This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search qu infected

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

. DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 7:46:51.50 on Wed 04/27/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.2450 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\vcsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Program Files\DigitalPersona\Bin\DpHostW.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\IDT\WDM\AESTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\DigitalPersona\Bin\DPAgent.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\explorer.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\gbourdon\Desktop\dds.com C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/home?AF=18707 uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: CescrtHlpr Object: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\ToolBar\searchqudtx.dll BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\ToolBar\searchqudtx.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarTlbr.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" uRun: [Google Update] "C:\Users\gbourdon\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [DATAMNGR] C:\PROGRA~2\WI3C8A~1\Datamngr\DATAMN~1.EXE mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [BabylonToolbar] "C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exe" /md I StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAPFI~1.LNK - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll LSA: Notification Packages = DPPassFilter scecli mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: UrlHelper Class: {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background mRun-x64: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey AppInit_DLLs-X64: C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll STS-X64: FencesShlExt Class: {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences Pro\FencesMenu64.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=18707 FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406 FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=406&q= FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll FF - plugin: C:\Users\gbourdon\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Users\gbourdon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll FF - plugin: C:\Users\gbourdon\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-10-24 188928] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-10-25 89600] R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-7-21 103992] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2010-8-5 681528] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2010-6-15 30520] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-9-28 26680] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344] R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-25 2533400] R2 vcsFPService;Validity VCS Fingerprint Service;C:\Windows\System32\vcsFPService.exe [2010-2-23 2192176] R3 clwvd;HP Webcam Splitter;C:\Windows\System32\drivers\clwvd.sys [2010-9-3 31088] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-5-1 56344] R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-6-21 287232] R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-10-24 40832] R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 72064] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-10-25 232992] S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-10-25 344680] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-4-18 1255736] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] . =============== Created Last 30 ================ . 2011-04-27 02:29:34 8802128 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{BDDC7B90-FA92-4FFA-9DAC-D192D5A15378}\mpengine.dll 2011-04-23 23:32:19 ——– d—–w- C:\Program Files\Babylon 2011-04-23 23:32:19 ——– d—–w- C:\Program Files (x86)\Babylon 2011-04-23 23:32:12 ——– d—–w- C:\Program Files (x86)\BabylonToolbar 2011-04-23 23:32:10 ——– d—–w- C:\Program Files (x86)\Yontoo Layers 2011-04-23 23:32:10 ——– d—–w- C:\PROGRA~3\Tarma Installer 2011-04-23 23:32:02 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\WinPump 2011-04-23 18:20:32 ——– d—–w- C:\Users\gbourdon\AppData\Local\Adobe 2011-04-23 16:54:10 ——– d—–w- C:\Users\gbourdon\AppData\Local\Apple Computer 2011-04-23 16:54:01 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2011-04-23 16:54:01 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll 2011-04-23 16:54:01 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2011-04-23 16:52:39 ——– d—–w- C:\Users\gbourdon\AppData\Local\Apple 2011-04-23 16:52:21 ——– d—–w- C:\Program Files\Bonjour 2011-04-23 16:52:21 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-04-23 16:47:49 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\playitall 2011-04-23 16:33:38 ——– d—–w- C:\Program Files (x86)\PlayItAll 2011-04-23 16:26:56 11776 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll 2011-04-23 16:26:49 ——– d—–w- C:\Program Files (x86)\Common Files\xing shared 2011-04-23 16:26:43 150712 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll 2011-04-23 16:26:41 105472 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll 2011-04-23 16:24:34 ——– d—–w- C:\Users\gbourdon\AppData\Local\Ares 2011-04-23 16:18:25 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\WhiteSmoke 2011-04-23 16:17:58 ——– d—–w- C:\Program Files (x86)\WhiteSmoke 2011-04-23 15:54:34 ——– d—–w- C:\Users\gbourdon\AppData\Local\Ilivid Player 2011-04-23 15:53:54 ——– dc-h–w- C:\PROGRA~3\{6A6F35C2-F1BB-455A-85C0-F522DF746DDA} 2011-04-23 15:53:44 ——– d—–w- C:\Program Files (x86)\iLivid 2011-04-23 15:53:27 ——– d—–w- C:\Program Files (x86)\Windows iLivid Toolbar 2011-04-23 15:53:12 ——– d—–w- C:\Users\gbourdon\AppData\Local\PackageAware 2011-04-22 13:46:46 ——– d—–w- C:\Users\gbourdon\AppData\Local\CrashDumps 2011-04-22 00:20:11 ——– d—–w- C:\PROGRA~3\{23D58E70-3B83-4B83-A227-68770F84F5EC} 2011-04-21 13:03:25 16856 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 2011-04-21 13:03:24 719832 —-a-w- C:\Program Files (x86)\Mozilla Firefox\mozcpp19.dll 2011-04-19 01:14:03 ——– d—–w- C:\Users\gbourdon\AppData\Local\Google 2011-04-18 12:20:16 ——– d—–w- C:\Windows\SysWow64\Wat 2011-04-18 12:20:16 ——– d—–w- C:\Windows\System32\Wat 2011-04-18 01:53:31 367104 —-a-w- C:\Windows\System32\wcncsvc.dll 2011-04-18 01:53:31 276992 —-a-w- C:\Windows\SysWow64\wcncsvc.dll 2011-04-18 01:49:14 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-04-18 01:47:25 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll 2011-04-18 01:47:25 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll 2011-04-18 01:47:25 444752 —-a-w- C:\Windows\System32\mscoree.dll 2011-04-18 01:47:25 320352 —-a-w- C:\Windows\System32\PresentationHost.exe 2011-04-18 01:47:25 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll 2011-04-18 01:47:25 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe 2011-04-18 01:47:25 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll 2011-04-18 01:47:25 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll 2011-04-18 01:47:24 48960 —-a-w- C:\Windows\System32\netfxperf.dll 2011-04-18 01:47:24 1942856 —-a-w- C:\Windows\System32\dfshim.dll 2011-04-17 17:22:06 8802128 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-17 17:21:47 ——– d—–w- C:\Users\gbourdon\AppData\Local\Mozilla 2011-04-17 17:21:12 ——– d—–w- C:\Users\gbourdon\AppData\Local\Ahead 2011-04-16 21:36:00 552376 —-a-w- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe 2011-04-16 21:31:55 714752 —-a-w- C:\Windows\System32\kerberos.dll 2011-04-16 21:30:59 461312 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-04-16 21:25:07 ——– d—–w- C:\Program Files (x86)\Nero 2011-04-16 21:25:07 ——– d—–w- C:\PROGRA~3\Nero 2011-04-16 21:25:02 1197056 —-a-w- C:\Windows\System32\wininet.dll 2011-04-16 21:20:42 720896 —-a-w- C:\Windows\System32\odbc32.dll 2011-04-16 21:20:42 573440 —-a-w- C:\Windows\SysWow64\odbc32.dll 2011-04-16 21:20:42 495616 —-a-w- C:\Program Files\Common Files\System\ado\msadox.dll 2011-04-16 21:20:42 466944 —-a-w- C:\Program Files\Common Files\System\ado\msadomd.dll 2011-04-16 21:20:42 1425408 —-a-w- C:\Program Files\Common Files\System\ado\msado15.dll 2011-04-16 21:20:41 987136 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll 2011-04-16 21:20:41 372736 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll 2011-04-16 21:20:41 352256 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll 2011-04-16 21:20:41 258048 —-a-w- C:\Program Files\Common Files\System\msadc\msadco.dll 2011-04-16 21:20:41 208896 —-a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll 2011-04-16 21:18:00 601424 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{631EF800-EA02-4905-9737-D285DB90DC7D}\gapaengine.dll 2011-04-16 21:13:50 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2011-04-16 21:13:45 ——– d—–w- C:\Program Files\Microsoft Security Client 2011-04-16 21:13:35 374664 —-a-w- C:\Windows\System32\drivers\netio.sys 2011-04-16 20:54:17 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio 8 2011-04-16 20:53:49 ——– d—–w- C:\Windows\SHELLNEW 2011-04-16 20:53:28 ——– d—–w- C:\Users\gbourdon\AppData\Local\Microsoft Help 2011-04-14 01:16:07 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared 2011-04-14 00:41:44 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\PictureMover 2011-04-14 00:40:27 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\Stardock 2011-04-14 00:39:53 ——– d—–w- C:\Users\gbourdon\AppData\Local\VirtualStore 2011-04-14 00:39:38 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\hpqlog 2011-04-14 00:39:31 ——– d—–w- C:\Users\gbourdon\AppData\Local\RemEngine 2011-04-14 00:36:44 ——– d—–w- C:\Users\gbourdon\AppData\Local\Hewlett-Packard 2011-04-14 00:36:30 ——– d—–w- C:\Users\gbourdon\AppData\Local\Hewlett-Packard_Company 2011-04-14 00:35:20 ——– d—–w- C:\Users\gbourdon\AppData\Roaming\DigitalPersona 2011-04-14 00:35:20 ——– d—–w- C:\Users\gbourdon\AppData\Local\DigitalPersona 2011-04-06 20:26:58 96544 —-a-w- C:\Windows\System32\dnssd.dll 2011-04-06 20:26:58 69408 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-04-06 20:26:58 237856 —-a-w- C:\Windows\System32\dnssdX.dll 2011-04-06 20:26:58 119584 —-a-w- C:\Windows\System32\dns-sd.exe 2011-04-06 20:20:16 91424 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-04-06 20:20:16 75040 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-04-06 20:20:16 197920 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-04-06 20:20:16 107808 —-a-w- C:\Windows\SysWow64\dns-sd.exe . ==================== Find3M ==================== . 2011-04-23 16:26:38 348160 —-a-w- C:\Windows\SysWow64\msvcr71.dll 2011-04-23 16:26:37 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll 2011-03-11 06:19:26 1395712 —-a-w- C:\Windows\System32\mfc42.dll 2011-03-11 06:19:26 1359872 —-a-w- C:\Windows\System32\mfc42u.dll 2011-03-11 05:40:24 1164288 —-a-w- C:\Windows\SysWow64\mfc42u.dll 2011-03-11 05:40:24 1137664 —-a-w- C:\Windows\SysWow64\mfc42.dll 2011-03-08 06:14:30 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-03-08 05:38:13 740864 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-03-03 06:17:10 182272 —-a-w- C:\Windows\System32\dnsrslvr.dll 2011-03-03 06:14:38 30208 —-a-w- C:\Windows\System32\dnscacheugc.exe 2011-03-03 05:27:30 28672 —-a-w- C:\Windows\SysWow64\dnscacheugc.exe 2011-03-03 03:58:32 3133440 —-a-w- C:\Windows\System32\win32k.sys 2011-02-24 06:30:00 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-02-24 06:24:57 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2011-02-24 05:32:52 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-02-24 05:32:44 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-02-24 05:30:16 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2011-02-24 05:05:13 482816 —-a-w- C:\Windows\System32\html.iec 2011-02-24 04:24:04 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-02-24 04:23:48 386048 —-a-w- C:\Windows\SysWow64\html.iec 2011-02-24 03:50:26 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-02-23 05:16:01 401920 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-02-23 05:15:50 161792 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-02-23 05:15:27 157696 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-02-23 05:15:14 286720 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-02-23 05:15:13 126464 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-02-23 05:15:06 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-02-19 06:36:13 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-02-19 05:32:08 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-02-19 04:13:39 367104 —-a-w- C:\Windows\System32\atmfd.dll 2011-02-19 03:37:02 294912 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-02-18 06:37:05 612352 —-a-w- C:\Windows\System32\vbscript.dll 2011-02-18 05:36:26 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll 2011-02-12 06:14:41 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2011-02-05 12:41:43 556928 —-a-w- C:\Windows\System32\winresume.efi 2011-02-05 12:41:35 640896 —-a-w- C:\Windows\System32\winload.efi 2011-02-05 12:41:24 20352 —-a-w- C:\Windows\System32\kdusb.dll 2011-02-05 12:41:24 19328 —-a-w- C:\Windows\System32\kd1394.dll 2011-02-05 12:41:23 17792 —-a-w- C:\Windows\System32\kdcom.dll 2011-02-05 12:39:21 603976 —-a-w- C:\Windows\System32\winload.exe 2011-02-05 12:39:21 518160 —-a-w- C:\Windows\System32\winresume.exe . ============= FINISH: 7:47:41.45 ===============
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

I'm currently reviewing your log and will be back with you shortly.
P2P - I see you have P2P software ( Ares ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.




