12:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/10 09:36:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/12 11:16:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/12/28 20:11:19 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/04 15:21:18 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cdloader] C:\Users\Jeff\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [CrossLoop] C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009/06/10 13:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/07/02 13:32:34 | 000,000,000 | R–D | M] - H:\autorun – [ NTFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,027,992 | R— | M] (magicJack L.P.) - J:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,016,158 | R— | M] () - J:\autorun.ico – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,000,308 | R— | M] () - J:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/08/03 09:04:35 | 000,728,816 | R— | M] (magicJack L.P.) - J:\autorunu.exe – [ CDFS ]
O32 - AutoRun File - [2009/08/01 16:17:00 | 000,000,270 | —- | M] () - K:\autorun.inf – [ FAT ]
O32 - AutoRun File - [2010/07/02 13:30:52 | 000,000,000 | R–D | M] - Q:\autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 11:43:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2011/01/08 17:35:20 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\DVDFab
[2011/01/07 13:09:06 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
[2011/01/07 13:06:59 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Deployment
[2011/01/06 15:36:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
[2011/01/06 11:15:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
[2011/01/06 11:15:37 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\mIRC
[2011/01/06 11:15:36 | 000,000,000 | —D | C] – C:\Program Files\mIRC
[2011/01/06 11:12:03 | 002,079,752 | —- | C] (mIRC Co. Ltd.) – C:\Users\Jeff\Desktop\mirc717.exe
[2011/01/06 11:04:55 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\AddOns
[2011/01/06 11:04:14 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\WTF
[2011/01/06 11:04:03 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\WTF.20100824-182143
[2011/01/06 11:02:50 | 000,000,000 | —D | C] – C:\Users\Jeff\Desktop\Screenshots
[2010/12/31 18:18:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDneXtCOPY 4
[2010/12/31 18:18:21 | 000,000,000 | —D | C] – C:\Program Files\DVDneXtCOPY 4
[2010/12/31 17:34:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Machinist 2
[2010/12/31 17:34:30 | 000,000,000 | —D | C] – C:\Program Files\Machinist 2
[2010/12/31 17:30:51 | 000,000,000 | —D | C] – C:\ProgramData\DVDneXtCOPY
[2010/12/31 17:30:51 | 000,000,000 | —D | C] – C:\DVDneXtCOPY
[2010/12/31 17:28:29 | 014,783,188 | —- | C] (DVDneXtCOPY Inc.) – C:\Users\Jeff\Documents\dvdnextcopy_next_tech_setup.exe
[2010/12/31 17:18:57 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\My DVD Backups
[2010/12/31 17:18:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitRipper
[2010/12/31 17:18:45 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\bitRipper
[2010/12/31 17:18:45 | 000,000,000 | —D | C] – C:\Program Files\bitRipper
[2010/12/29 03:07:09 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\DVDFab
[2010/12/28 20:12:05 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Real
[2010/12/28 20:11:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2010/12/28 20:11:02 | 000,199,904 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2010/12/28 20:10:50 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2010/12/28 20:10:50 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2010/12/28 20:10:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2010/12/28 19:56:33 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\NVIDIA
[2010/12/28 19:56:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8
[2010/12/28 19:56:21 | 000,000,000 | —D | C] – C:\Program Files\DVDFab 8
[2010/12/28 19:48:40 | 014,917,520 | —- | C] (Fengtao Software Inc. ) – C:\Users\Jeff\Documents\DVDFab8065_avangate-675.exe
[2010/12/26 15:07:53 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\CyberLink
[2010/12/26 15:07:38 | 000,000,000 | —D | C] – C:\Users\Jeff\Documents\CyberLink
[2010/12/26 15:06:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2010/12/26 15:05:54 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2010/12/26 15:05:45 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2010/12/26 13:31:06 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVD Decrypter
[2010/12/26 13:31:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Decrypter
[2010/12/26 13:31:05 | 000,000,000 | —D | C] – C:\Program Files\DVD Decrypter
[2010/12/25 15:33:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
[2010/12/25 15:33:00 | 000,000,000 | —D | C] – C:\Program Files\DVD Shrink
[2010/12/24 14:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy DVD Shrink
[2010/12/24 14:28:33 | 000,000,000 | —D | C] – C:\Easy_DVD_Shrink 3.0.19
[2010/12/24 14:25:59 | 000,045,056 | —- | C] (Adaptec) – C:\Windows\System32\WNASPI32.DLL
[2010/12/24 14:25:59 | 000,025,244 | —- | C] (Adaptec) – C:\Windows\System32\drivers\ASPI32.SYS
[2010/12/24 14:25:59 | 000,005,600 | —- | C] (Adaptec) – C:\Windows\System\WINASPI.DLL
[2010/12/24 14:25:59 | 000,004,672 | —- | C] (Adaptec) – C:\Windows\System\WOWPOST.EXE
[2010/12/24 14:25:49 | 000,000,000 | —D | C] – C:\Program Files\EasyDVDShrink
[2010/12/16 16:09:33 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\vlc
[2010/12/16 16:09:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2010/12/15 03:53:24 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/15 03:53:17 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 03:53:15 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 03:53:15 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 03:53:15 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 03:53:15 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 03:53:15 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 03:53:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/15 03:53:15 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/15 03:53:15 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 03:53:15 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/15 03:53:15 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/15 03:53:05 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 03:53:05 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 03:53:05 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 03:53:05 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
[2010/12/15 03:52:59 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 03:52:59 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 03:52:57 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2010/12/15 03:52:56 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 03:51:26 | 002,327,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/07/14 11:42:07 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Jeff\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/01/12 11:43:08 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2011/01/12 11:29:07 | 000,023,200 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/12 11:29:07 | 000,023,200 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/12 11:18:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/01/12 11:17:37 | 2006,278,144 | -HS- | M] () – C:\hiberfil.sys
[2011/01/08 00:26:50 | 000,000,636 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/01/07 13:09:06 | 000,000,312 | —- | M] () – C:\Users\Jeff\Desktop\Curse Client.appref-ms
[2011/01/06 11:38:56 | 000,000,987 | —- | M] () – C:\Users\Jeff\Desktop\magicJack.lnk
[2011/01/06 11:15:38 | 000,000,909 | —- | M] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/01/06 11:12:22 | 002,079,752 | —- | M] (mIRC Co. Ltd.) – C:\Users\Jeff\Desktop\mirc717.exe
[2011/01/05 02:12:50 | 001,573,304 | —- | M] () – C:\Users\Jeff\Desktop\High PCSX2 shot.jpg
[2011/01/05 02:06:53 | 000,049,016 | —- | M] () – C:\Users\Jeff\Desktop\Low Res.jpg
[2011/01/04 05:30:56 | 000,067,272 | —- | M] () – C:\Users\Jeff\Documents\2F858BD6E084D53FEAE36FCC8DA5F35D18FC3D9E.torrent
[2011/01/01 17:34:57 | 000,196,351 | —- | M] () – C:\Users\Jeff\Documents\newyear09.jpg
[2011/01/01 16:59:28 | 000,352,031 | —- | M] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive (2).zip
[2011/01/01 16:59:21 | 000,378,538 | —- | M] () – C:\Users\Jeff\Documents\2011 Newsletter.odt
[2011/01/01 16:47:45 | 000,009,716 | —- | M] () – C:\Users\Jeff\Documents\longribbon.gif
[2011/01/01 16:47:38 | 000,012,332 | —- | M] () – C:\Users\Jeff\Documents\ribbonbar.gif
[2011/01/01 16:47:26 | 000,017,869 | —- | M] () – C:\Users\Jeff\Documents\ribbon.gif
[2011/01/01 16:37:18 | 000,069,927 | —- | M] () – C:\Users\Jeff\Documents\Happy-New-Year-Fireworks-1-800x600.jpg
[2011/01/01 16:36:33 | 000,164,757 | —- | M] () – C:\Users\Jeff\Documents\sydney-fireworks.jpg
[2011/01/01 16:36:09 | 000,242,158 | —- | M] () – C:\Users\Jeff\Documents\firecracker.jpg.bmp
[2011/01/01 16:35:56 | 000,065,909 | —- | M] () – C:\Users\Jeff\Documents\fireworks.jpg
[2011/01/01 16:35:44 | 002,294,114 | —- | M] () – C:\Users\Jeff\Documents\(Holiday - New Year) - Wallpapers4Desktop.com 001.jpg
[2011/01/01 16:33:41 | 000,014,084 | —- | M] () – C:\Users\Jeff\Documents\images2u.jpg
[2011/01/01 16:32:53 | 000,050,415 | —- | M] () – C:\Users\Jeff\Documents\Happy_New_Year_2011_Wallpapers7.jpg
[2011/01/01 16:31:48 | 000,167,713 | —- | M] () – C:\Users\Jeff\Documents\happy-new-year-2011-iphone.jpg
[2011/01/01 15:55:15 | 000,107,725 | —- | M] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive.zip
[2011/01/01 15:51:03 | 000,112,488 | —- | M] () – C:\Users\Jeff\Documents\mexican theme birthday celebration.odt
[2011/01/01 15:41:27 | 000,029,265 | —- | M] () – C:\Users\Jeff\Documents\PBANN-00138.jpg
[2011/01/01 15:41:07 | 000,018,541 | —- | M] () – C:\Users\Jeff\Documents\happy-18th-banner-qa258.jpg
[2011/01/01 15:14:29 | 000,019,545 | —- | M] () – C:\Users\Jeff\Documents\18-today-its-party-time-banner-qa104.jpg
[2011/01/01 15:13:02 | 000,043,328 | —- | M] () – C:\Users\Jeff\Documents\Party.Pug.JPEG
[2011/01/01 15:12:05 | 000,017,118 | —- | M] () – C:\Users\Jeff\Documents\mexican0.jpg
[2011/01/01 15:10:18 | 000,068,826 | —- | M] () – C:\Users\Jeff\Documents\MexicanFiestaSupplies-MAIN.jpg
[2010/12/31 18:18:24 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\DVDneXtCOPY 4.lnk
[2010/12/31 18:07:18 | 000,005,276 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_v4_0_2_8_Crack_Latest__RH.torrent
[2010/12/31 18:07:01 | 000,005,471 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_Edition_v4_2_6_3___Patch__TrT_TcT_.torrent
[2010/12/31 17:54:09 | 000,000,664 | —- | M] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_4_2_5_2____KeyGen___rar.torrent
[2010/12/31 17:30:28 | 014,783,188 | —- | M] (DVDneXtCOPY Inc.) – C:\Users\Jeff\Documents\dvdnextcopy_next_tech_setup.exe
[2010/12/31 17:18:10 | 001,178,319 | —- | M] () – C:\Users\Jeff\Documents\bitRipperSetup.exe
[2010/12/30 20:59:13 | 000,001,685 | —- | M] () – C:\Users\Jeff\Documents\msg0002.WAV
[2010/12/29 21:08:20 | 000,001,041 | —- | M] () – C:\Users\Jeff\AppData\Roaming\vso_ts_preview.xml
[2010/12/28 20:11:31 | 000,001,012 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2010/12/28 20:11:02 | 000,199,904 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2010/12/28 20:10:50 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2010/12/28 20:10:50 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2010/12/28 19:56:30 | 000,000,977 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2010/12/28 19:56:30 | 000,000,953 | —- | M] () – C:\Users\Jeff\Desktop\DVDFab 8.lnk
[2010/12/28 19:55:25 | 014,917,520 | —- | M] (Fengtao Software Inc. ) – C:\Users\Jeff\Documents\DVDFab8065_avangate-675.exe
[2010/12/26 17:09:29 | 000,091,136 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_6_Complete_S06_S06E01_S06E17_S06E00_ADreaNaL.torrent
[2010/12/26 17:05:12 | 000,028,265 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E07_VOSTFR_HDTV_XViD_avi.torrent
[2010/12/26 17:04:39 | 000,014,560 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E06_ITA_HDTVMux_NovaRip__CR_Bt_.torrent
[2010/12/26 17:03:59 | 000,015,619 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E05_This_Place_Is_Death_PROPER_HDTV_XviD_FQM__rarbg_.torrent
[2010/12/26 17:03:34 | 000,014,717 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E05_HDTV_XviD___XOR.torrent
[2010/12/26 17:02:18 | 000,028,475 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E16_E17_The_Incident_HDTV_XviD_FQM.torrent
[2010/12/26 17:02:01 | 000,014,479 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E15_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:45 | 000,006,815 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E14_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:18 | 000,014,533 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E13_HDTV_XviD_NoTV_eztv.torrent
[2010/12/26 17:01:01 | 000,015,046 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E12_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 17:00:47 | 000,014,552 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E11_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:33 | 000,014,552 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E10_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:08 | 000,014,760 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E09_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 16:59:53 | 000,014,670 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E08_HDTV_XviD_XOR.torrent
[2010/12/26 16:57:22 | 000,027,658 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E04_VOSTFR_XviD_avi.torrent
[2010/12/26 16:56:45 | 000,015,262 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E03_HDTV_XviD_XOR__rarbg_com_.torrent
[2010/12/26 16:56:28 | 000,015,896 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E02_The_Lie_HDTV_XviD_2HD_avi.torrent
[2010/12/26 16:54:09 | 000,016,545 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_5__Episodes_1_7_.torrent
[2010/12/26 16:53:04 | 000,015,556 | —- | M] () – C:\Users\Jeff\Documents\Lost_S05E01_HDTV_XviD_PusherCrew_avi.torrent
[2010/12/26 16:30:50 | 000,030,080 | —- | M] () – C:\Users\Jeff\Documents\Lost_S04E02__HDTV_XviD_ENG___SUB_ENG_ITA_.torrent
[2010/12/26 16:29:39 | 000,028,370 | —- | M] () – C:\Users\Jeff\Documents\Lost_S04E01_HDTV_XviD_XOR__eztv_.torrent
[2010/12/26 16:28:50 | 000,025,984 | —- | M] () – C:\Users\Jeff\Documents\Lost_Season_4_S04E01to_S04E13_14_complete.torrent
[2010/12/26 15:38:27 | 000,000,000 | —- | M] () – C:\Users\Jeff\Documents\PDVD_MediaDisc.PlayList
[2010/12/26 15:06:04 | 000,001,989 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2010/12/26 13:31:06 | 000,001,942 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk
[2010/12/26 13:31:06 | 000,001,918 | —- | M] () – C:\Users\Jeff\Desktop\DVD Decrypter.lnk
[2010/12/26 13:30:40 | 000,899,414 | —- | M] () – C:\Users\Jeff\Documents\SetupDVDDecrypter_3.5.4.0.exe
[2010/12/26 05:32:30 | 000,014,992 | —- | M] () – C:\Users\Jeff\Documents\[Vegapunk]_One_Piece_321_330_HD.torrent
[2010/12/25 15:33:01 | 000,000,953 | —- | M] () – C:\Users\Jeff\Desktop\DVD Shrink 3.2.lnk
[2010/12/25 14:43:34 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/25 14:43:34 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/25 14:43:17 | 001,094,021 | —- | M] () – C:\Users\Jeff\Documents\dvdshrink32setup1.zip
[2010/12/24 17:04:52 | 001,528,276 | —- | M] () – C:\Users\Jeff\Documents\haruhi_christmas.jpg
[2010/12/24 17:01:19 | 000,074,865 | —- | M] () – C:\Users\Jeff\Documents\TAC_MerryChristmas2007.jpg
[2010/12/24 16:59:58 | 000,018,345 | —- | M] () – C:\Users\Jeff\Documents\images4.jpg
[2010/12/24 16:48:30 | 000,097,591 | —- | M] () – C:\Users\Jeff\Documents\okami-the-movie-20070112041935217.jpg
[2010/12/24 16:46:05 | 000,420,513 | —- | M] () – C:\Users\Jeff\Documents\Death_Note_Christmas_by_yuumei.jpg
[2010/12/24 14:57:44 | 000,001,009 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy DVD Shrink.lnk
[2010/12/24 14:57:44 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\Easy DVD Shrink.lnk
[2010/12/24 14:56:47 | 003,137,120 | —- | M] () – C:\Users\Jeff\Documents\EasyDVDShrink.exe
[2010/12/24 14:30:52 | 000,002,799 | —- | M] () – C:\Users\Jeff\Documents\BurnerSoft_Easy_DVD_Shrink_v3_0_24_WinAll_Cracked_PALACE.torrent
[2010/12/24 14:27:18 | 000,000,677 | —- | M] () – C:\Users\Jeff\Documents\Easy_DVD_Shrink_3_0_19___crack.torrent
[2010/12/21 02:05:13 | 000,027,381 | —- | M] () – C:\Users\Jeff\Documents\rob lucci 12.jpg
[2010/12/20 13:35:13 | 000,030,990 | —- | M] () – C:\Users\Jeff\Documents\New VM (4) - 018 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/20 13:35:03 | 000,024,565 | —- | M] () – C:\Users\Jeff\Documents\msg0003.WAV
[2010/12/19 11:43:45 | 000,026,245 | —- | M] () – C:\Users\Jeff\Documents\New VM (2) - 016 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/19 00:07:44 | 000,160,095 | —- | M] () – C:\Users\Jeff\Documents\1292720334657.jpg
[2010/12/18 18:55:40 | 000,026,710 | —- | M] () – C:\Users\Jeff\Documents\msg0001.WAV
[2010/12/17 15:38:22 | 000,000,222 | —- | M] () – C:\Users\Jeff\Documents\payment debt owed in credit cards.rtf
[2010/12/16 16:09:26 | 000,001,024 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/12/16 16:08:39 | 019,985,265 | —- | M] () – C:\Users\Jeff\Documents\vlc-1.1.5-win32.exe
[2010/12/16 12:45:31 | 000,026,474 | —- | M] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___01__1280x720_h264___DABC2A44__mkv.torren
t
[2010/12/16 12:42:45 | 000,030,774 | —- | M] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 03 (1280x720 h264) [DA0E37C2].mkv.torrent
[2010/12/16 12:42:04 | 000,031,674 | —- | M] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 04 (1280x720 h264) [C47036F2].mkv.torrent
[2010/12/16 12:41:22 | 000,018,625 | —- | M] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___03__XviD___880C2A90__avi.torrent
[2010/12/16 12:41:01 | 000,032,430 | —- | M] () – C:\Users\Jeff\Documents\SS_Eclipse_Shakugan_no_Shana_S_02_1280x720_h264_29745873.torrent
[2010/12/16 03:20:00 | 000,292,496 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2011/01/11 18:50:11 | 576,200,490 | —- | C] () – C:\Users\Jeff\Desktop\[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4
[2011/01/07 13:09:06 | 000,000,312 | —- | C] () – C:\Users\Jeff\Desktop\Curse Client.appref-ms
[2011/01/06 14:40:29 | 000,000,636 | —- | C] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/01/06 11:15:38 | 000,000,909 | —- | C] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/01/05 02:12:05 | 001,573,304 | —- | C] () – C:\Users\Jeff\Desktop\High PCSX2 shot.jpg
[2011/01/05 02:06:49 | 000,049,016 | —- | C] () – C:\Users\Jeff\Desktop\Low Res.jpg
[2011/01/04 05:30:46 | 000,067,272 | —- | C] () – C:\Users\Jeff\Documents\2F858BD6E084D53FEAE36FCC8DA5F35D18FC3D9E.torrent
[2011/01/01 17:34:56 | 000,196,351 | —- | C] () – C:\Users\Jeff\Documents\newyear09.jpg
[2011/01/01 16:59:26 | 000,352,031 | —- | C] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive (2).zip
[2011/01/01 16:55:28 | 000,378,538 | —- | C] () – C:\Users\Jeff\Documents\2011 Newsletter.odt
[2011/01/01 16:47:45 | 000,009,716 | —- | C] () – C:\Users\Jeff\Documents\longribbon.gif
[2011/01/01 16:47:37 | 000,012,332 | —- | C] () – C:\Users\Jeff\Documents\ribbonbar.gif
[2011/01/01 16:47:25 | 000,017,869 | —- | C] () – C:\Users\Jeff\Documents\ribbon.gif
[2011/01/01 16:37:17 | 000,069,927 | —- | C] () – C:\Users\Jeff\Documents\Happy-New-Year-Fireworks-1-800x600.jpg
[2011/01/01 16:36:32 | 000,164,757 | —- | C] () – C:\Users\Jeff\Documents\sydney-fireworks.jpg
[2011/01/01 16:36:08 | 000,242,158 | —- | C] () – C:\Users\Jeff\Documents\firecracker.jpg.bmp
[2011/01/01 16:35:56 | 000,065,909 | —- | C] () – C:\Users\Jeff\Documents\fireworks.jpg
[2011/01/01 16:35:43 | 002,294,114 | —- | C] () – C:\Users\Jeff\Documents\(Holiday - New Year) - Wallpapers4Desktop.com 001.jpg
[2011/01/01 16:33:40 | 000,014,084 | —- | C] () – C:\Users\Jeff\Documents\images2u.jpg
[2011/01/01 16:32:52 | 000,050,415 | —- | C] () – C:\Users\Jeff\Documents\Happy_New_Year_2011_Wallpapers7.jpg
[2011/01/01 16:31:47 | 000,167,713 | —- | C] () – C:\Users\Jeff\Documents\happy-new-year-2011-iphone.jpg
[2011/01/01 15:55:12 | 000,107,725 | —- | C] () – C:\Users\Jeff\Documents\New WinRAR ZIP archive.zip
[2011/01/01 15:51:01 | 000,112,488 | —- | C] () – C:\Users\Jeff\Documents\mexican theme birthday celebration.odt
[2011/01/01 15:41:26 | 000,029,265 | —- | C] () – C:\Users\Jeff\Documents\PBANN-00138.jpg
[2011/01/01 15:41:06 | 000,018,541 | —- | C] () – C:\Users\Jeff\Documents\happy-18th-banner-qa258.jpg
[2011/01/01 15:14:28 | 000,019,545 | —- | C] () – C:\Users\Jeff\Documents\18-today-its-party-time-banner-qa104.jpg
[2011/01/01 15:13:01 | 000,043,328 | —- | C] () – C:\Users\Jeff\Documents\Party.Pug.JPEG
[2011/01/01 15:12:04 | 000,017,118 | —- | C] () – C:\Users\Jeff\Documents\mexican0.jpg
[2011/01/01 15:10:15 | 000,068,826 | —- | C] () – C:\Users\Jeff\Documents\MexicanFiestaSupplies-MAIN.jpg
[2010/12/31 18:18:24 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\DVDneXtCOPY 4.lnk
[2010/12/31 18:07:18 | 000,005,276 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_v4_0_2_8_Crack_Latest__RH.torrent
[2010/12/31 18:06:59 | 000,005,471 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_Edition_v4_2_6_3___Patch__TrT_TcT_.torrent
[2010/12/31 17:54:00 | 000,000,664 | —- | C] () – C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_4_2_5_2____KeyGen___rar.torrent
[2010/12/31 17:16:16 | 001,178,319 | —- | C] () – C:\Users\Jeff\Documents\bitRipperSetup.exe
[2010/12/30 20:59:07 | 000,001,685 | —- | C] () – C:\Users\Jeff\Documents\msg0002.WAV
[2010/12/28 20:11:31 | 000,001,012 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2010/12/28 19:56:30 | 000,000,977 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2010/12/28 19:56:30 | 000,000,953 | —- | C] () – C:\Users\Jeff\Desktop\DVDFab 8.lnk
[2010/12/26 17:09:26 | 000,091,136 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_6_Complete_S06_S06E01_S06E17_S06E00_ADreaNaL.torrent
[2010/12/26 17:05:12 | 000,028,265 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E07_VOSTFR_HDTV_XViD_avi.torrent
[2010/12/26 17:04:39 | 000,014,560 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E06_ITA_HDTVMux_NovaRip__CR_Bt_.torrent
[2010/12/26 17:03:58 | 000,015,619 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E05_This_Place_Is_Death_PROPER_HDTV_XviD_FQM__rarbg_.torrent
[2010/12/26 17:03:34 | 000,014,717 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E05_HDTV_XviD___XOR.torrent
[2010/12/26 17:02:18 | 000,028,475 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E16_E17_The_Incident_HDTV_XviD_FQM.torrent
[2010/12/26 17:02:01 | 000,014,479 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E15_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:45 | 000,006,815 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E14_HDTV_XviD_NoTV.torrent
[2010/12/26 17:01:17 | 000,014,533 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E13_HDTV_XviD_NoTV_eztv.torrent
[2010/12/26 17:01:01 | 000,015,046 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E12_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 17:00:46 | 000,014,552 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E11_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:32 | 000,014,552 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E10_HDTV_XviD_XOR_eztv.torrent
[2010/12/26 17:00:07 | 000,014,760 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E09_HDTV_XviD_NoTV_avi.torrent
[2010/12/26 16:59:52 | 000,014,670 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E08_HDTV_XviD_XOR.torrent
[2010/12/26 16:57:22 | 000,027,658 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E04_VOSTFR_XviD_avi.torrent
[2010/12/26 16:56:44 | 000,015,262 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E03_HDTV_XviD_XOR__rarbg_com_.torrent
[2010/12/26 16:56:28 | 000,015,896 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E02_The_Lie_HDTV_XviD_2HD_avi.torrent
[2010/12/26 16:54:09 | 000,016,545 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_5__Episodes_1_7_.torrent
[2010/12/26 16:53:04 | 000,015,556 | —- | C] () – C:\Users\Jeff\Documents\Lost_S05E01_HDTV_XviD_PusherCrew_avi.torrent
[2010/12/26 16:30:50 | 000,030,080 | —- | C] () – C:\Users\Jeff\Documents\Lost_S04E02__HDTV_XviD_ENG___SUB_ENG_ITA_.torrent
[2010/12/26 16:29:39 | 000,028,370 | —- | C] () – C:\Users\Jeff\Documents\Lost_S04E01_HDTV_XviD_XOR__eztv_.torrent
[2010/12/26 16:28:49 | 000,025,984 | —- | C] () – C:\Users\Jeff\Documents\Lost_Season_4_S04E01to_S04E13_14_complete.torrent
[2010/12/26 15:38:27 | 000,000,000 | —- | C] () – C:\Users\Jeff\Documents\PDVD_MediaDisc.PlayList
[2010/12/26 15:06:04 | 000,001,989 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2010/12/26 13:31:06 | 000,001,942 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk
[2010/12/26 13:31:06 | 000,001,918 | —- | C] () – C:\Users\Jeff\Desktop\DVD Decrypter.lnk
[2010/12/26 13:30:34 | 000,899,414 | —- | C] () – C:\Users\Jeff\Documents\SetupDVDDecrypter_3.5.4.0.exe
[2010/12/26 05:32:03 | 000,014,992 | —- | C] () – C:\Users\Jeff\Documents\[Vegapunk]_One_Piece_321_330_HD.torrent
[2010/12/25 15:33:01 | 000,000,953 | —- | C] () – C:\Users\Jeff\Desktop\DVD Shrink 3.2.lnk
[2010/12/25 14:43:15 | 001,094,021 | —- | C] () – C:\Users\Jeff\Documents\dvdshrink32setup1.zip
[2010/12/24 17:04:51 | 001,528,276 | —- | C] () – C:\Users\Jeff\Documents\haruhi_christmas.jpg
[2010/12/24 17:01:18 | 000,074,865 | —- | C] () – C:\Users\Jeff\Documents\TAC_MerryChristmas2007.jpg
[2010/12/24 16:59:57 | 000,018,345 | —- | C] () – C:\Users\Jeff\Documents\images4.jpg
[2010/12/24 16:48:28 | 000,097,591 | —- | C] () – C:\Users\Jeff\Documents\okami-the-movie-20070112041935217.jpg
[2010/12/24 16:46:02 | 000,420,513 | —- | C] () – C:\Users\Jeff\Documents\Death_Note_Christmas_by_yuumei.jpg
[2010/12/24 14:57:44 | 000,001,009 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy DVD Shrink.lnk
[2010/12/24 14:57:44 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\Easy DVD Shrink.lnk
[2010/12/24 14:56:22 | 003,137,120 | —- | C] () – C:\Users\Jeff\Documents\EasyDVDShrink.exe
[2010/12/24 14:30:51 | 000,002,799 | —- | C] () – C:\Users\Jeff\Documents\BurnerSoft_Easy_DVD_Shrink_v3_0_24_WinAll_Cracked_PALACE.torrent
[2010/12/24 14:27:17 | 000,000,677 | —- | C] () – C:\Users\Jeff\Documents\Easy_DVD_Shrink_3_0_19___crack.torrent
[2010/12/21 02:05:10 | 000,027,381 | —- | C] () – C:\Users\Jeff\Documents\rob lucci 12.jpg
[2010/12/20 13:35:13 | 000,030,990 | —- | C] () – C:\Users\Jeff\Documents\New VM (4) - 018 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/20 13:35:02 | 000,024,565 | —- | C] () – C:\Users\Jeff\Documents\msg0003.WAV
[2010/12/19 11:43:44 | 000,026,245 | —- | C] () – C:\Users\Jeff\Documents\New VM (2) - 016 minutes in your magicJack mailbox from 5418466474.zip
[2010/12/19 00:07:40 | 000,160,095 | —- | C] () – C:\Users\Jeff\Documents\1292720334657.jpg
[2010/12/18 18:55:39 | 000,026,710 | —- | C] () – C:\Users\Jeff\Documents\msg0001.WAV
[2010/12/17 15:38:22 | 000,000,222 | —- | C] () – C:\Users\Jeff\Documents\payment debt owed in credit cards.rtf
[2010/12/16 16:09:26 | 000,001,024 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/12/16 16:06:34 | 019,985,265 | —- | C] () – C:\Users\Jeff\Documents\vlc-1.1.5-win32.exe
[2010/12/16 12:45:29 | 000,026,474 | —- | C] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___01__1280x720_h264___DABC2A44__mkv.torren
t
[2010/12/16 12:42:44 | 000,030,774 | —- | C] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 03 (1280x720 h264) [DA0E37C2].mkv.torrent
[2010/12/16 12:42:03 | 000,031,674 | —- | C] () – C:\Users\Jeff\Documents\[SS-Eclipse] Shakugan no Shana S - 04 (1280x720 h264) [C47036F2].mkv.torrent
[2010/12/16 12:41:22 | 000,018,625 | —- | C] () – C:\Users\Jeff\Documents\_SS_Eclipse__Shakugan_no_Shana_S___03__XviD___880C2A90__avi.torrent
[2010/12/16 12:41:00 | 000,032,430 | —- | C] () – C:\Users\Jeff\Documents\SS_Eclipse_Shakugan_no_Shana_S_02_1280x720_h264_29745873.torrent
[2010/11/29 22:39:04 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/10 13:16:12 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/07/18 15:23:50 | 000,000,017 | —- | C] () – C:\Users\Jeff\AppData\Local\resmon.resmoncfg
[2010/07/18 14:52:22 | 000,000,036 | —- | C] () – C:\Users\Jeff\AppData\Local\housecall.guid.cache
[2010/07/14 13:49:02 | 000,000,818 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/14 11:42:56 | 000,001,041 | —- | C] () – C:\Users\Jeff\AppData\Roaming\vso_ts_preview.xml
[2010/07/14 11:42:37 | 000,000,034 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.log
[2010/07/14 11:42:07 | 000,007,887 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.cat
[2010/07/14 11:42:07 | 000,001,144 | —- | C] () – C:\Users\Jeff\AppData\Roaming\pcouffin.inf
[2010/07/11 20:30:11 | 000,051,712 | —- | C] () – C:\Users\Jeff\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/23 12:59:34 | 000,059,924 | —- | C] () – C:\Windows\System32\libdvdcss-2.dll
[2009/12/20 11:05:52 | 000,086,016 | —- | C] () – C:\Windows\System32\Machinist2.dll
[2009/07/13 15:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2006/03/18 05:16:04 | 000,540,178 | —- | C] () – C:\Windows\System32\x264vfw.dll

========== LOP Check ==========

[2010/10/26 21:48:06 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Amazon
[2010/09/23 03:14:16 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Any Video Converter
[2010/07/24 13:42:42 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Auslogics
[2010/09/19 19:42:51 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\avidemux
[2010/12/10 12:31:51 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Bitmeter2
[2010/09/24 01:59:26 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\CometPlayer
[2010/12/29 03:07:09 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\DVDFab
[2010/07/28 12:38:45 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\KeePass
[2011/01/06 12:14:28 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Mal Updater
[2011/01/06 11:39:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\mjusbsp
[2010/07/14 11:52:45 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\OpenOffice.org
[2010/11/09 23:06:00 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PMS
[2011/01/05 17:05:32 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TigerPlayer
[2011/01/12 13:28:17 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\uTorrent
[2010/12/29 21:08:20 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Vso
[2010/11/15 22:26:07 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Windows Live Writer
[2009/07/13 20:53:46 | 000,012,432 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 191 bytes -> C:\ProgramData\TEMP:2CFDCA54
@Alternate Data Stream - 182 bytes -> C:\ProgramData\TEMP:6971CCC5
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:07BB519E

< End of report >
Jeff,

Keygens?? What kind of keygens. I don't use anything like that, i do use a p2p sharing software application, i can uninstall that for the time being i guess. But i dont think that is causing any complications on my machine as i have not downloaded anything new in quite a while and this problem only just surfaced like a few days ago once i copied that file to my C root drive.

By "quite a while" you apparently mean the last 10 days. You have a couple of obviously pirated programs (the last one installed on December 31), and several very suspicious ones. The following script will take out the obvious ones. Unforunately the infection may be in one of the suspicious ones. It appears that you've installed some infected codex files that have to do with burning DVD's (you have several). I just don't know which ones they are at this point. Hopefully they will rise to the surface as we continue.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:otl
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_v4_0_2_8_Crack_Latest__RH.torrent
C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_Edition_v4_2_6_3___Patch__TrT_TcT_.torrent
C:\Users\Jeff\Documents\DVD_neXt_COPY_neXt_Tech_4_2_5_2____KeyGen___rar.torrent
C:\Users\Jeff\Documents\dvdnextcopy_next_tech_setup.exe
C:\Users\Public\Desktop\Easy DVD Shrink.lnk
C:\Users\Jeff\Documents\EasyDVDShrink.exe
C:\Users\Jeff\Documents\BurnerSoft_Easy_DVD_Shrink_v3_0_24_WinAll_Cracked_PALACE.torrent
C:\Users\Jeff\Documents\Easy_DVD_Shrink_3_0_19___crack.torrent
C:\Users\Jeff\Desktop\[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4
C:\Users\Public\Desktop\DVDneXtCOPY 4.lnk

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Then:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

and finally (for now):

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    [AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Ok i am in trouble. I did everything you said, once the OTL finished its scan. It told me to reboot. So i rebooted and it posted a log. I forgot to save the log, the moment i copyed the log information. The explorer.exe file started refreshing every 5 seconds. (Just basically becoming non responsive every 3-5 seconds) so at that point there was nothing i could do but to reboot again. So what ever log i had, i lost it now. I don't' think it was OTL that caused this issue, i think it just had to do with when i rebooted my pc. Because it does it off and on like that. I tried rebooting into safe mode, didn't work, i tried "last known good configuration", didn't work. The only thing i know that works is if i restore my pc to another date such as 2 days ago, then it will actually work. Because ive done this 3 times already. Anyways im posting to you from another pc and await further instructions on what i must do. If you want me to restore my pc i can do that but that will reset all the settings that we made in the previous post. I am pretty sure that FFVII file is the cause of this and maybe perhaps we should of tried removing that first, anyways. I'll be waiting for a reply from you, but at the current state of my pc. I can't use it right now accept to go into windows recovery, but thats it.
ok, i got extremely lucky. After 6 reboots, it actually loaded with out the windows explorer.exe file refreshing, so i can post to you directly from my computer. Unfortunately i don't have the log file of OTL any more. But it did perform the tasks and the scan completed successfully. I am just very worried bout having to reboot again as that could cause the issue once again. Anyways, what do you want me to do now?
Oh yeah i almost forgot bout those two things you wanted me to do so here is both logs.



SystemLook 04.09.10 by jpshortstuff
Log created at 15:26 on 12/01/2011 by Jeff
Administrator - Elevation successful

========== filefind ==========

Searching for "[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4"
C:\Users\Jeff\Desktop\[AonE]_FFVII_Dirge_of_Cerberus_CG_Movies_[94988310][1200th_Release].mp4 –a—- 576200490 bytes [02:50 12/01/2011] [01:41 12/11/2010]









Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5508

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

1/12/2011 3:33:47 PM
mbam-log-2011-01-12 (15-33-47).txt

Scan type: Quick scan
Objects scanned: 148096
Time elapsed: 7 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I also will note that i tried "deleting" the file that system look found on my desktop and it will not delete. Not matter what task i perform i can not remove that file from my desktop or my external hard drive which was the original location before i copied it to my desktop.
Jeff,

I had you run systemlook to try to find the "address" of that file on your external hard drive. Unfortunately it didn't find it. neither did OTL succedd in removing the one on your desktop.

Can you provide the path to the file on your external drive?

Let's try a different tool. It will also reboot your system but hopefully will find (or at least indicate) what is causing the reboot problem.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Ok a few things before i run this. First how do i get a desired complete search path of my external hard drive. I am still learning the fundamentals of windows 7 and its a bit different then windows xp so im not exactly sure how to do that.

Second.

4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.

Will this be an issue for my problem since it has to do with trying to locate a file on one of my external hard drives which is connected via USB. Once i run this software, i wont have access to my hard drives.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI