*******************************
OTL
*******************************
OTL logfile created on: 09/02/2011 21:27:00 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Bloke\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
986.00 Mb Total Physical Memory | 131.00 Mb Available Physical Memory | 13.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 47.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 55.34 Gb Free Space | 41.19% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 8.82 Gb Free Space | 60.20% Space Free | Partition Type: NTFS
Computer Name: BLOKEANDBIRDSPC | User Name: Bloke | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/09 21:23:40 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Bloke\Desktop\OTL.exe
PRC - [2011/02/04 20:56:31 | 001,402,272 | โ- | M] (Lavasoft) โ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/02/04 20:56:31 | 000,936,712 | โ- | M] (Lavasoft) โ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/12/11 10:54:47 | 000,912,344 | โ- | M] (Mozilla Corporation) โ C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/12/06 15:04:56 | 000,086,016 | โ- | M] (alch) โ C:\Program Files\ClamWin\bin\ClamTray.exe
PRC - [2010/11/19 13:38:08 | 000,193,880 | โ- | M] (LeapFrog Enterprises, Inc.) โ C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2010/11/19 13:29:00 | 004,916,568 | โ- | M] (LeapFrog Enterprises, Inc.) โ C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | โ- | M] (Apple Inc.) โ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/05/14 10:00:26 | 000,249,136 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/11/13 16:15:00 | 001,807,600 | โ- | M] () โ C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/11/13 11:31:14 | 000,092,008 | โ- | M] (TomTom) โ C:\Users\Bloke\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/11/13 11:31:12 | 000,247,144 | โ- | M] (TomTom) โ C:\Users\Bloke\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2009/06/03 13:46:38 | 000,206,064 | โ- | M] (SupportSoft, Inc.) โ C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | โ- | M] (Microsoft Corporation) โ C:\Windows\explorer.exe
PRC - [2009/02/27 20:10:16 | 001,316,192 | โ- | M] (Stardock Corporation) โ C:\Program Files\Dell\DellDock\DellDock.exe
PRC - [2009/01/30 05:50:06 | 000,201,968 | โ- | M] (SupportSoft, Inc.) โ C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/01/09 17:06:32 | 001,735,760 | โ- | M] (Dell Inc.) โ C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2008/12/18 18:05:28 | 000,155,648 | โ- | M] (Stardock Corporation) โ C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/12/15 04:13:50 | 000,483,420 | โ- | M] (IDT, Inc.) โ C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/12/15 04:13:46 | 000,241,746 | โ- | M] (IDT, Inc.) โ C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe
PRC - [2008/12/15 04:13:30 | 000,081,920 | โ- | M] (Andrea Electronics Corporation) โ C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe
PRC - [2008/09/04 05:29:18 | 000,040,960 | โ- | M] (Alps Electric Co., Ltd.) โ C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/09/04 05:29:10 | 000,200,704 | โ- | M] (Alps Electric Co., Ltd.) โ C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/09/04 05:29:10 | 000,049,152 | โ- | M] (Alps Electric Co., Ltd.) โ C:\Program Files\DellTPad\ApntEx.exe
PRC - [2008/09/04 05:29:10 | 000,046,376 | โ- | M] (Alps Electric Co., Ltd.) โ C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/23 19:06:08 | 000,128,296 | โ- | M] (CyberLink Corp.) โ C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/05/07 22:41:14 | 000,354,840 | โ- | M] (Intel Corporation) โ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/05/07 22:41:12 | 000,178,712 | โ- | M] (Intel Corporation) โ C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/30 15:33:46 | 001,228,800 | โ- | M] () โ C:\Program Files\Nike+ Utility\Nike+ Utility.exe
PRC - [2008/01/21 02:33:00 | 001,008,184 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Windows Defender\MSASCui.exe
========== Modules (SafeList) ==========
MOD - [2011/02/09 21:23:40 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Bloke\Desktop\OTL.exe
MOD - [2010/08/31 15:43:52 | 001,686,016 | โ- | M] (Microsoft Corporation) โ C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/02/04 20:56:31 | 001,402,272 | โ- | M] (Lavasoft) [Auto | Running] โ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe โ (Lavasoft Ad-Aware Service)
SRV - [2010/11/19 13:29:00 | 004,916,568 | โ- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] โ C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe โ (LeapFrog Connect Device Service)
SRV - [2010/06/10 20:03:08 | 000,144,176 | โ- | M] (Apple Inc.) [Auto | Running] โ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe โ (Apple Mobile Device)
SRV - [2010/05/14 10:00:26 | 000,249,136 | โ- | M] (Microsoft Corporation) [Auto | Running] โ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe โ (SeaPort)
SRV - [2010/03/18 12:16:28 | 000,753,504 | โ- | M] (Microsoft Corporation) [On_Demand | Stopped] โ C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe โ (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | โ- | M] (Microsoft Corporation) [Auto | Stopped] โ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe โ (clr_optimization_v4.0.30319_32)
SRV - [2009/11/13 11:31:14 | 000,092,008 | โ- | M] (TomTom) [Auto | Running] โ C:\Users\Bloke\TomTom HOME 2\TomTomHOMEService.exe โ (TomTomHOMEService)
SRV - [2009/09/25 01:27:04 | 000,793,088 | โ- | M] (Microsoft Corporation) [On_Demand | Stopped] โ C:\Windows\System32\FntCache.dll โ (FontCache)
SRV - [2009/05/09 15:49:17 | 000,016,680 | โ- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] โ C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe โ (GoToAssist)
SRV - [2009/01/30 05:50:06 | 000,201,968 | โ- | M] (SupportSoft, Inc.) [Auto | Running] โ C:\Program Files\Dell Support Center\bin\sprtsvc.exe โ (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2008/12/18 18:05:28 | 000,155,648 | โ- | M] (Stardock Corporation) [Auto | Running] โ C:\Program Files\Dell\DellDock\DockLogin.exe โ (DockLoginService)
SRV - [2008/12/15 04:13:46 | 000,241,746 | โ- | M] (IDT, Inc.) [Auto | Running] โ C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe โ (STacSV)
SRV - [2008/12/15 04:13:30 | 000,081,920 | โ- | M] (Andrea Electronics Corporation) [Auto | Running] โ C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe โ (AESTFilters)
SRV - [2008/05/07 22:41:14 | 000,354,840 | โ- | M] (Intel Corporation) [Auto | Running] โ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe โ (IAANTMON) Intelยฎ
SRV - [2008/01/21 02:33:00 | 000,272,952 | โ- | M] (Microsoft Corporation) [Auto | Running] โ C:\Program Files\Windows Defender\MpSvc.dll โ (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2010/12/03 09:05:34 | 000,064,288 | โ- | M] (Lavasoft AB) [File_System | Boot | Running] โ C:\Windows\system32\DRIVERS\Lbd.sys โ (Lbd)
DRV - [2010/12/03 09:05:33 | 000,015,264 | โ- | M] () [Kernel | On_Demand | Stopped] โ C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys โ (Lavasoft Kernexplorer)
DRV - [2008/12/22 10:32:18 | 000,018,424 | โ- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\bcm42rly.sys โ (BCM42RLY)
DRV - [2008/12/17 08:56:50 | 001,331,192 | โ- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\BCMWL6.SYS โ (BCM43XX)
DRV - [2008/12/15 04:13:54 | 000,393,216 | โ- | M] (IDT, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\stwrt.sys โ (STHDA)
DRV - [2008/12/09 05:25:14 | 002,473,472 | โ- | M] (Intel Corporation) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\igdkmd32.sys โ (igfx)
DRV - [2008/12/08 05:32:50 | 000,062,976 | โ- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\RTSTOR.sys โ (RTSTOR)
DRV - [2008/11/04 23:16:40 | 000,022,904 | โ- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] โ C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms โ (PCD5SRVC{3F6A8B78-EC003E00-05040104})
DRV - [2008/09/04 05:29:08 | 000,170,032 | โ- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\Apfiltr.sys โ (ApfiltrService)
DRV - [2008/09/01 10:19:40 | 000,304,128 | โ- | M] (Marvell) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\yk60x86.sys โ (yukonwlh)
DRV - [2008/09/01 10:15:54 | 000,317,976 | โ- | M] (Intel Corporation) [Kernel | Boot | Running] โ C:\Windows\system32\drivers\iastor.sys โ (iaStor)
DRV - [2008/04/01 13:33:16 | 000,019,456 | โ- | M] (LeapFrog) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\FlyUsb.sys โ (FlyUsb)
DRV - [2008/01/21 02:32:53 | 000,149,560 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpu320.sys โ (adpu320)
DRV - [2008/01/21 02:32:53 | 000,031,288 | โ- | M] (LSI Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\megasas.sys โ (megasas)
DRV - [2008/01/21 02:32:52 | 000,386,616 | โ- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\megasr.sys โ (MegaSR)
DRV - [2008/01/21 02:32:52 | 000,101,432 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpu160m.sys โ (adpu160m)
DRV - [2008/01/21 02:32:52 | 000,074,808 | โ- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sisraid4.sys โ (SiSRaid4)
DRV - [2008/01/21 02:32:52 | 000,040,504 | โ- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\hpcisss.sys โ (HpCISSs)
DRV - [2008/01/21 02:32:51 | 000,300,600 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpahci.sys โ (adpahci)
DRV - [2008/01/21 02:32:51 | 000,220,672 | โ- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\e1e6032.sys โ (e1express) Intelยฎ
DRV - [2008/01/21 02:32:51 | 000,089,656 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_sas.sys โ (LSI_SAS)
DRV - [2008/01/21 02:32:50 | 001,122,360 | โ- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ql2300.sys โ (ql2300)
DRV - [2008/01/21 02:32:50 | 000,118,784 | โ- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\E1G60I32.sys โ (E1G60) Intelยฎ
DRV - [2008/01/21 02:32:50 | 000,079,928 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\arcsas.sys โ (arcsas)
DRV - [2008/01/21 02:32:49 | 000,235,064 | โ- | M] (Intel Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iastorv.sys โ (iaStorV)
DRV - [2008/01/21 02:32:49 | 000,130,616 | โ- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\vsmraid.sys โ (vsmraid)
DRV - [2008/01/21 02:32:49 | 000,115,816 | โ- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ulsata2.sys โ (ulsata2)
DRV - [2008/01/21 02:32:49 | 000,096,312 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_fc.sys โ (LSI_FC)
DRV - [2008/01/21 02:32:49 | 000,079,416 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\arc.sys โ (arc)
DRV - [2008/01/21 02:32:48 | 000,342,584 | โ- | M] (Emulex) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\elxstor.sys โ (elxstor)
DRV - [2008/01/21 02:32:48 | 000,096,312 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_scsi.sys โ (LSI_SCSI)
DRV - [2008/01/21 02:32:47 | 000,102,968 | โ- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nvraid.sys โ (nvraid)
DRV - [2008/01/21 02:32:47 | 000,045,112 | โ- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nvstor.sys โ (nvstor)
DRV - [2008/01/21 02:32:46 | 000,422,968 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adp94xx.sys โ (adp94xx)
DRV - [2008/01/21 02:32:45 | 000,238,648 | โ- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\uliahci.sys โ (uliahci)
DRV - [2008/01/21 02:32:21 | 000,020,024 | โ- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\viaide.sys โ (viaide)
DRV - [2008/01/21 02:32:21 | 000,019,000 | โ- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\cmdide.sys โ (cmdide)
DRV - [2008/01/21 02:32:21 | 000,017,464 | โ- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\aliide.sys โ (aliide)
DRV - [2006/11/02 09:50:35 | 000,106,088 | โ- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ql40xx.sys โ (ql40xx)
DRV - [2006/11/02 09:50:35 | 000,098,408 | โ- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ulsata.sys โ (UlSata)
DRV - [2006/11/02 09:50:19 | 000,045,160 | โ- | M] (IBM Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nfrd960.sys โ (nfrd960)
DRV - [2006/11/02 09:50:17 | 000,041,576 | โ- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iirsp.sys โ (iirsp)
DRV - [2006/11/02 09:50:11 | 000,071,272 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\djsvs.sys โ (aic78xx)
DRV - [2006/11/02 09:50:09 | 000,035,944 | โ- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iteraid.sys โ (iteraid)
DRV - [2006/11/02 09:50:07 | 000,035,944 | โ- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iteatapi.sys โ (iteatapi)
DRV - [2006/11/02 09:50:05 | 000,035,944 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\symc8xx.sys โ (Symc8xx)
DRV - [2006/11/02 09:50:03 | 000,034,920 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sym_u3.sys โ (Sym_u3)
DRV - [2006/11/02 09:49:59 | 000,033,384 | โ- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\mraid35x.sys โ (Mraid35x)
DRV - [2006/11/02 09:49:56 | 000,031,848 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sym_hi.sys โ (Sym_hi)
DRV - [2006/11/02 08:25:24 | 000,071,808 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brserid.sys โ (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 08:24:47 | 000,011,904 | โ- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brusbser.sys โ (BrUsbSer)
DRV - [2006/11/02 08:24:46 | 000,005,248 | โ- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brfiltup.sys โ (BrFiltUp)
DRV - [2006/11/02 08:24:45 | 000,013,568 | โ- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brfiltlo.sys โ (BrFiltLo)
DRV - [2006/11/02 08:24:44 | 000,062,336 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brserwdm.sys โ (BrSerWdm)
DRV - [2006/11/02 08:24:44 | 000,012,160 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brusbmdm.sys โ (BrUsbMdm)
DRV - [2006/11/02 07:36:50 | 000,020,608 | โ- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ntrigdigi.sys โ (ntrigdigi)
DRV - [2006/11/02 07:36:43 | 002,028,032 | โ- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\atikmdag.sys โ (R300)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.11.0.15286
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src;=kw&tb;=CLA&o;=15310&locale;=en_UK&apn;_uid=B6484064-7265-4541-ADAF-7D5EFC56ED3C&apn;_ptnrs=J4&apn;_sauid=F566DDE2-D2B6-4C76-B542-9AAD15C8F3FE&apn;_dtid=&q;="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 10:54:52 | 000,000,000 | โD | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/11 10:54:52 | 000,000,000 | โD | M]
[2010/02/13 12:00:59 | 000,000,000 | โD | M] (No name found) โ C:\Users\Bloke\AppData\Roaming\Mozilla\Extensions
[2010/02/13 12:00:59 | 000,000,000 | โD | M] (No name found) โ C:\Users\Bloke\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/02/05 07:51:58 | 000,000,000 | โD | M] (No name found) โ C:\Users\Bloke\AppData\Roaming\Mozilla\Firefox\Profiles\y3zx1b1a.default\extensions
[2010/04/28 19:10:37 | 000,000,000 | โD | M] (Microsoft .NET Framework Assistant) โ C:\Users\Bloke\AppData\Roaming\Mozilla\Firefox\Profiles\y3zx1b1a.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/26 22:05:35 | 000,000,000 | โD | M] (Ask Toolbar) โ C:\Users\Bloke\AppData\Roaming\Mozilla\Firefox\Profiles\y3zx1b1a.default\extensions\[removed]
[2011/02/09 21:20:39 | 000,002,560 | โ- | M] () โ C:\Users\Bloke\AppData\Roaming\Mozilla\Firefox\Profiles\y3zx1b1a.default\searchplugins\askcom.xml
[2009/05/16 15:36:47 | 000,000,000 | โD | M] (No name found) โ C:\Program Files\Mozilla Firefox\extensions
[2010/03/14 11:59:31 | 000,001,538 | โ- | M] () โ C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/14 11:59:31 | 000,000,947 | โ- | M] () โ C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/03/14 11:59:31 | 000,000,769 | โ- | M] () โ C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/03/14 11:59:31 | 000,001,135 | โ- | M] () โ C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2006/09/18 21:41:30 | 000,000,761 | โ- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Javaโข Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ClamWin] C:\Program Files\ClamWin\bin\ClamTray.exe (alch)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [Nokia FastStart] File not found
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Users\Bloke\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Users\Bloke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Bloke\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Bloke\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | โ- | M] () - C:\autoexec.bat โ [ NTFS ]
O33 - MountPoints2\{8c42404b-1892-11df-8c78-0023ae332766}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ "%1" %*
O35 - HKLM\..exefile [open] โ "%1" %*
O37 - HKLM\โฆcom [@ = comfile] โ "%1" %*
O37 - HKLM\โฆexe [@ = exefile] โ "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/02/09 21:23:03 | 000,602,624 | โ- | C] (OldTimer Tools) โ C:\Users\Bloke\Desktop\OTL.exe
[2011/02/05 08:11:31 | 000,000,000 | โD | C] โ C:\Users\Bloke\AppData\Roaming\Reviversoft
[2011/02/05 08:11:13 | 000,016,704 | โ- | C] (ReviverSoft) โ C:\Windows\System32\roboot.exe
[2011/02/04 20:56:53 | 000,064,288 | โ- | C] (Lavasoft AB) โ C:\Windows\System32\drivers\Lbd.sys
[2011/02/04 20:52:16 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/02/04 20:50:53 | 000,000,000 | โD | C] โ C:\Program Files\Google
[2011/02/04 20:50:52 | 000,000,000 | โD | C] โ C:\Users\Bloke\AppData\Local\Google
[2011/02/04 20:50:43 | 000,000,000 | -H-D | C] โ C:\ProgramData\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2011/02/04 20:50:02 | 000,000,000 | โD | C] โ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/02/04 20:50:02 | 000,000,000 | โD | C] โ C:\Program Files\Lavasoft
[2011/02/04 13:47:03 | 000,000,000 | โD | C] โ C:\Users\Bloke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool
[2009/06/24 16:32:58 | 008,653,312 | โ- | C] (Dell, Inc. ) โ C:\Users\Bloke\AppData\Roaming\DataSafeDotNet.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/09 21:26:43 | 000,000,878 | โ- | M] () โ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/09 21:23:40 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Bloke\Desktop\OTL.exe
[2011/02/09 21:20:19 | 000,000,882 | โ- | M] () โ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/09 21:20:16 | 000,003,616 | -Hโ | M] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 21:20:16 | 000,003,616 | -Hโ | M] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 21:19:50 | 000,067,584 | โS- | M] () โ C:\Windows\bootstat.dat
[2011/02/06 13:54:58 | 1034,276,864 | -HS- | M] () โ C:\hiberfil.sys
[2011/02/05 09:00:41 | 000,359,929 | โ- | M] () โ C:\Users\Bloke\Desktop\dds.scr
[2011/02/05 01:37:23 | 000,000,036 | โ- | M] () โ C:\Users\Bloke\AppData\Local\housecall.guid.cache
[2011/02/04 20:52:16 | 000,001,973 | โ- | M] () โ C:\Users\Public\Desktop\Google Chrome.lnk
[2011/02/04 20:52:16 | 000,001,957 | โ- | M] () โ C:\Users\Bloke\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/04 20:50:40 | 000,001,033 | โ- | M] () โ C:\Users\Bloke\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/02/04 20:50:39 | 000,001,009 | โ- | M] () โ C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/01/26 07:02:01 | 000,609,196 | โ- | M] () โ C:\Windows\System32\perfh009.dat
[2011/01/26 07:02:01 | 000,108,672 | โ- | M] () โ C:\Windows\System32\perfc009.dat
[2011/01/25 05:46:36 | 000,000,680 | โ- | M] () โ C:\Users\Bloke\AppData\Local\d3d9caps.dat
[2011/01/22 15:33:44 | 000,016,704 | โ- | M] (ReviverSoft) โ C:\Windows\System32\roboot.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/05 09:00:04 | 000,359,929 | โ- | C] () โ C:\Users\Bloke\Desktop\dds.scr
[2011/02/05 01:37:23 | 000,000,036 | โ- | C] () โ C:\Users\Bloke\AppData\Local\housecall.guid.cache
[2011/02/04 20:52:16 | 000,001,973 | โ- | C] () โ C:\Users\Public\Desktop\Google Chrome.lnk
[2011/02/04 20:52:16 | 000,001,957 | โ- | C] () โ C:\Users\Bloke\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/04 20:51:08 | 000,000,882 | โ- | C] () โ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/04 20:51:05 | 000,000,878 | โ- | C] () โ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/04 20:50:40 | 000,001,033 | โ- | C] () โ C:\Users\Bloke\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/02/04 20:50:39 | 000,001,009 | โ- | C] () โ C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/02/04 20:20:42 | 1034,276,864 | -HS- | C] () โ C:\hiberfil.sys
[2010/04/27 17:28:45 | 000,024,064 | โ- | C] () โ C:\Users\Bloke\AppData\Roaming\UserTile.png
[2009/10/20 22:35:24 | 000,117,248 | โ- | C] () โ C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 14:07:42 | 000,403,816 | โ- | C] () โ C:\Windows\System32\OGACheckControl.dll
[2009/06/13 21:18:07 | 000,000,680 | โ- | C] () โ C:\Users\Bloke\AppData\Local\d3d9caps.dat
[2009/06/03 12:02:52 | 000,018,432 | โ- | C] () โ C:\Users\Bloke\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/16 17:52:11 | 000,000,108 | โ- | C] () โ C:\Users\Bloke\AppData\Roaming\wklnhst.dat
[2009/05/16 16:48:36 | 000,000,552 | โ- | C] () โ C:\Users\Bloke\AppData\Local\d3d8caps.dat
[2009/05/09 18:15:55 | 000,147,456 | โ- | C] () โ C:\Windows\System32\igfxCoIn_v1576.dll
[2009/05/09 15:37:40 | 000,054,784 | โ- | C] () โ C:\Windows\System32\bcmwlrmt.dll
[2009/05/09 15:37:40 | 000,006,656 | โ- | C] () โ C:\Windows\System32\bcmwlrc.dll
[2008/12/11 11:27:24 | 000,165,321 | โ- | C] () โ C:\Users\Bloke\AppData\Roaming\com.kennettnet.MusicRescue4.Profiles.plist
[2008/12/11 10:53:22 | 001,776,688 | โ- | C] () โ C:\Users\Bloke\AppData\Roaming\com.kennettnet.MusicRescue4.plist
[2006/11/02 10:25:44 | 000,159,744 | โ- | C] () โ C:\Windows\System32\atitmmxx.dll
[2006/11/02 07:40:29 | 000,013,750 | โ- | C] () โ C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2009/05/17 23:16:23 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/06/25 21:06:24 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\Nokia
[2009/06/25 21:09:33 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\PC Suite
[2011/02/05 08:11:31 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\Reviversoft
[2010/08/08 17:35:15 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\Template
[2010/02/13 12:00:55 | 000,000,000 | โD | M] โ C:\Users\Bloke\AppData\Roaming\TomTom
[2011/02/06 01:45:33 | 000,032,644 | โ- | M] () โ C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\*. /mp /s >
< End of report >
*******************************
Extras
*******************************
OTL Extras logfile created on: 09/02/2011 21:27:00 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Bloke\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
986.00 Mb Total Physical Memory | 131.00 Mb Available Physical Memory | 13.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 47.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134.36 Gb Total Space | 55.34 Gb Free Space | 41.19% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 8.82 Gb Free Space | 60.20% Space Free | Partition Type: NTFS
Computer Name: BLOKEANDBIRDSPC | User Name: Bloke | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] โ C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] โ C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ "%1" %*
cmdfile [open] โ "%1" %*
comfile [open] โ "%1" %*
cplfile [cplopen] โ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ "%1" %*
helpfile [open] โ Reg Error: Key error.
hlpfile [open] โ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile โ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] โ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ "%1" (Google Inc.)
https [open] โ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ "%1" (Google Inc.)
inffile [install] โ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] โ "%1" %*
regfile [merge] โ Reg Error: Key error.
scrfile [config] โ "%1"
scrfile [install] โ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ "%1" /S
txtfile โ Reg Error: Key error.
Unknown [openas] โ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] โ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type โ File not found
"VistaSp2" = Reg Error: Unknown registry data type โ File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{043165F3-B6B7-4FB0-91A8-F31193C8B6A5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{103E9466-CCAA-42F6-B2E4-09691E9DB9F7}" = lport=137 | protocol=17 | dir=in | app=system |
"{26BEB0A7-02AF-4A90-8DB5-3630450978AD}" = rport=138 | protocol=17 | dir=out | app=system |
"{33086BBF-F7A9-41BF-B49D-966C1A36D235}" = rport=445 | protocol=6 | dir=out | app=system |
"{3A12D838-7EB0-40B4-BAE9-DFDF12999D09}" = rport=139 | protocol=6 | dir=out | app=system |
"{5B7FB9AE-003F-4DB5-91BD-B7B08F351CE4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{63E6E204-1376-404A-B83B-D3283ACE2A25}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BCDE3074-38E7-4049-B85F-77846882EBF0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C6F42FC4-07E7-4EC5-ABEB-774F4C29A6B5}" = lport=139 | protocol=6 | dir=in | app=system |
"{CD21FB55-3EEE-4D07-BACC-D3C14A9ED349}" = rport=137 | protocol=17 | dir=out | app=system |
"{E0A1D05E-816F-42EA-8021-A8F9D64DEA96}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E259A2E3-D218-4A8A-9DA7-53C7432BE5F2}" = lport=445 | protocol=6 | dir=in | app=system |
"{F120DCF9-7ECE-431A-9D58-30A1B6DA15F2}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0312DED9-9CC1-4065-AD5D-8E0D37C2CA80}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1644A0C4-9D88-488A-AF51-371420B2E92C}" = protocol=17 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{22B29C90-EFEF-4E9A-BD13-8D6ABF9EF0E0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2E240F14-9F5D-4E61-804E-191D12F0ABED}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{30B79699-B568-4B13-AA99-EB27FD93B0EC}" = protocol=6 | dir=in | app=c:\program files\dell video chat\dellvideochat.exe |
"{4DB2E09F-4BC0-4D4A-BF05-B0983FCBFA75}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{4EED6B29-D4A0-457E-B06A-BBF1F1CDF211}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{7A11C9A9-E9BF-450B-9403-49D69ED6CA8D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{806D429E-01A0-481A-986C-6870B7A4DFA0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{832F3B09-DFD4-49B2-96AE-C1AF52FBC259}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8A8FA171-13E4-4208-B126-0B3E87A45BC6}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{915D1CC0-771F-4410-A924-BD9EEDA242C8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B89F5782-3318-477E-8869-162C0E0474D9}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{D25132F6-15CF-4115-92D7-D8C6C9A10793}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{D5AED29D-692A-4CD0-B1C3-A9B67B33EE55}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{D7570C0F-A1BB-4FEA-96F9-2A8A28145C52}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E52FAA94-90E4-438B-B7AD-47136E3F8584}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E7FB3648-411E-461F-A1AC-96460918C1C4}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{EBB03539-A035-4B98-ABD7-1873AA23BB0B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{EE2E4B5E-3F46-4A08-A1D0-DC0C39C7771D}" = dir=in | app=c:\program files\leapfrog\leapfrog connect\leapfrogconnect.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Javaโข 6 Update 11
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{309C137D-66B4-491B-9D21-F03892DAFD93}" = Nike+ Utility
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3364BD16-5A28-4862-86A1-A8FF5FD23919}" = Music Rescue
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51F96AEC-D902-4434-A0DC-B9692A21AE7C}" = MobileMe Control Panel
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intelยฎ Matrix Storage Manager
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A67BB21E-D419-45BB-AB86-7D87D14BBCE2}" = Safari
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C4972073-2BFE-475D-8441-564EA97DA161}" = QuickSet
"{C6359569-E03E-4CDC-98E8-CDD080C6EEB5}" = LeapFrog Connect
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E51FFEFB-68E2-4516-B293-35DC83B9767E}" = LeapFrog Tag Plugin
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"ClamWin Free Antivirus_is1" = ClamWin Free Antivirus 0.96.5
"Dell Video Chat" = Dell Video Chat
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"TomTom HOME" = TomTom HOME 2.7.3.1894
"UPCShell" = LeapFrog Connect
"WinLiveSuite_Wave3" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 28/01/2011 18:04:00 | Computer Name = Blokeandbirdspc | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 56661170
Error - 30/01/2011 11:02:45 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 30/01/2011 13:02:09 | Computer Name = Blokeandbirdspc | Source = Bonjour Service | ID = 100
Description = 376: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 30/01/2011 16:01:41 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 31/01/2011 01:40:26 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 02/02/2011 17:23:50 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 04/02/2011 02:33:53 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 04/02/2011 09:13:28 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
Error - 04/02/2011 09:45:20 | Computer Name = Blokeandbirdspc | Source = VSS | ID = 8194
Description =
Error - 04/02/2011 09:50:33 | Computer Name = Blokeandbirdspc | Source = WinMgmt | ID = 10
Description =
[ Broadcom Wireless LAN Events ]
Error - 15/12/2010 16:10:06 | Computer Name = Blokeandbirdspc | Source = WLAN-Tray | ID = 0
Description = 20:10:06, Wed, Dec 15, 10 Error - Unable to gain access to user store
[ System Events ]
Error - 05/02/2011 13:09:42 | Computer Name = Blokeandbirdspc | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 05/02/2011 13:09:55 | Computer Name = Blokeandbirdspc | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 00242C8C8CBB has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Error - 05/02/2011 13:10:03 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7000
Description =
Error - 05/02/2011 13:10:03 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7000
Description =
Error - 06/02/2011 09:54:55 | Computer Name = Blokeandbirdspc | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 06/02/2011 09:55:07 | Computer Name = Blokeandbirdspc | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 00242C8C8CBB has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Error - 06/02/2011 09:55:13 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7000
Description =
Error - 06/02/2011 09:55:13 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7000
Description =
Error - 09/02/2011 17:21:13 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7022
Description =
Error - 09/02/2011 17:27:30 | Computer Name = Blokeandbirdspc | Source = Service Control Manager | ID = 7022
Description =
< End of report >
*******************************
Report
*******************************
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #1
==============================================
>Drivers
==============================================
0x89602000 C:\Windows\system32\DRIVERS\igdkmd32.sys 7315456 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x81C39000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x81C39000 PnpManager 3903488 bytes
0x81C39000 RAW 3903488 bytes
0x81C39000 WMIxWDM 3903488 bytes
0x91CE0000 Win32k 2109440 bytes
0x91CE0000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8A08D000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1343488 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)
0x86204000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)
0x85E04000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x86002000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804DD000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0xA5EDB000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x86107000 C:\Windows\System32\Drivers\dump_iaStor.sys 851968 bytes
0x82207000 C:\Windows\system32\drivers\iastor.sys 851968 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0xA5E03000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x89CFC000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8A000000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x80609000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x82331000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x80413000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0xA5005000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8A69A000 C:\Windows\system32\DRIVERS\stwrt.sys 409600 bytes (IDT, Inc., IDT PC Audio)
0xA5176000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x85F75000 C:\Windows\system32\DRIVERS\yk60x86.sys 315392 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)
0x8073B000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x8AA0D000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x80692000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x8049C000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x80795000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x89DB4000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x8AABE000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x85F3A000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0xA50FD000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x86314000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8A654000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x81C06000 ACPI_HAL 208896 bytes
0x81C06000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x822D7000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x8AA55000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x823A2000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x85FC2000 C:\Windows\system32\DRIVERS\Apfiltr.sys 184320 bytes (Alps Electric Co., Ltd., Alps Touch Pad Driver)
0x8A6FE000 C:\Windows\system32\DRIVERS\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x85F0F000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8A613000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0x8AB71000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0xA5EB3000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0xA514E000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x86364000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x806E9000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x8A72B000 C:\Windows\system32\DRIVERS\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x807D6000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x8639C000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0xA50BD000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x8A773000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0xA50DE000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xA5072000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x860EC000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x8AB56000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0xA508F000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x861D7000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xA5136000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x8AB04000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x823D1000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xA5FD7000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x8AA87000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x8A7C6000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0xA50A8000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x805E0000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x805CC000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x8A7DC000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8A1D5000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0x8ABA5000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8AB1B000 C:\Windows\system32\drivers\RTSTOR.SYS 77824 bytes (Realtek Semiconductor Corp., Realtek USB Mass Storage Driver for Vista)
0x8AAAB000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x8638B000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x8A689000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x80483000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x82309000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x8ABC8000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x80785000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8A601000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x861EF000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x82319000 C:\Windows\system32\DRIVERS\Lbd.sys 61440 bytes (Lavasoft AB, Boot Driver)
0x8AB47000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x86355000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x80710000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x805BD000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x863E7000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x8072C000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x91F20000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x8AA9D000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8A7AF000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x8AB30000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x8A647000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x80685000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0xA5FC3000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x8A767000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x89D9D000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x8A1F3000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0x8A1E8000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x8A7A4000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x823E8000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x85FEF000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x863D3000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x89DA9000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x80722000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x8AB3D000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x8A63D000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x8AB9B000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8AAFA000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0xA5FB9000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x863BD000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x8A750000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0xA5FF1000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x82328000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0x8A7BD000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x91F00000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x863DE000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x863F6000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806D8000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xA5FCF000 C:\Windows\system32\drivers\BCM42RLY.sys 32768 bytes (Broadcom Corporation, Broadcom iLine10โข PCI Network Adapter Proxy Protocol Driver)
0x80494000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x806E1000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8A794000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8A79C000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8634D000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8A760000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x8040C000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x8A759000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x89DF2000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0x89DF8000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xA5FED000 C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms 16384 bytes (PC-Doctor, Inc., Kernel Driver)
0x8071F000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x8A611000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8AB2E000 C:\Windows\system32\drivers\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
==============================================
>Stealth
==============================================
0x03D50000 Hidden Imageโ>msvcm90.dll [ EPROCESS 0xA3B50D90 ] PID: 1572, 270336 bytes
0x02270000 Hidden Imageโ>msvcm90.dll [ EPROCESS 0x84DD76D8 ] PID: 3472, 270336 bytes
0x01D40000 Hidden Imageโ>SupportSoft.Agent.Sprocket.dll [ EPROCESS 0x84DFA3D8 ] PID: 3568, 28672 bytes
0x05BC0000 Hidden Imageโ>WLTRAY.EXE [ EPROCESS 0xA3B50D90 ] PID: 1572, 4231168 bytes
0x01B60000 Hidden Imageโ>SupportSoft.Agent.Sprocket.SupportMessage.dll [ EPROCESS 0x84DFA3D8 ] PID: 3568, 45056 bytes
0x041C0000 Hidden Imageโ>bcmwlrmt.dll [ EPROCESS 0xA3B50D90 ] PID: 1572, 77824 bytes
0x022E0000 Hidden Imageโ>bcmwlrmt.dll [ EPROCESS 0x84DD76D8 ] PID: 3472, 77824 bytes
0x007F0000 Hidden Imageโ>sprtmessage.dll [ EPROCESS 0x84DFA3D8 ] PID: 3568, 77824 bytes