DDS is a diagnostic tool that lets me get a look at what we are dealing with. Now, I'd like to get another scan with the tool we'll be using to fix this problem.
OTL Custom Scan

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


After I take a look at the results, we'll see if we can't get this taken care of for you :)
OTL logfile created on: 4/27/2011 12:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\gbourdon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 268.85 Gb Total Space | 199.61 Gb Free Space | 74.25% Space Free | Partition Type: NTFS
Drive D: | 28.95 Gb Total Space | 4.25 Gb Free Space | 14.68% Space Free | Partition Type: NTFS

Computer Name: GBOURDON-HP | User Name: gbourdon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gbourdon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\gbourdon\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Users\gbourdon\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=18707"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 05:13:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2010/10/25 05:14:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/25 05:14:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/10/25 05:14:40 | 000,000,000 | —D | M]

[2011/04/23 11:53:36 | 000,000,000 | —D | M] (No name found) – C:\Users\gbourdon\AppData\Roaming\Mozilla\Extensions
[2011/04/26 22:27:36 | 000,000,000 | —D | M] (No name found) – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\extensions
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml
[2011/04/27 09:42:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/04/23 19:32:10 | 000,002,226 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKCU..\Run: [ares] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.200.0.3
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files\Stardock\Fences Pro\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/27 12:13:19 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\gbourdon\Desktop\OTL.exe
[2011/04/27 10:16:05 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/04/27 10:16:05 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/04/27 10:16:05 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/04/27 10:15:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/04/27 10:15:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/04/27 10:15:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/04/27 10:13:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/04/27 10:13:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/04/27 10:13:05 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/04/27 10:13:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/04/27 10:12:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/04/27 09:47:15 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/27 09:26:14 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/04/27 07:50:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Windows Live Writer
[2011/04/27 07:50:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Windows Live Writer
[2011/04/23 19:32:19 | 000,000,000 | —D | C] – C:\Program Files\Babylon
[2011/04/23 19:32:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Babylon
[2011/04/23 19:32:02 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WinPump
[2011/04/23 14:20:32 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Adobe
[2011/04/23 13:02:58 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WinRAR
[2011/04/23 12:54:10 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Apple Computer
[2011/04/23 12:54:10 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Apple Computer
[2011/04/23 12:54:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/23 12:54:00 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011/04/23 12:53:27 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/04/23 12:52:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/23 12:52:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/04/23 12:52:46 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/04/23 12:52:39 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Apple
[2011/04/23 12:52:15 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/04/23 12:47:49 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\vlc
[2011/04/23 12:47:49 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\playitall
[2011/04/23 12:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/04/23 12:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/04/23 12:24:34 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ares
[2011/04/23 12:23:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Real
[2011/04/23 12:18:25 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WhiteSmoke
[2011/04/23 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\WhiteSmoke
[2011/04/23 11:54:34 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ilivid Player
[2011/04/23 11:53:54 | 000,000,000 | -H-D | C] – C:\ProgramData\~0
[2011/04/23 11:53:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/04/23 11:53:12 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\PackageAware
[2011/04/22 09:46:46 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\CrashDumps
[2011/04/21 20:20:11 | 000,000,000 | —D | C] – C:\ProgramData\{23D58E70-3B83-4B83-A227-68770F84F5EC}
[2011/04/18 21:14:03 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Google
[2011/04/18 08:20:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/04/18 08:20:16 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/04/17 21:49:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2011/04/17 21:47:25 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/04/17 21:47:25 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/04/17 21:47:25 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/04/17 21:47:25 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/04/17 21:47:25 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/04/17 21:47:25 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/04/17 21:47:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/04/17 21:47:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/04/17 13:21:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Mozilla
[2011/04/17 13:21:46 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Mozilla
[2011/04/17 13:21:12 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ahead
[2011/04/16 17:35:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/04/16 17:31:36 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/04/16 17:31:36 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/04/16 17:31:35 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/04/16 17:31:35 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/04/16 17:31:34 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/04/16 17:31:34 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/04/16 17:31:34 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/04/16 17:31:34 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/04/16 17:31:31 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/04/16 17:31:31 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/04/16 17:31:31 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/04/16 17:31:31 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/04/16 17:31:31 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/04/16 17:31:31 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/04/16 17:31:31 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/04/16 17:31:30 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/04/16 17:31:26 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/04/16 17:31:26 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/04/16 17:31:26 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/04/16 17:31:19 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/04/16 17:31:19 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/04/16 17:31:16 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/04/16 17:31:16 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/04/16 17:31:15 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/04/16 17:31:10 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/04/16 17:31:10 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/04/16 17:31:09 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/04/16 17:31:08 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/04/16 17:31:08 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/04/16 17:31:08 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/04/16 17:31:08 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/04/16 17:31:08 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/04/16 17:31:01 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/04/16 17:31:01 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/04/16 17:31:00 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/04/16 17:31:00 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/04/16 17:30:54 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/04/16 17:30:54 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/04/16 17:30:52 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/04/16 17:30:52 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/04/16 17:30:51 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/04/16 17:30:51 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/04/16 17:30:49 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/04/16 17:30:49 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/04/16 17:30:48 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/04/16 17:30:48 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/04/16 17:30:48 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/04/16 17:30:48 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/04/16 17:30:48 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/04/16 17:30:47 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/04/16 17:30:47 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/04/16 17:30:46 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/04/16 17:30:46 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/04/16 17:30:46 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/04/16 17:30:46 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/04/16 17:30:46 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/04/16 17:30:46 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/04/16 17:30:46 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/04/16 17:30:46 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/04/16 17:30:44 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/04/16 17:30:44 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/04/16 17:28:41 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/04/16 17:28:40 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/04/16 17:28:40 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/04/16 17:28:31 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/04/16 17:28:30 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/04/16 17:28:30 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/04/16 17:28:30 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/04/16 17:28:15 | 000,640,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2011/04/16 17:28:15 | 000,603,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2011/04/16 17:28:15 | 000,518,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2011/04/16 17:28:15 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2011/04/16 17:28:15 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2011/04/16 17:28:15 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2011/04/16 17:28:14 | 000,556,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2011/04/16 17:28:09 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/04/16 17:28:09 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/04/16 17:28:08 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/04/16 17:28:08 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/04/16 17:28:07 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/04/16 17:27:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition
[2011/04/16 17:26:57 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Ahead
[2011/04/16 17:26:41 | 000,000,000 | —D | C] – C:\ProgramData\Ahead
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nero
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Ahead
[2011/04/16 17:24:55 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/04/16 17:24:54 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/04/16 17:24:54 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/04/16 17:24:54 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/04/16 17:24:52 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/04/16 17:24:52 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/04/16 17:24:51 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/04/16 17:24:50 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/04/16 17:24:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/04/16 17:24:50 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/04/16 17:24:49 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/04/16 17:24:49 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/04/16 17:24:49 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/04/16 17:24:49 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/04/16 17:24:37 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/04/16 17:24:29 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/04/16 17:23:37 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2011/04/16 17:23:37 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2011/04/16 17:20:42 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/04/16 17:20:42 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/04/16 17:15:52 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/04/16 17:15:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/04/16 17:15:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/04/16 17:13:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/04/16 17:13:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/04/16 17:13:35 | 000,374,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2011/04/16 16:58:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/04/16 16:56:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/04/16 16:56:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/04/16 16:56:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/04/16 16:56:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/04/16 16:54:21 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/04/16 16:54:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2011/04/16 16:53:49 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2011/04/16 16:53:28 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Microsoft Help
[2011/04/16 16:53:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/04/16 16:53:07 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/04/16 07:17:21 | 000,000,000 | —D | C] – C:\Users\gbourdon\Desktop\greg
[2011/04/13 21:16:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2011/04/13 20:41:57 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Adobe
[2011/04/13 20:41:44 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\PictureMover
[2011/04/13 20:40:27 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Stardock
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Searches
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/04/13 20:40:06 | 000,000,000 | -H-D | C] – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/04/13 20:39:59 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Identities
[2011/04/13 20:39:55 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Contacts
[2011/04/13 20:39:53 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\VirtualStore
[2011/04/13 20:39:38 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\hpqlog
[2011/04/13 20:39:31 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\RemEngine
[2011/04/13 20:36:53 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Hewlett-Packard
[2011/04/13 20:36:44 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Hewlett-Packard
[2011/04/13 20:36:30 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Hewlett-Packard_Company
[2011/04/13 20:35:20 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\DigitalPersona
[2011/04/13 20:35:20 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\DigitalPersona
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\Temporary Internet Files
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Templates
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Start Menu
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\SendTo
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Recent
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\PrintHood
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\NetHood
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Videos
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Pictures
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Music
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\My Documents
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Local Settings
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\History
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Cookies
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Application Data
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\Application Data
[2011/04/13 20:34:47 | 000,000,000 | –SD | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Videos
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Saved Games
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Pictures
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Music
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Links
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Favorites
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Downloads
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\My Documents
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Desktop
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/04/13 20:34:47 | 000,000,000 | -H-D | C] – C:\Users\gbourdon\AppData
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Temp
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Microsoft
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Media Center Programs
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Macromedia
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\HuluDesktop
[2011/04/06 16:26:58 | 000,237,856 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dnssdX.dll
[2011/04/06 16:26:58 | 000,119,584 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dns-sd.exe
[2011/04/06 16:26:58 | 000,096,544 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dnssd.dll
[2011/04/06 16:26:58 | 000,069,408 | —- | C] (Apple Inc.) – C:\Windows\SysNative\jdns_sd.dll
[2011/04/06 16:20:16 | 000,197,920 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\jdns_sd.dll

========== Files - Modified Within 30 Days ==========

[2011/04/27 12:19:00 | 000,000,920 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000UA.job
[2011/04/27 12:13:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\gbourdon\Desktop\OTL.exe
[2011/04/27 12:09:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/27 10:16:09 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/04/27 10:14:14 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/27 09:36:09 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 09:36:09 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 09:35:57 | 000,002,289 | —- | M] () – C:\Users\gbourdon\Desktop\Google Chrome.lnk
[2011/04/27 09:28:06 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2011/04/26 22:28:04 | 000,729,688 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/26 22:28:04 | 000,626,278 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/04/26 22:28:04 | 000,107,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/04/25 12:58:10 | 000,279,283 | —- | M] () – C:\Users\gbourdon\Desktop\Confirmation.xps
[2011/04/23 21:19:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000Core.job
[2011/04/22 09:18:40 | 000,000,344 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForgbourdon.job
[2011/04/22 09:18:34 | 000,424,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/04/16 17:27:25 | 000,002,766 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/04/16 17:27:25 | 000,002,666 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/04/16 17:15:06 | 000,002,154 | —- | M] () – C:\Windows\epplauncher.mif
[2011/04/16 17:13:52 | 000,731,106 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/16 16:58:47 | 000,002,693 | —- | M] () – C:\Users\gbourdon\Desktop\Microsoft Office Word 2007.lnk
[2011/04/16 16:51:34 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/04/13 20:43:27 | 000,002,962 | —- | M] () – C:\Users\gbourdon\Desktop\Skype.lnk
[2011/04/13 20:41:47 | 000,001,437 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/13 19:31:46 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/04/13 19:31:46 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/04/06 16:26:58 | 000,237,856 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dnssdX.dll
[2011/04/06 16:26:58 | 000,119,584 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dns-sd.exe
[2011/04/06 16:26:58 | 000,096,544 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dnssd.dll
[2011/04/06 16:26:58 | 000,069,408 | —- | M] (Apple Inc.) – C:\Windows\SysNative\jdns_sd.dll
[2011/04/06 16:20:16 | 000,197,920 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\jdns_sd.dll

========== Files Created - No Company Name ==========

[2011/04/27 10:16:09 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/04/27 10:14:14 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/27 10:13:42 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/27 09:26:17 | 000,002,289 | —- | C] () – C:\Users\gbourdon\Desktop\Google Chrome.lnk
[2011/04/25 12:58:08 | 000,279,283 | —- | C] () – C:\Users\gbourdon\Desktop\Confirmation.xps
[2011/04/21 21:35:36 | 000,000,344 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForgbourdon.job
[2011/04/18 21:14:04 | 000,000,920 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000UA.job
[2011/04/18 21:14:04 | 000,000,868 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000Core.job
[2011/04/16 17:27:25 | 000,002,766 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/04/16 17:27:25 | 000,002,666 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/04/16 17:15:06 | 000,002,154 | —- | C] () – C:\Windows\epplauncher.mif
[2011/04/16 17:13:52 | 000,731,106 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/16 17:13:47 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/04/16 16:58:47 | 000,002,693 | —- | C] () – C:\Users\gbourdon\Desktop\Microsoft Office Word 2007.lnk
[2011/04/16 16:51:34 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/04/13 20:43:27 | 000,002,962 | —- | C] () – C:\Users\gbourdon\Desktop\Skype.lnk
[2011/04/13 20:41:47 | 000,001,437 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/13 20:40:14 | 000,001,409 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/04/13 20:40:08 | 000,001,443 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/04/13 20:36:35 | 000,002,278 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
[2011/04/13 20:36:35 | 000,002,272 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk
[2011/04/13 20:36:35 | 000,002,196 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish.lnk
[2011/04/13 20:34:47 | 000,001,974 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hulu Desktop.lnk
[2011/04/13 20:34:47 | 000,000,290 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/04/13 20:34:47 | 000,000,272 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/10/25 04:38:00 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 04:38:00 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 11:35:25 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 13:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 18:08:44 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 18:08:42 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 18:08:40 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 17:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 17:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 001,498,564 | —- | C] () – C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/04/13 20:35:20 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\DigitalPersona
[2011/04/13 20:41:45 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\PictureMover
[2011/04/23 12:47:49 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\playitall
[2011/04/13 20:40:27 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\Stardock
[2011/04/26 22:23:46 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\WhiteSmoke
[2011/04/27 07:50:19 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\Windows Live Writer
[2011/04/23 19:32:10 | 000,000,000 | —D | M] – C:\Users\gbourdon\AppData\Roaming\WinPump
[2009/07/14 01:08:49 | 000,008,382 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/04/27 09:28:06 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2011/04/27 09:28:10 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/13 20:41:47 | 000,000,221 | -HS- | M] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/04/27 12:13:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\gbourdon\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
OTL Extras logfile created on: 4/27/2011 12:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\gbourdon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 268.85 Gb Total Space | 199.61 Gb Free Space | 74.25% Space Free | Partition Type: NTFS
Drive D: | 28.95 Gb Total Space | 4.25 Gb Free Space | 14.68% Space Free | Partition Type: NTFS

Computer Name: GBOURDON-HP | User Name: gbourdon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{09BDCC02-80F2-4EFB-8F1B-A807D2C38E31}" = HP MediaSmart Movies and TV
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences Pro
"{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant
"{16DDB3D1-5C27-4599-9C63-E583287191CC}" = iTunes
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java™ 6 Update 21 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{426FAE9F-7373-496E-A215-9DB7EF4398CF}" = Validity Sensors DDK
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BE6725F2-6D15-477C-86C6-4522B8569D62}" = HP MediaSmart SmartMenu
"{C84FFB07-C687-45CF-91C8-868DB8D8C8CD}" = HP 3D DriveGuard
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{E77543EE-6FB5-4FF6-AB70-635392C8C756}" = Microsoft Security Client
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08DB3902-2CE0-474D-BCE3-0177766CE9F1}" = HP Support Assistant
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{264FE20A-757B-492a-B0C3-4009E2997D8A}" = PictureMover
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D1193CC-0658-4C98-B1FF-86CBC5BFB27C}" = HP Documentation
"{504CC891-B140-4E1B-860B-5E4C1DFBA9E3}" = Blio
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6B114F59-6732-4EA5-A33E-ACC6DEC49B61}" = HP Software Framework
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{705B639E-FAAF-40D7-AD58-C445321C7C3F}" = LightScribe System Software
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FA2E0CF-64E8-3536-BA71-618A48D9AF55}" = Google Talk Plugin
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.3.3 MUI
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{AF306BD8-F9D1-4627-89B9-246E59074A05}" = HP Power Manager
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EF682D1C-591D-48B5-9803-628DA622C281}" = HP Quick Launch
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Fences Pro" = Fences Pro
"HP DVB-T TV Tuner" = HP DVB-T TV Tuner 8.0.64.43
"HP Photo Creations" = HP Photo Creations
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"My HP Game Console" = HP Game Console
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"ZumoDrive" = HP CloudDrive

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
"WinPump" = WinPump

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/16/2011 5:13:24 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 4/16/2011 5:13:24 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 4/16/2011 5:13:24 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 4/16/2011 5:23:21 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 4/16/2011 5:23:21 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 4/16/2011 5:23:21 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 4/16/2011 5:24:02 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 4/16/2011 5:24:02 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 4/16/2011 5:24:02 PM | Computer Name = gbourdon-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

[ HP Wireless Assistant Events ]
Error - 4/15/2011 8:35:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:36:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:37:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:38:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:39:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:40:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:41:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:42:25 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:43:26 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/15/2011 8:44:26 AM | Computer Name = gbourdon-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

[ System Events ]
Error - 4/15/2011 4:19:53 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7001
Description = The IP Helper service depends on the Network Store Interface Service
service which failed to start because of the following error: %%1068

Error - 4/15/2011 4:19:53 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7001
Description = The SMB MiniRedirector Wrapper and Engine service depends on the Redirected
Buffering Sub Sysytem service which failed to start because of the following error:
%%31

Error - 4/15/2011 4:19:53 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7001
Description = The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector
Wrapper and Engine service which failed to start because of the following error:
%%1068

Error - 4/15/2011 4:19:53 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7001
Description = The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector
Wrapper and Engine service which failed to start because of the following error:
%%1068

Error - 4/15/2011 4:19:53 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7001
Description = The Network Location Awareness service depends on the Network Store
Interface Service service which failed to start because of the following error:
%%1068

Error - 4/15/2011 4:19:55 PM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD BHDrvx64 DfsC discache eeCtrl IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX
SymIRON
SymNetS
tdx
vwififlt
Wanarpv6
WfpLwf

Error - 4/16/2011 5:03:57 PM | Computer Name = gbourdon-HP | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR3.

Error - 4/16/2011 5:17:35 PM | Computer Name = gbourdon-HP | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.

Feature:
%%886 Error Code: 0x8007042c Error description: The dependency service or group failed
to start. Reason: %%892

Error - 4/18/2011 8:22:42 AM | Computer Name = gbourdon-HP | Source = Service Control Manager | ID = 7023
Description = The Windows Modules Installer service terminated with the following
error: %%16405

Error - 4/18/2011 2:05:53 PM | Computer Name = gbourdon-HP | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:46:17 PM on ?4/?18/?2011 was unexpected.


< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
    [2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml
    [2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
    O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
    O4 - HKLM..\RunOnce: [removeSearchqutoolbar]  File not found
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log please.

Also, can you please tell me how the system is running now?
OTL logfile created on: 4/27/2011 6:08:59 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\gbourdon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 268.85 Gb Total Space | 199.33 Gb Free Space | 74.14% Space Free | Partition Type: NTFS
Drive D: | 28.95 Gb Total Space | 4.25 Gb Free Space | 14.68% Space Free | Partition Type: NTFS

Computer Name: GBOURDON-HP | User Name: gbourdon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gbourdon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\gbourdon\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Users\gbourdon\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=18707"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 05:13:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2010/10/25 05:14:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/25 05:14:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/10/25 05:14:40 | 000,000,000 | —D | M]

[2011/04/23 11:53:36 | 000,000,000 | —D | M] (No name found) – C:\Users\gbourdon\AppData\Roaming\Mozilla\Extensions
[2011/04/26 22:27:36 | 000,000,000 | —D | M] (No name found) – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\extensions
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml
[2011/04/27 09:42:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/04/23 19:32:10 | 000,002,226 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKCU..\Run: [ares] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files\Stardock\Fences Pro\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

[CREATERESTOREPOINT]
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/27 12:13:19 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\gbourdon\Desktop\OTL.exe
[2011/04/27 10:16:05 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/04/27 10:16:05 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/04/27 10:16:05 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/04/27 10:15:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/04/27 10:15:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/04/27 10:15:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/04/27 10:13:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/04/27 10:13:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/04/27 10:13:05 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/04/27 10:13:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/04/27 10:12:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/04/27 09:47:15 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/27 09:26:14 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/04/27 07:50:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Windows Live Writer
[2011/04/27 07:50:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Windows Live Writer
[2011/04/23 19:32:19 | 000,000,000 | —D | C] – C:\Program Files\Babylon
[2011/04/23 19:32:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Babylon
[2011/04/23 19:32:02 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WinPump
[2011/04/23 14:20:32 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Adobe
[2011/04/23 13:02:58 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WinRAR
[2011/04/23 12:54:10 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Apple Computer
[2011/04/23 12:54:10 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Apple Computer
[2011/04/23 12:54:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/23 12:54:00 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011/04/23 12:53:27 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/04/23 12:52:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/04/23 12:52:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/04/23 12:52:46 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/04/23 12:52:39 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Apple
[2011/04/23 12:52:15 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/04/23 12:47:49 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\vlc
[2011/04/23 12:47:49 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\playitall
[2011/04/23 12:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/04/23 12:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/04/23 12:24:34 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ares
[2011/04/23 12:23:19 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Real
[2011/04/23 12:18:25 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\WhiteSmoke
[2011/04/23 12:17:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\WhiteSmoke
[2011/04/23 11:54:34 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ilivid Player
[2011/04/23 11:53:54 | 000,000,000 | -H-D | C] – C:\ProgramData\~0
[2011/04/23 11:53:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/04/23 11:53:12 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\PackageAware
[2011/04/22 09:46:46 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\CrashDumps
[2011/04/21 20:20:11 | 000,000,000 | —D | C] – C:\ProgramData\{23D58E70-3B83-4B83-A227-68770F84F5EC}
[2011/04/18 21:14:03 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Google
[2011/04/18 08:20:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/04/18 08:20:16 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/04/17 21:49:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2011/04/17 21:47:25 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/04/17 21:47:25 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/04/17 21:47:25 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/04/17 21:47:25 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/04/17 21:47:25 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/04/17 21:47:25 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/04/17 21:47:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/04/17 21:47:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/04/17 13:21:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Mozilla
[2011/04/17 13:21:46 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Mozilla
[2011/04/17 13:21:12 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Ahead
[2011/04/16 17:35:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/04/16 17:31:36 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/04/16 17:31:36 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/04/16 17:31:35 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/04/16 17:31:35 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/04/16 17:31:34 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/04/16 17:31:34 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/04/16 17:31:34 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/04/16 17:31:34 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/04/16 17:31:31 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/04/16 17:31:31 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/04/16 17:31:31 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/04/16 17:31:31 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/04/16 17:31:31 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/04/16 17:31:31 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/04/16 17:31:31 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/04/16 17:31:30 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/04/16 17:31:26 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/04/16 17:31:26 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/04/16 17:31:26 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/04/16 17:31:19 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/04/16 17:31:19 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/04/16 17:31:16 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/04/16 17:31:16 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/04/16 17:31:15 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/04/16 17:31:10 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/04/16 17:31:10 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/04/16 17:31:09 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/04/16 17:31:08 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/04/16 17:31:08 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/04/16 17:31:08 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/04/16 17:31:08 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/04/16 17:31:08 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/04/16 17:31:01 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/04/16 17:31:01 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/04/16 17:31:00 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/04/16 17:31:00 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/04/16 17:30:54 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/04/16 17:30:54 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/04/16 17:30:52 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/04/16 17:30:52 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/04/16 17:30:51 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/04/16 17:30:51 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/04/16 17:30:49 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/04/16 17:30:49 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/04/16 17:30:48 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/04/16 17:30:48 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/04/16 17:30:48 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/04/16 17:30:48 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/04/16 17:30:48 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/04/16 17:30:47 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/04/16 17:30:47 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/04/16 17:30:46 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/04/16 17:30:46 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/04/16 17:30:46 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/04/16 17:30:46 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/04/16 17:30:46 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/04/16 17:30:46 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/04/16 17:30:46 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/04/16 17:30:46 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/04/16 17:30:44 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/04/16 17:30:44 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/04/16 17:28:41 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/04/16 17:28:40 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/04/16 17:28:40 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/04/16 17:28:31 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/04/16 17:28:30 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/04/16 17:28:30 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/04/16 17:28:30 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/04/16 17:28:15 | 000,640,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2011/04/16 17:28:15 | 000,603,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2011/04/16 17:28:15 | 000,518,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2011/04/16 17:28:15 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2011/04/16 17:28:15 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2011/04/16 17:28:15 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2011/04/16 17:28:14 | 000,556,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2011/04/16 17:28:09 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/04/16 17:28:09 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/04/16 17:28:08 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/04/16 17:28:08 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/04/16 17:28:07 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/04/16 17:27:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition
[2011/04/16 17:26:57 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Ahead
[2011/04/16 17:26:41 | 000,000,000 | —D | C] – C:\ProgramData\Ahead
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nero
[2011/04/16 17:25:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Ahead
[2011/04/16 17:24:55 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/04/16 17:24:54 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/04/16 17:24:54 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/04/16 17:24:54 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/04/16 17:24:52 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/04/16 17:24:52 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/04/16 17:24:51 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/04/16 17:24:50 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/04/16 17:24:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/04/16 17:24:50 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/04/16 17:24:49 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/04/16 17:24:49 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/04/16 17:24:49 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/04/16 17:24:49 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/04/16 17:24:37 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/04/16 17:24:29 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/04/16 17:23:37 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2011/04/16 17:23:37 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2011/04/16 17:20:42 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/04/16 17:20:42 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/04/16 17:15:52 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/04/16 17:15:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/04/16 17:15:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/04/16 17:13:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/04/16 17:13:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/04/16 17:13:35 | 000,374,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2011/04/16 16:58:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/04/16 16:56:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/04/16 16:56:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/04/16 16:56:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/04/16 16:56:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/04/16 16:54:21 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/04/16 16:54:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2011/04/16 16:53:49 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2011/04/16 16:53:28 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Microsoft Help
[2011/04/16 16:53:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/04/16 16:53:07 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/04/16 07:17:21 | 000,000,000 | —D | C] – C:\Users\gbourdon\Desktop\greg
[2011/04/13 21:16:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2011/04/13 20:41:57 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Adobe
[2011/04/13 20:41:44 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\PictureMover
[2011/04/13 20:40:27 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Stardock
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Searches
[2011/04/13 20:40:07 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/04/13 20:40:06 | 000,000,000 | -H-D | C] – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/04/13 20:39:59 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Identities
[2011/04/13 20:39:55 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Contacts
[2011/04/13 20:39:53 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\VirtualStore
[2011/04/13 20:39:38 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\hpqlog
[2011/04/13 20:39:31 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\RemEngine
[2011/04/13 20:36:53 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Hewlett-Packard
[2011/04/13 20:36:44 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Hewlett-Packard
[2011/04/13 20:36:30 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Hewlett-Packard_Company
[2011/04/13 20:35:20 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\DigitalPersona
[2011/04/13 20:35:20 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\DigitalPersona
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\Temporary Internet Files
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Templates
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Start Menu
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\SendTo
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Recent
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\PrintHood
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\NetHood
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Videos
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Pictures
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Documents\My Music
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\My Documents
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Local Settings
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\History
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Cookies
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\Application Data
[2011/04/13 20:34:49 | 000,000,000 | -HSD | C] – C:\Users\gbourdon\AppData\Local\Application Data
[2011/04/13 20:34:47 | 000,000,000 | –SD | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Videos
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Saved Games
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Pictures
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Music
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Links
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Favorites
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Downloads
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\My Documents
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\Desktop
[2011/04/13 20:34:47 | 000,000,000 | R–D | C] – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/04/13 20:34:47 | 000,000,000 | -H-D | C] – C:\Users\gbourdon\AppData
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Temp
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\Microsoft
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Media Center Programs
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Roaming\Macromedia
[2011/04/13 20:34:47 | 000,000,000 | —D | C] – C:\Users\gbourdon\AppData\Local\HuluDesktop
[2011/04/06 16:26:58 | 000,237,856 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dnssdX.dll
[2011/04/06 16:26:58 | 000,119,584 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dns-sd.exe
[2011/04/06 16:26:58 | 000,096,544 | —- | C] (Apple Inc.) – C:\Windows\SysNative\dnssd.dll
[2011/04/06 16:26:58 | 000,069,408 | —- | C] (Apple Inc.) – C:\Windows\SysNative\jdns_sd.dll
[2011/04/06 16:20:16 | 000,197,920 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\jdns_sd.dll

========== Files - Modified Within 30 Days ==========

[2011/04/27 18:00:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/27 15:19:00 | 000,000,920 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000UA.job
[2011/04/27 12:13:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\gbourdon\Desktop\OTL.exe
[2011/04/27 10:16:09 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/04/27 10:14:14 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/27 09:36:09 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 09:36:09 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 09:35:57 | 000,002,289 | —- | M] () – C:\Users\gbourdon\Desktop\Google Chrome.lnk
[2011/04/27 09:28:06 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2011/04/26 22:28:04 | 000,729,688 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/26 22:28:04 | 000,626,278 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/04/26 22:28:04 | 000,107,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/04/25 12:58:10 | 000,279,283 | —- | M] () – C:\Users\gbourdon\Desktop\Confirmation.xps
[2011/04/23 21:19:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000Core.job
[2011/04/22 09:18:40 | 000,000,344 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForgbourdon.job
[2011/04/22 09:18:34 | 000,424,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/04/16 17:27:25 | 000,002,766 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/04/16 17:27:25 | 000,002,666 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/04/16 17:15:06 | 000,002,154 | —- | M] () – C:\Windows\epplauncher.mif
[2011/04/16 17:13:52 | 000,731,106 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/16 16:58:47 | 000,002,693 | —- | M] () – C:\Users\gbourdon\Desktop\Microsoft Office Word 2007.lnk
[2011/04/16 16:51:34 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/04/13 20:43:27 | 000,002,962 | —- | M] () – C:\Users\gbourdon\Desktop\Skype.lnk
[2011/04/13 20:41:47 | 000,001,437 | —- | M] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/13 19:31:46 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/04/13 19:31:46 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/04/06 16:26:58 | 000,237,856 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dnssdX.dll
[2011/04/06 16:26:58 | 000,119,584 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dns-sd.exe
[2011/04/06 16:26:58 | 000,096,544 | —- | M] (Apple Inc.) – C:\Windows\SysNative\dnssd.dll
[2011/04/06 16:26:58 | 000,069,408 | —- | M] (Apple Inc.) – C:\Windows\SysNative\jdns_sd.dll
[2011/04/06 16:20:16 | 000,197,920 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dnssdX.dll
[2011/04/06 16:20:16 | 000,107,808 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dns-sd.exe
[2011/04/06 16:20:16 | 000,091,424 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\dnssd.dll
[2011/04/06 16:20:16 | 000,075,040 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\jdns_sd.dll

========== Files Created - No Company Name ==========

[2011/04/27 10:16:09 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/04/27 10:14:14 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/04/27 10:13:42 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/27 09:26:17 | 000,002,289 | —- | C] () – C:\Users\gbourdon\Desktop\Google Chrome.lnk
[2011/04/25 12:58:08 | 000,279,283 | —- | C] () – C:\Users\gbourdon\Desktop\Confirmation.xps
[2011/04/21 21:35:36 | 000,000,344 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForgbourdon.job
[2011/04/18 21:14:04 | 000,000,920 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000UA.job
[2011/04/18 21:14:04 | 000,000,868 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1230881665-1955091148-432883134-1000Core.job
[2011/04/16 17:27:25 | 000,002,766 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/04/16 17:27:25 | 000,002,666 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk
[2011/04/16 17:15:06 | 000,002,154 | —- | C] () – C:\Windows\epplauncher.mif
[2011/04/16 17:13:52 | 000,731,106 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/16 17:13:47 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/04/16 16:58:47 | 000,002,693 | —- | C] () – C:\Users\gbourdon\Desktop\Microsoft Office Word 2007.lnk
[2011/04/16 16:51:34 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/04/13 20:43:27 | 000,002,962 | —- | C] () – C:\Users\gbourdon\Desktop\Skype.lnk
[2011/04/13 20:41:47 | 000,001,437 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/13 20:40:14 | 000,001,409 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/04/13 20:40:08 | 000,001,443 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/04/13 20:36:35 | 000,002,278 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
[2011/04/13 20:36:35 | 000,002,272 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk
[2011/04/13 20:36:35 | 000,002,196 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish.lnk
[2011/04/13 20:34:47 | 000,001,974 | —- | C] () – C:\Users\gbourdon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hulu Desktop.lnk
[2011/04/13 20:34:47 | 000,000,290 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/04/13 20:34:47 | 000,000,272 | —- | C] () – C:\Users\gbourdon\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/10/25 04:38:00 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 04:38:00 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 11:35:25 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 13:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 18:08:44 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 18:08:42 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 18:08:40 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 17:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 17:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 001,498,564 | —- | C] () – C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== Custom Scans ==========


< :Services >

< :OTL >

< PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >

< FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406" >

< FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" >

< [2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml >
Invalid Switch: 23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml


< [2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml >
Invalid Switch: 23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml


< O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >

< O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >

< O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >

< O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found >

< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD) >

< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >

< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD) >

< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >

< >

< :Commands >

< [purity] >

< [emptytemp] >

< [emptyflash] >

< End of report >



The computer is still running a little slow. But nothing drastic. About the same as it's been since I got the virus.
It does not appear that the fix ran properly. Can you please try tgain? Make sure to Copy & paste the text written inside of the code box (don't copy the word Code) into the Custom Scans/Fixes box located at the bottom of OTL and follow the rest of the directions in the fix again.

Make sure you reboot when it is done and post the resulting log file.
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== No active process named Program Files was found! Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL C:\Users\gbourdon\AppData\Roaming\Mozilla\Firefox\Profiles\x0a879cs.default\searchplugins\SearchquWebSearch.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\removeSearchqutoolbar not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll deleted successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: gbourdon ->Temp folder emptied: 929033515 bytes ->Temporary Internet Files folder emptied: 67871927 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 46258801 bytes ->Google Chrome cache emptied: 135294543 bytes ->Flash cache emptied: 71477 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 22443256 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,145.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: gbourdon ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.22.3 log created on 04272011_184340 Files\Folders moved on Reboot… C:\Users\gbourdon\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Unheck Remove found threats.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.


Please let me know how the machine is running now.
The Malaware system deleted 4 items but it rebooted and didn't open up with a Notepad afterwards. I'm running the second test now. Should all the viruses be deleted?
You can find the Malwarebytes report by running Malwarebytes and choosing the tab labeled Logs. You can then open the report and copy and paste it in your reply.

I cannot yet tell you all the malware files have been removed. I need to see the reports from both Malwarebytes and ESET before I know what our next steps will be.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6460 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/27/2011 7:01:32 PM mbam-log-2011-04-27 (19-01-32).txt Scan type: Quick scan Objects scanned: 155610 Time elapsed: 2 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\WhiteSmoke (PUP.Whitesmoke) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\WhiteSmoke (PUP.Whitesmoke) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\gbourdon\AppData\Roaming\whitesmoke (PUP.WhiteSmoke) -> Quarantined and deleted successfully. Files Infected: c:\Users\gbourdon\AppData\Roaming\whitesmoke\stat.log (PUP.WhiteSmoke) -> Quarantined and deleted successfully.
I did the second scan but the log didn't save. Where can I find it? I'm doing it again right now. It came up as 1 threat last time.
The ESET log should be saved at C:\Program Files\EsetOnlineScanner\log.txt. You should be able to open it and copy and paste the results. Have you noticed any improvement since we did the fix and ran Malwarebytes?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI