pekaboo
Topic Starter
Hi I have tired to get rid of this spyware and can't get rid of it!! Please help Please!!
We followed your forum and this is what the notepads gave us
OTL
Extras logfile created on: 29/05/2011 6:42:41 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 38.32% Memory free
5.96 Gb Paging File | 4.10 Gb Available in Paging File | 68.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.03 Gb Total Space | 149.97 Gb Free Space | 41.31% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.28 Gb Free Space | 13.40% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{131133EE-8D5F-49FD-9053-5D491D1507A2}" = lport=139 | protocol=6 | dir=in | app=system |
"{205F577A-7A3B-4F89-A336-2026AF31E4D9}" = lport=138 | protocol=17 | dir=in | app=system |
"{2F7B2D67-FAB5-4F4D-8A0D-47B092712816}" = rport=137 | protocol=17 | dir=out | app=system |
"{3A08E6C9-3C11-46A4-98E4-6EDBE6FDCF95}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{41DAA685-066B-4DEF-9482-84A597B9CC8D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4B91FD58-539C-4F06-B595-4B4CEF7A99F3}" = rport=139 | protocol=6 | dir=out | app=system |
"{537E415F-69DE-4C26-B0FA-23CC940F9EBD}" = lport=137 | protocol=17 | dir=in | app=system |
"{5D05B9BB-728D-4243-86E1-D4CB0E5F09BC}" = rport=445 | protocol=6 | dir=out | app=system |
"{7955B2CE-B925-41B3-9478-66DBEDF1A83B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{864A61E1-9200-45CF-9202-DD93D9A22647}" = rport=138 | protocol=17 | dir=out | app=system |
"{A927F88A-1C64-487B-BA7D-08507F4EEFF8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AA3749A9-DC1D-4ADB-8F2A-27E2DC42C248}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D6526779-EB9D-4B1E-8205-BFA1325838AD}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{F2D02CAB-20CC-43C2-A753-7D85564A22A6}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02DBBBDB-0E14-45D1-8FCA-758010403C62}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{11EEED7E-3439-482C-8A35-D6D91ABD77A4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{127E536A-2A00-4C0E-9795-B52287A025E6}" = protocol=6 | dir=in | app=c:\program files\winsim\connectionmanager\mysqlbinary\5.0.38\mysql\mysqld-nt.exe |
"{143B314B-C609-4813-A64A-A20DCC755B0C}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{1800CBBB-BB63-4EB1-AB32-EC5E9CA82C09}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2B2B9ADB-FCE4-4694-A99D-5B3070536101}" = protocol=17 | dir=in | app=c:\program files\winsim\connectionmanager\mysqlbinary\5.0.38\mysql\mysqld-nt.exe |
"{2D95F4E9-694F-45B7-A64B-D14A686FA12A}" = protocol=17 | dir=in | app=c:\program files\winsim\connectionmanager\simplyconnectionmanager.exe |
"{33AA8CBD-68BA-4D6B-8534-493A849D28BA}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{44A63B59-ACB9-44CF-A361-392EDD3F59D3}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E7F71E3-2668-4B76-A68D-70C315F9C203}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5738465F-F40F-43FD-926B-95B2B8D58E6D}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{626568F9-7E70-472A-BA59-2E18B0ECA2CE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7EB79B07-CE33-4994-BBB6-E813CA618900}" = protocol=17 | dir=in | app=c:\program files\bell\internet service advisor\servicepointservice.exe |
"{9CCAB77F-BC0A-4962-A74D-6CF3200F5552}" = protocol=6 | dir=in | app=c:\program files\winsim\connectionmanager\simplyconnectionmanager.exe |
"{B9C08119-ED8B-4B25-8BE6-B305D5EC0ED8}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D0AA3381-A72F-4270-8FF2-A4783BE03DAD}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D9E7FDB3-97CB-4F5F-AB0D-250A5412B63E}" = protocol=6 | dir=in | app=c:\program files\bell\internet service advisor\servicepointservice.exe |
"{DB36148A-A9F0-4FE6-AAC5-103B6F3D92EF}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{EA4E4D35-7BCA-4087-B329-725306C422E1}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{EE006529-A0B4-49BD-AFFD-78AB18F43EF0}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{F2659035-303F-4976-A0BD-A968A1B34CB8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F2E0634F-17D3-4622-BD19-16F1A616F30E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{FA873FF9-E13D-4436-ADC8-45871D7B64B7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FCCE2B2D-49E4-43E7-92AB-E71D26DAB49F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FD355650-C9AD-49AD-BABF-67C5A09B7260}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"TCP Query User{4C9ADB52-62A5-4C7F-A4AF-4DC1BF9BA5DE}C:\program files\tbn\tbn.exe" = protocol=6 | dir=in | app=c:\program files\tbn\tbn.exe |
"TCP Query User{4D5911D2-46F1-49D0-9CE2-36B8D72F098D}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{62B01A5E-EA75-4E72-AF06-25CE60CC792A}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{685B0A27-EE33-4596-9CC5-C70A4C634A7D}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"TCP Query User{7F69124C-5337-451C-BC10-5C6BE96A9246}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F46D13FB-1637-41F8-89F4-8BF8BBF110B1}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{3AC5A89B-6B5F-4BB6-BC60-06DD41286CBE}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{4D94C018-3ECA-428D-BB4A-8F39C2C3D8DD}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{8403364D-E752-4F2F-9AF6-072E6F80CC21}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{AA81933C-3DAD-4B32-8500-B9AC17946837}C:\program files\tbn\tbn.exe" = protocol=17 | dir=in | app=c:\program files\tbn\tbn.exe |
"UDP Query User{ACAC6332-8823-4580-A1A7-0C7B07A3BA0B}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{DA55B8C7-04BE-4B04-A9CE-7919AF7AA3CE}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{142E0726-73B2-4CD5-95BE-8B018801886C}" = Simply Accounting by Sage 2009
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20585CDC-114E-4372-986A-0686B1A37A30}" = Business Plan Pro 2007
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2C464EC1-2B0C-4490-9CAC-D4562DD8377A}" = Soap 3.0 Toolkit
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34699808-5D74-40E4-AD81-2F07F3313ECE}" = RPS RpsCore
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{37C11957-8228-4119-888D-3EA6B742BD9C}" = Simply Accounting by Sage 2009
"{37D74171-3131-498A-BE5D-7E3DA6AC0DBE}" = UFile 2007
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3EBA6E7C-3DF6-48AE-B87B-4CAFB2C1C3F7}" = LightScribe Template Labeler
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{451BB54C-8B23-4455-8BDC-14FC7D43E056}" = MSXML4SP2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{565E29BB-5863-46FD-ABF3-8074FBB5BAFF}" = QBFC 4.0
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9193306E-5935-47E0-B458-2548778C1614}_is1" = MediaGet2 version 2.1.494.0
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AFAD41A9-9687-48A3-848F-693C11451433}" = HP Customer Experience Enhancements
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BAF0296B-77EA-425B-934E-671B4DBAED6E}" = UFile Updater 2007
"{C44365D5-634A-4D55-9B9C-346FF6ED76BE}" = Bell Internet Security Services
"{C54856BC-3549-4ADE-AD4B-BC48C336DF5A}" = Simply Accounting by Sage 2009
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D22D11A0-DF6A-4DE9-B6E2-62A8C5ECCDDE}" = RPS CRT
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DD2EA1EE-6CAE-4227-A944-C9F9B43AA950}" = RPS PerfectDiskStub
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E8C2622C-9FF1-4F60-8008-A0208154F9F3}" = muvee autoProducer 6.1
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECC69E86-3B0E-4010-AA37-414C5D71B7B9}" = RPS CRT
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F929096B-54A0-4C5C-B125-1E7EB1917412}" = MySQL Connector/ODBC 3.51
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Business Card Maker 4.0_is1" = Business Card Maker 4.0
"AudioStreamer Pro" = AudioStreamer Pro
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"Cozy Restaurant Reservation_is1" = Cozy Restaurant Reservation version 1.8
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LogoSmartz 5.0 Trial" = LogoSmartz 5.0 Trial
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"RadialpointClientGateway_is1" = Bell Internet Service Advisor 3.7.44
"Royal RegisterLink" = Royal RegisterLink
"ShareDRMusic_is1" = ShareDRMusic 2.3.0
"T4 Internet - T4 par Internet 10.0" = T4 Internet - T4 par Internet 10.0
"Vault" = Personal Vault Manager
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinTax 2009 Calculator" = WinTax 2009 Calculator
"WinTax 2010 Calculator" = WinTax 2010 Calculator
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{9193306E-5935-47E0-B458-2548778C1614}_is1" = MediaGet2 version 2.1.538.0
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
[ Media Center Events ]
Error - 28/08/2008 9:03:06 AM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 06/09/2008 3:34:58 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 27/10/2008 7:58:24 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 24/11/2008 8:45:53 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 10/06/2009 8:35:16 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 31/07/2009 5:29:31 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ System Events ]
Error - 29/05/2011 1:28:46 PM | Computer Name = owner-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 29/05/2011 2:01:04 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:01:12 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:03:07 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:03:24 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:23 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:48 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
< End of report >
OTL logfile created on: 29/05/2011 6:42:41 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 38.32% Memory free
5.96 Gb Paging File | 4.10 Gb Available in Paging File | 68.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.03 Gb Total Space | 149.97 Gb Free Space | 41.31% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.28 Gb Free Space | 13.40% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/29 18:42:20 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\owner\Desktop\Downloads\OTL.exe
PRC - [2011/04/14 12:25:41 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/17 18:37:40 | 011,322,880 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 18:37:40 | 011,314,688 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2011/01/06 16:56:50 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe
PRC - [2011/01/06 16:56:46 | 004,318,520 | —- | M] (Bell) – C:\Program Files\Bell\Internet Service Advisor\BISA.exe
PRC - [2011/01/06 16:56:46 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files\Bell\Internet Service Advisor\BISAComHandler.exe
PRC - [2010/01/18 16:11:16 | 000,165,408 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe
PRC - [2010/01/18 16:11:12 | 000,377,576 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\RPS.exe
PRC - [2010/01/18 16:10:12 | 000,371,920 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\Fws.exe
PRC - [2010/01/17 19:08:58 | 000,056,400 | —- | M] (Bell Canada) – C:\Program Files\Personal Vault\VaultClientUpgrade.exe
PRC - [2010/01/17 19:08:54 | 001,051,728 | —- | M] (Bell Canada) – C:\Program Files\Personal Vault\VaultClientSRV.exe
PRC - [2009/11/02 15:26:48 | 005,832,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe
PRC - [2009/11/02 15:26:48 | 000,592,392 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\bin\AVGIDSMonitor.exe
PRC - [2009/06/08 12:07:50 | 001,033,480 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
PRC - [2009/06/08 12:07:50 | 000,066,824 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
PRC - [2009/06/08 12:07:48 | 000,931,080 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/09/19 01:00:00 | 000,087,336 | —- | M] (Sage Software) – C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe
PRC - [2008/09/19 01:00:00 | 000,016,680 | —- | M] (Sage Software) – C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 03:33:27 | 000,151,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\schtasks.exe
PRC - [2008/01/15 11:26:18 | 004,874,240 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtHDVCpl.exe
PRC - [2007/04/18 11:01:34 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2007/02/15 07:59:00 | 000,118,784 | —- | M] (OsdMaestro) – C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
========== Modules (SafeList) ==========
MOD - [2011/05/29 18:42:20 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\owner\Desktop\Downloads\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/05/09 18:18:14 | 000,315,392 | —- | M] (S.C. BitDefender S.R.L) [On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\scan.dll – (scan)
SRV - [2011/01/06 16:56:50 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe – (ServicepointService)
SRV - [2010/01/18 16:11:16 | 000,165,408 | —- | M] (Bell) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe – (Radialpoint Security Services)
SRV - [2010/01/18 16:10:12 | 000,371,920 | —- | M] (Bell) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\Fws.exe – (RP_FWS)
SRV - [2010/01/17 19:08:58 | 000,056,400 | —- | M] (Bell Canada) [Auto | Running] – C:\Program Files\Personal Vault\VaultClientUpgrade.exe – (VaultClientUpgrade)
SRV - [2010/01/17 19:08:54 | 001,051,728 | —- | M] (Bell Canada) [Auto | Running] – C:\Program Files\Personal Vault\VaultClientSRV.exe – (VaultClientSRV)
SRV - [2009/11/02 15:26:48 | 005,832,712 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe – (RadialpointIDSAgent)
SRV - [2009/06/08 12:07:50 | 001,033,480 | —- | M] (Raxco Software, Inc.) [On_Demand | Running] – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe – (PDEngine)
SRV - [2009/06/08 12:07:48 | 000,931,080 | —- | M] (Raxco Software, Inc.) [On_Demand | Running] – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe – (PDAgent)
SRV - [2008/09/19 01:00:00 | 000,016,680 | —- | M] (Sage Software) [Auto | Running] – C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe – (Simply Accounting Database Connection Manager)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011/05/09 16:07:08 | 000,053,192 | —- | M] (Radialpoint Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\rp_skt32.sys – (RPSKT) Security Services Driver (x86)
DRV - [2009/11/26 09:50:32 | 000,039,808 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\trufos.sys – (Trufos)
DRV - [2009/11/26 09:50:32 | 000,014,720 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\profos.sys – (Profos)
DRV - [2009/11/02 15:27:00 | 000,122,376 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys – (RadialpointIDSDriver)
DRV - [2009/11/02 15:27:00 | 000,030,216 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys – (RadialpointIDSFilter)
DRV - [2009/11/02 15:27:00 | 000,027,800 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys – (RadialpointIDSShim)
DRV - [2009/11/02 15:27:00 | 000,025,608 | —- | M] (AVG Technologies ) [Kernel | Boot | Running] – C:\Windows\system32\drivers\AVGIDSEH.sys – (RadialpointIDSEH)
DRV - [2009/10/23 13:25:54 | 000,285,704 | —- | M] (BitDefender S.R.L. Bucharest, ROMANIA) [File_System | Boot | Running] – C:\Windows\system32\drivers\bdfsfltr.sys – (bdfsfltr)
DRV - [2009/06/08 10:00:56 | 000,071,696 | —- | M] (Raxco Software, Inc.) [File_System | Auto | Running] – C:\Windows\System32\drivers\DefragFs.sys – (DefragFS)
DRV - [2008/08/01 19:51:14 | 001,052,704 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2008/05/22 14:49:00 | 007,465,312 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/05/08 05:05:18 | 000,266,752 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2008/05/08 05:03:18 | 000,980,992 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2008/01/08 14:23:48 | 000,017,408 | —- | M] () [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\vburner.sys – (vburner)
DRV - [2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2007/10/18 07:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2005/12/12 13:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 98 55 60 38 D3 14 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/09 21:03:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/09 21:02:56 | 000,000,000 | —D | M]
[2011/05/29 15:35:20 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\mozilla\Extensions
[2011/05/29 15:35:27 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions
[2008/09/08 00:14:33 | 000,000,000 | —D | M] (Vista-aero) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}(189)
[2010/06/10 21:17:46 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/04 21:18:28 | 000,000,000 | —D | M] (IE Tab) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2008/12/01 11:37:35 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2011/05/25 16:35:35 | 000,000,000 | —D | M] (Awesome screenshot: Capture and Annotate) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\57iosvow.default\searchplugins\SearchquWebSearch.xml
[2011/05/29 15:35:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/25 17:01:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/05/09 20:56:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\57IOSVOW.DEFAULT\EXTENSIONS\{6E84150A-D526-41F1-A480-A67D3FED910D}.XPI
[2011/04/14 12:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BellCanada_UninstallTracking] File not found
O4 - HKLM..\Run: [BISA.exe] C:\Program Files\Bell\Internet Service Advisor\BISA.exe (Bell)
O4 - HKLM..\Run: [ConnectionManager] C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe (Sage Software)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [removeSearchqudatamngr] File not found
O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/29 00:45:16 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\Windows\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/29 13:25:51 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{644ACA86-7A2E-45B5-B6B8-0C3515C00D94}
[2011/05/29 13:22:32 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{DACBE0D5-3E85-4B21-BAFE-A0F3E222AE39}
[2011/05/29 13:17:26 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{CD5B25B1-7A16-4B5A-9059-ACD449EEF833}
[2011/05/29 13:00:29 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{36F1F6BC-5FD1-4198-86FC-AE933C4FE385}
[2011/05/28 06:14:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{37B2D8B2-276E-43AC-959F-D1FF0B8FE69E}
[2011/05/27 19:58:48 | 000,000,000 | —D | C] – C:\recordings
[2011/05/27 19:51:42 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AudioStreamer Pro
[2011/05/27 19:51:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioStreamer Pro
[2011/05/27 19:51:07 | 000,000,000 | —D | C] – C:\Windows\AudioStreamer Pro
[2011/05/27 19:51:07 | 000,000,000 | —D | C] – C:\Program Files\AudioStreamer Pro
[2011/05/27 06:51:34 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{77BE3100-4DB4-474B-9E93-6819EDB7D983}
[2011/05/26 11:21:31 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{53090489-3478-47CF-A211-1F420FCC7285}
[2011/05/25 23:20:57 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{545A9942-B397-4B4A-BA24-91BDB7895B59}
[2011/05/25 17:11:53 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\OpenOffice.org
[2011/05/25 17:09:14 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2011/05/25 17:08:04 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2011/05/25 17:06:57 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/05/25 17:01:42 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/25 17:01:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/25 17:01:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/05/25 11:20:22 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{41CF8AA5-286A-4A00-AD94-3F60C02106FE}
[2011/05/24 23:19:29 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{653C79F2-B59B-409B-8B2C-CA41EB43B631}
[2011/05/24 09:13:35 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/05/24 09:12:50 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/05/24 09:12:36 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\PackageAware
[2011/05/24 08:57:07 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{77E19AC9-827D-4FB6-BCDF-98158C2D5B03}
[2011/05/23 13:12:03 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\2010 Top Cafe Taxes
[2011/05/23 09:25:27 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{29F759C5-AE61-40B0-8BF4-A32C71C8C7EF}
[2011/05/22 19:53:11 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{7BFF0B7F-2992-4565-A18E-8990238DDCC5}
[2011/05/20 10:10:53 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{5D5E4CE8-8275-4F0B-B875-F257A30EADAD}
[2011/05/19 09:01:02 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{57E6B5E5-3D59-439E-ABA6-048ECF0EE4D8}
[2011/05/18 22:33:13 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{A8E16545-F068-4CAE-950F-373CFFB99743}
[2011/05/18 09:45:21 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{35FBA623-15FB-4BD7-B0FA-746CB0919F56}
[2011/05/17 21:41:58 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{BC938204-08DE-4ABB-8F58-976ED5779383}
[2011/05/17 20:26:10 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/17 09:00:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{1A06BAE7-671E-4304-8965-CB97164D3C83}
[2011/05/16 09:46:52 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/16 09:20:12 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{921B75F1-655C-4B39-BA83-52C56994DADB}
[2011/05/16 00:31:02 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{5244478C-318F-4719-8D4C-808747CBC025}
[2011/05/15 11:10:33 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{65AF53E6-8F4C-4C98-A785-AE9DCDA88B67}
[2011/05/15 07:42:45 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{4845957C-A953-4A1B-AC0A-215406F7C526}
[2011/05/14 09:56:45 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{A3CFF85F-69F9-455F-80C6-0E11DB313373}
[2011/05/13 21:56:11 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{66300D6B-1DCA-4C69-808C-5897B80E9188}
[2011/05/13 16:42:55 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/05/13 16:42:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/05/13 10:41:23 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/05/13 10:41:22 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/05/12 22:08:36 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/05/10 10:48:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaGet2
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Media Get LLC
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Media Get LLC
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\ProgramData\Media Get LLC
[2011/05/10 10:48:23 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\MediaGet2
[2011/05/09 20:57:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/05/09 20:55:58 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/05/09 17:41:16 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2011/05/09 17:36:49 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2011/05/09 17:36:43 | 000,000,000 | —D | C] – C:\Program Files\Bing Bar Installer
[2011/05/09 17:30:09 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Windows Live
[2011/05/09 17:29:37 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2011/05/09 17:20:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/09 17:20:42 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/09 17:20:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/09 17:20:42 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/09 17:20:42 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/09 17:20:42 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/09 17:20:42 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/09 17:20:42 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/09 17:20:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/09 17:20:41 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/09 17:20:41 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/09 17:20:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/09 17:20:41 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/09 17:20:41 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/09 17:20:41 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/09 17:20:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/09 17:20:41 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/09 17:20:41 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/09 17:20:41 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/09 17:20:41 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/09 17:20:41 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/09 17:20:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/09 17:20:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/09 17:20:41 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/09 17:20:40 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/09 17:20:40 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/09 17:20:40 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/09 17:20:40 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/09 17:20:40 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/09 17:20:40 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/09 17:20:40 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/09 17:20:40 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/09 17:20:40 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/09 17:20:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/09 17:20:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/09 17:20:40 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/09 17:20:40 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/09 17:20:40 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/09 17:20:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/09 17:18:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2011/05/09 17:17:48 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2011/05/09 17:17:48 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2011/05/09 17:17:48 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2011/05/09 17:17:46 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2011/05/09 17:17:46 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2011/05/09 17:17:43 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2011/05/09 17:17:43 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2011/05/09 17:17:43 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2011/05/09 17:17:43 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2011/05/09 17:17:42 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2011/05/09 17:17:35 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2011/05/09 17:17:35 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2011/05/09 17:17:35 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2011/05/09 17:17:35 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2011/05/09 17:17:35 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2011/05/09 17:16:18 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/05/09 17:16:18 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/05/09 17:16:17 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/05/09 17:16:16 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/05/09 17:16:15 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/05/09 17:16:15 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/05/09 17:16:15 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/05/09 17:16:15 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/05/09 17:16:10 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/05/09 17:16:09 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/05/09 16:07:36 | 000,025,608 | —- | C] (AVG Technologies ) – C:\Windows\System32\drivers\AVGIDSEH.sys
[2011/05/09 16:07:10 | 000,285,704 | —- | C] (BitDefender S.R.L. Bucharest, ROMANIA) – C:\Windows\System32\drivers\bdfsfltr.sys
[2011/05/09 16:06:50 | 000,000,000 | —D | C] – C:\ProgramData\Raxco
[2011/05/09 16:06:50 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2011/05/09 16:06:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bell Internet Security Services
[2 C:\Users\owner\AppData\Local\*.tmp files -> C:\Users\owner\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/29 18:25:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3346605070-2425595462-292171502-1000UA.job
[2011/05/29 18:12:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/29 17:24:50 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/29 17:24:50 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/29 15:25:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3346605070-2425595462-292171502-1000Core.job
[2011/05/29 15:12:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/29 14:27:01 | 000,648,388 | —- | M] () – C:\Users\owner\Documents\Casio_PCR-T2100_E071227A.pdf
[2011/05/29 13:24:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/29 13:24:45 | 3085,410,304 | -HS- | M] () – C:\hiberfil.sys
[2011/05/29 13:24:43 | 232,244,463 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/05/28 17:10:27 | 000,327,680 | —- | M] () – C:\Users\owner\Desktop\TakeOut Menu#2 2010.pub
[2011/05/28 14:55:07 | 000,002,609 | —- | M] () – C:\Users\owner\Desktop\Microsoft Office Word 2003.lnk
[2011/05/28 10:50:32 | 000,124,928 | —- | M] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2011.pub
[2011/05/28 10:50:26 | 000,124,928 | —- | M] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2010.pub
[2011/05/28 10:31:41 | 000,002,555 | —- | M] () – C:\Users\owner\Desktop\Microsoft Office Publisher 2003.lnk
[2011/05/27 19:46:19 | 000,678,592 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/27 19:46:19 | 000,143,068 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/25 23:14:53 | 000,368,672 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/25 17:12:31 | 000,001,030 | —- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/05/25 17:09:14 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/05/18 11:50:36 | 000,053,248 | —- | M] () – C:\Users\owner\Documents\may 22 2011 catering.pub
[2011/05/17 20:26:10 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/17 11:22:34 | 000,002,305 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/16 10:07:55 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/05/10 10:48:41 | 000,000,900 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaGet.lnk
[2011/05/09 21:03:01 | 000,000,872 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 21:03:01 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/09 17:48:08 | 000,000,945 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/09 17:20:53 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/05/09 17:20:53 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/05/09 17:20:42 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/09 17:20:42 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/09 17:20:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/09 17:20:42 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/09 17:20:42 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/09 17:20:42 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/09 17:20:42 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/09 17:20:42 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/09 17:20:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/09 17:20:41 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/09 17:20:41 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/09 17:20:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/09 17:20:41 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/09 17:20:41 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/09 17:20:41 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/09 17:20:41 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/09 17:20:41 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/09 17:20:41 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/09 17:20:41 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/09 17:20:41 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/09 17:20:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/09 17:20:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/09 17:20:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/09 17:20:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/09 17:20:41 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/09 17:20:40 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/09 17:20:40 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/09 17:20:40 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/09 17:20:40 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/09 17:20:40 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/09 17:20:40 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/09 17:20:40 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/09 17:20:40 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/09 17:20:40 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/09 17:20:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/09 17:20:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/09 17:20:40 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/09 17:20:40 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/09 17:20:40 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/09 17:20:39 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/09 16:08:24 | 120,922,400 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2011/05/09 16:08:24 | 001,621,616 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2011/05/09 16:07:08 | 000,053,192 | —- | M] (Radialpoint Inc.) – C:\Windows\System32\drivers\rp_skt32.sys
[2011/05/09 16:06:27 | 000,002,045 | —- | M] () – C:\Users\Public\Desktop\Bell Internet Security Services.lnk
[2 C:\Users\owner\AppData\Local\*.tmp files -> C:\Users\owner\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/29 14:27:01 | 000,648,388 | —- | C] () – C:\Users\owner\Documents\Casio_PCR-T2100_E071227A.pdf
[2011/05/28 10:50:32 | 000,124,928 | —- | C] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2011.pub
[2011/05/25 17:12:31 | 000,001,030 | —- | C] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/05/25 17:09:14 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/05/18 11:50:35 | 000,053,248 | —- | C] () – C:\Users\owner\Documents\may 22 2011 catering.pub
[2011/05/13 22:12:58 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2011/05/10 10:48:41 | 000,000,900 | —- | C] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaGet.lnk
[2011/05/09 21:03:01 | 000,000,860 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/09 21:03:01 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/09 17:48:08 | 000,000,945 | —- | C] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/09 17:38:38 | 000,002,027 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/05/09 17:20:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/09 17:17:37 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2011/05/09 17:17:37 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2011/05/09 17:17:37 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2011/05/09 16:06:27 | 000,002,045 | —- | C] () – C:\Users\Public\Desktop\Bell Internet Security Services.lnk
[2010/12/13 17:10:54 | 000,000,000 | —- | C] () – C:\Windows\PROTOCOL.INI
[2009/10/21 13:20:08 | 000,005,504 | —- | C] () – C:\Windows\System32\drivers\StarOpen_x86.sys
[2009/09/13 22:44:08 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/13 22:44:07 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/31 23:06:23 | 120,922,400 | -HS- | C] () – C:\Windows\System32\drivers\fidbox.dat
[2009/02/16 14:47:58 | 000,053,248 | —- | C] () – C:\Windows\System32\zlib.dll
[2009/02/16 10:13:51 | 000,000,572 | —- | C] () – C:\Windows\ODBCINST.INI
[2009/02/16 10:12:41 | 000,017,920 | —- | C] () – C:\Windows\System32\Implode.dll
[2008/09/11 23:04:35 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/05/18 18:18:34 | 000,017,408 | —- | C] () – C:\Windows\System32\drivers\vburner.sys
[2008/04/30 20:41:40 | 000,016,896 | —- | C] () – C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/24 09:39:48 | 000,000,940 | —- | C] () – C:\Windows\ODBC.INI
[2008/04/22 10:41:03 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2008/04/22 09:48:49 | 000,000,136 | —- | C] () – C:\Users\owner\AppData\Roaming\wklnhst.dat
[2008/04/19 09:42:15 | 000,000,680 | —- | C] () – C:\Users\owner\AppData\Local\d3d9caps.dat
[2007/11/29 00:38:28 | 000,102,451 | —- | C] () – C:\Windows\hpqins13.dat
[2007/11/29 00:25:22 | 000,061,440 | —- | C] () – C:\Windows\System32\OsdRemove.exe
[2007/11/29 00:22:37 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2007/11/29 00:22:37 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/08/09 15:59:54 | 000,114,688 | —- | C] () – C:\Windows\System32\myodbc3i.exe
[2007/08/09 15:59:54 | 000,106,496 | —- | C] () – C:\Windows\System32\myodbc3m.exe
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,368,672 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,678,592 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,143,068 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/08/17 08:53:03 | 000,401,408 | —- | C] () – C:\Windows\System32\StepButtonS.dll
[2005/05/19 19:56:26 | 000,491,520 | —- | C] () – C:\Windows\System32\mp3lib.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
========== Files - Unicode (All) ==========
[2009/08/31 23:03:56 | 000,000,036 | —- | M] ()(C:\Windows\System32\?????????????????4????????????????????????g) – C:\Windows\System32\㩃停潲牧浡䘠汩獥䉜汥屬敂汬䤠瑮牥敮⁴敓畣楲祴匠牥楶散屳慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
[2009/08/31 23:03:56 | 000,000,036 | —- | C] ()(C:\Windows\System32\?????????????????4????????????????????????g) – C:\Windows\System32\㩃停潲牧浡䘠汩獥䉜汥屬敂汬䤠瑮牥敮⁴敓畣楲祴匠牥楶散屳慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
< End of report >
We followed your forum and this is what the notepads gave us
OTL
Extras logfile created on: 29/05/2011 6:42:41 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 38.32% Memory free
5.96 Gb Paging File | 4.10 Gb Available in Paging File | 68.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.03 Gb Total Space | 149.97 Gb Free Space | 41.31% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.28 Gb Free Space | 13.40% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{131133EE-8D5F-49FD-9053-5D491D1507A2}" = lport=139 | protocol=6 | dir=in | app=system |
"{205F577A-7A3B-4F89-A336-2026AF31E4D9}" = lport=138 | protocol=17 | dir=in | app=system |
"{2F7B2D67-FAB5-4F4D-8A0D-47B092712816}" = rport=137 | protocol=17 | dir=out | app=system |
"{3A08E6C9-3C11-46A4-98E4-6EDBE6FDCF95}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{41DAA685-066B-4DEF-9482-84A597B9CC8D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4B91FD58-539C-4F06-B595-4B4CEF7A99F3}" = rport=139 | protocol=6 | dir=out | app=system |
"{537E415F-69DE-4C26-B0FA-23CC940F9EBD}" = lport=137 | protocol=17 | dir=in | app=system |
"{5D05B9BB-728D-4243-86E1-D4CB0E5F09BC}" = rport=445 | protocol=6 | dir=out | app=system |
"{7955B2CE-B925-41B3-9478-66DBEDF1A83B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{864A61E1-9200-45CF-9202-DD93D9A22647}" = rport=138 | protocol=17 | dir=out | app=system |
"{A927F88A-1C64-487B-BA7D-08507F4EEFF8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AA3749A9-DC1D-4ADB-8F2A-27E2DC42C248}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D6526779-EB9D-4B1E-8205-BFA1325838AD}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{F2D02CAB-20CC-43C2-A753-7D85564A22A6}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02DBBBDB-0E14-45D1-8FCA-758010403C62}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{11EEED7E-3439-482C-8A35-D6D91ABD77A4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{127E536A-2A00-4C0E-9795-B52287A025E6}" = protocol=6 | dir=in | app=c:\program files\winsim\connectionmanager\mysqlbinary\5.0.38\mysql\mysqld-nt.exe |
"{143B314B-C609-4813-A64A-A20DCC755B0C}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{1800CBBB-BB63-4EB1-AB32-EC5E9CA82C09}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2B2B9ADB-FCE4-4694-A99D-5B3070536101}" = protocol=17 | dir=in | app=c:\program files\winsim\connectionmanager\mysqlbinary\5.0.38\mysql\mysqld-nt.exe |
"{2D95F4E9-694F-45B7-A64B-D14A686FA12A}" = protocol=17 | dir=in | app=c:\program files\winsim\connectionmanager\simplyconnectionmanager.exe |
"{33AA8CBD-68BA-4D6B-8534-493A849D28BA}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{44A63B59-ACB9-44CF-A361-392EDD3F59D3}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E7F71E3-2668-4B76-A68D-70C315F9C203}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5738465F-F40F-43FD-926B-95B2B8D58E6D}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{626568F9-7E70-472A-BA59-2E18B0ECA2CE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7EB79B07-CE33-4994-BBB6-E813CA618900}" = protocol=17 | dir=in | app=c:\program files\bell\internet service advisor\servicepointservice.exe |
"{9CCAB77F-BC0A-4962-A74D-6CF3200F5552}" = protocol=6 | dir=in | app=c:\program files\winsim\connectionmanager\simplyconnectionmanager.exe |
"{B9C08119-ED8B-4B25-8BE6-B305D5EC0ED8}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D0AA3381-A72F-4270-8FF2-A4783BE03DAD}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D9E7FDB3-97CB-4F5F-AB0D-250A5412B63E}" = protocol=6 | dir=in | app=c:\program files\bell\internet service advisor\servicepointservice.exe |
"{DB36148A-A9F0-4FE6-AAC5-103B6F3D92EF}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{EA4E4D35-7BCA-4087-B329-725306C422E1}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{EE006529-A0B4-49BD-AFFD-78AB18F43EF0}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{F2659035-303F-4976-A0BD-A968A1B34CB8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F2E0634F-17D3-4622-BD19-16F1A616F30E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{FA873FF9-E13D-4436-ADC8-45871D7B64B7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FCCE2B2D-49E4-43E7-92AB-E71D26DAB49F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FD355650-C9AD-49AD-BABF-67C5A09B7260}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"TCP Query User{4C9ADB52-62A5-4C7F-A4AF-4DC1BF9BA5DE}C:\program files\tbn\tbn.exe" = protocol=6 | dir=in | app=c:\program files\tbn\tbn.exe |
"TCP Query User{4D5911D2-46F1-49D0-9CE2-36B8D72F098D}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{62B01A5E-EA75-4E72-AF06-25CE60CC792A}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{685B0A27-EE33-4596-9CC5-C70A4C634A7D}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"TCP Query User{7F69124C-5337-451C-BC10-5C6BE96A9246}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{F46D13FB-1637-41F8-89F4-8BF8BBF110B1}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{3AC5A89B-6B5F-4BB6-BC60-06DD41286CBE}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{4D94C018-3ECA-428D-BB4A-8F39C2C3D8DD}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{8403364D-E752-4F2F-9AF6-072E6F80CC21}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{AA81933C-3DAD-4B32-8500-B9AC17946837}C:\program files\tbn\tbn.exe" = protocol=17 | dir=in | app=c:\program files\tbn\tbn.exe |
"UDP Query User{ACAC6332-8823-4580-A1A7-0C7B07A3BA0B}C:\program files\veoh networks\veoh\veohclient.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veoh\veohclient.exe |
"UDP Query User{DA55B8C7-04BE-4B04-A9CE-7919AF7AA3CE}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{142E0726-73B2-4CD5-95BE-8B018801886C}" = Simply Accounting by Sage 2009
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20585CDC-114E-4372-986A-0686B1A37A30}" = Business Plan Pro 2007
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2C464EC1-2B0C-4490-9CAC-D4562DD8377A}" = Soap 3.0 Toolkit
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34699808-5D74-40E4-AD81-2F07F3313ECE}" = RPS RpsCore
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{37C11957-8228-4119-888D-3EA6B742BD9C}" = Simply Accounting by Sage 2009
"{37D74171-3131-498A-BE5D-7E3DA6AC0DBE}" = UFile 2007
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3EBA6E7C-3DF6-48AE-B87B-4CAFB2C1C3F7}" = LightScribe Template Labeler
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{451BB54C-8B23-4455-8BDC-14FC7D43E056}" = MSXML4SP2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{565E29BB-5863-46FD-ABF3-8074FBB5BAFF}" = QBFC 4.0
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65C0025A-2CDE-43C5-82D0-C7A56EF0DB39}" = Bing Bar Platform
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9193306E-5935-47E0-B458-2548778C1614}_is1" = MediaGet2 version 2.1.494.0
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AFAD41A9-9687-48A3-848F-693C11451433}" = HP Customer Experience Enhancements
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BAF0296B-77EA-425B-934E-671B4DBAED6E}" = UFile Updater 2007
"{C44365D5-634A-4D55-9B9C-346FF6ED76BE}" = Bell Internet Security Services
"{C54856BC-3549-4ADE-AD4B-BC48C336DF5A}" = Simply Accounting by Sage 2009
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D22D11A0-DF6A-4DE9-B6E2-62A8C5ECCDDE}" = RPS CRT
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DD2EA1EE-6CAE-4227-A944-C9F9B43AA950}" = RPS PerfectDiskStub
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E8C2622C-9FF1-4F60-8008-A0208154F9F3}" = muvee autoProducer 6.1
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECC69E86-3B0E-4010-AA37-414C5D71B7B9}" = RPS CRT
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F929096B-54A0-4C5C-B125-1E7EB1917412}" = MySQL Connector/ODBC 3.51
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Business Card Maker 4.0_is1" = Business Card Maker 4.0
"AudioStreamer Pro" = AudioStreamer Pro
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"Cozy Restaurant Reservation_is1" = Cozy Restaurant Reservation version 1.8
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LogoSmartz 5.0 Trial" = LogoSmartz 5.0 Trial
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"RadialpointClientGateway_is1" = Bell Internet Service Advisor 3.7.44
"Royal RegisterLink" = Royal RegisterLink
"ShareDRMusic_is1" = ShareDRMusic 2.3.0
"T4 Internet - T4 par Internet 10.0" = T4 Internet - T4 par Internet 10.0
"Vault" = Personal Vault Manager
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinTax 2009 Calculator" = WinTax 2009 Calculator
"WinTax 2010 Calculator" = WinTax 2010 Calculator
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{9193306E-5935-47E0-B458-2548778C1614}_is1" = MediaGet2 version 2.1.538.0
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:16 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 29/05/2011 3:07:17 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3013
Description =
[ Media Center Events ]
Error - 28/08/2008 9:03:06 AM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 06/09/2008 3:34:58 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 27/10/2008 7:58:24 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 24/11/2008 8:45:53 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 10/06/2009 8:35:16 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 31/07/2009 5:29:31 PM | Computer Name = owner-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ System Events ]
Error - 29/05/2011 1:28:46 PM | Computer Name = owner-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 29/05/2011 2:01:04 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:01:12 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:03:07 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:03:24 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:22 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:23 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
Error - 29/05/2011 2:04:48 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =
< End of report >
OTL logfile created on: 29/05/2011 6:42:41 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 38.32% Memory free
5.96 Gb Paging File | 4.10 Gb Available in Paging File | 68.85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.03 Gb Total Space | 149.97 Gb Free Space | 41.31% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.28 Gb Free Space | 13.40% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/29 18:42:20 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\owner\Desktop\Downloads\OTL.exe
PRC - [2011/04/14 12:25:41 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/17 18:37:40 | 011,322,880 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 18:37:40 | 011,314,688 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2011/01/06 16:56:50 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe
PRC - [2011/01/06 16:56:46 | 004,318,520 | —- | M] (Bell) – C:\Program Files\Bell\Internet Service Advisor\BISA.exe
PRC - [2011/01/06 16:56:46 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files\Bell\Internet Service Advisor\BISAComHandler.exe
PRC - [2010/01/18 16:11:16 | 000,165,408 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe
PRC - [2010/01/18 16:11:12 | 000,377,576 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\RPS.exe
PRC - [2010/01/18 16:10:12 | 000,371,920 | —- | M] (Bell) – C:\Program Files\Bell\Bell Internet Security Services\Fws.exe
PRC - [2010/01/17 19:08:58 | 000,056,400 | —- | M] (Bell Canada) – C:\Program Files\Personal Vault\VaultClientUpgrade.exe
PRC - [2010/01/17 19:08:54 | 001,051,728 | —- | M] (Bell Canada) – C:\Program Files\Personal Vault\VaultClientSRV.exe
PRC - [2009/11/02 15:26:48 | 005,832,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe
PRC - [2009/11/02 15:26:48 | 000,592,392 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\bin\AVGIDSMonitor.exe
PRC - [2009/06/08 12:07:50 | 001,033,480 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
PRC - [2009/06/08 12:07:50 | 000,066,824 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
PRC - [2009/06/08 12:07:48 | 000,931,080 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/09/19 01:00:00 | 000,087,336 | —- | M] (Sage Software) – C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe
PRC - [2008/09/19 01:00:00 | 000,016,680 | —- | M] (Sage Software) – C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 03:33:27 | 000,151,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\schtasks.exe
PRC - [2008/01/15 11:26:18 | 004,874,240 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtHDVCpl.exe
PRC - [2007/04/18 11:01:34 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2007/02/15 07:59:00 | 000,118,784 | —- | M] (OsdMaestro) – C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
========== Modules (SafeList) ==========
MOD - [2011/05/29 18:42:20 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\owner\Desktop\Downloads\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/05/09 18:18:14 | 000,315,392 | —- | M] (S.C. BitDefender S.R.L) [On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\scan.dll – (scan)
SRV - [2011/01/06 16:56:50 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe – (ServicepointService)
SRV - [2010/01/18 16:11:16 | 000,165,408 | —- | M] (Bell) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe – (Radialpoint Security Services)
SRV - [2010/01/18 16:10:12 | 000,371,920 | —- | M] (Bell) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\Fws.exe – (RP_FWS)
SRV - [2010/01/17 19:08:58 | 000,056,400 | —- | M] (Bell Canada) [Auto | Running] – C:\Program Files\Personal Vault\VaultClientUpgrade.exe – (VaultClientUpgrade)
SRV - [2010/01/17 19:08:54 | 001,051,728 | —- | M] (Bell Canada) [Auto | Running] – C:\Program Files\Personal Vault\VaultClientSRV.exe – (VaultClientSRV)
SRV - [2009/11/02 15:26:48 | 005,832,712 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe – (RadialpointIDSAgent)
SRV - [2009/06/08 12:07:50 | 001,033,480 | —- | M] (Raxco Software, Inc.) [On_Demand | Running] – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe – (PDEngine)
SRV - [2009/06/08 12:07:48 | 000,931,080 | —- | M] (Raxco Software, Inc.) [On_Demand | Running] – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe – (PDAgent)
SRV - [2008/09/19 01:00:00 | 000,016,680 | —- | M] (Sage Software) [Auto | Running] – C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe – (Simply Accounting Database Connection Manager)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011/05/09 16:07:08 | 000,053,192 | —- | M] (Radialpoint Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\rp_skt32.sys – (RPSKT) Security Services Driver (x86)
DRV - [2009/11/26 09:50:32 | 000,039,808 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\trufos.sys – (Trufos)
DRV - [2009/11/26 09:50:32 | 000,014,720 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\BitDefender\profos.sys – (Profos)
DRV - [2009/11/02 15:27:00 | 000,122,376 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys – (RadialpointIDSDriver)
DRV - [2009/11/02 15:27:00 | 000,030,216 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys – (RadialpointIDSFilter)
DRV - [2009/11/02 15:27:00 | 000,027,800 | —- | M] (AVG Technologies ) [Kernel | On_Demand | Running] – C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys – (RadialpointIDSShim)
DRV - [2009/11/02 15:27:00 | 000,025,608 | —- | M] (AVG Technologies ) [Kernel | Boot | Running] – C:\Windows\system32\drivers\AVGIDSEH.sys – (RadialpointIDSEH)
DRV - [2009/10/23 13:25:54 | 000,285,704 | —- | M] (BitDefender S.R.L. Bucharest, ROMANIA) [File_System | Boot | Running] – C:\Windows\system32\drivers\bdfsfltr.sys – (bdfsfltr)
DRV - [2009/06/08 10:00:56 | 000,071,696 | —- | M] (Raxco Software, Inc.) [File_System | Auto | Running] – C:\Windows\System32\drivers\DefragFs.sys – (DefragFS)
DRV - [2008/08/01 19:51:14 | 001,052,704 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2008/05/22 14:49:00 | 007,465,312 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/05/08 05:05:18 | 000,266,752 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2008/05/08 05:03:18 | 000,980,992 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2008/01/08 14:23:48 | 000,017,408 | —- | M] () [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\vburner.sys – (vburner)
DRV - [2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2007/10/18 07:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2005/12/12 13:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 98 55 60 38 D3 14 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/09 21:03:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/09 21:02:56 | 000,000,000 | —D | M]
[2011/05/29 15:35:20 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\mozilla\Extensions
[2011/05/29 15:35:27 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions
[2008/09/08 00:14:33 | 000,000,000 | —D | M] (Vista-aero) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}(189)
[2010/06/10 21:17:46 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/04 21:18:28 | 000,000,000 | —D | M] (IE Tab) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2008/12/01 11:37:35 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2011/05/25 16:35:35 | 000,000,000 | —D | M] (Awesome screenshot: Capture and Annotate) – C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\57iosvow.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\57iosvow.default\searchplugins\SearchquWebSearch.xml
[2011/05/29 15:35:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/25 17:01:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/05/09 20:56:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\57IOSVOW.DEFAULT\EXTENSIONS\{6E84150A-D526-41F1-A480-A67D3FED910D}.XPI
[2011/04/14 12:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BellCanada_UninstallTracking] File not found
O4 - HKLM..\Run: [BISA.exe] C:\Program Files\Bell\Internet Service Advisor\BISA.exe (Bell)
O4 - HKLM..\Run: [ConnectionManager] C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe (Sage Software)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [removeSearchqudatamngr] File not found
O4 - HKLM..\RunOnce: [removeSearchqutoolbar] File not found
O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/29 00:45:16 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\Windows\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/29 13:25:51 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{644ACA86-7A2E-45B5-B6B8-0C3515C00D94}
[2011/05/29 13:22:32 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{DACBE0D5-3E85-4B21-BAFE-A0F3E222AE39}
[2011/05/29 13:17:26 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{CD5B25B1-7A16-4B5A-9059-ACD449EEF833}
[2011/05/29 13:00:29 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{36F1F6BC-5FD1-4198-86FC-AE933C4FE385}
[2011/05/28 06:14:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{37B2D8B2-276E-43AC-959F-D1FF0B8FE69E}
[2011/05/27 19:58:48 | 000,000,000 | —D | C] – C:\recordings
[2011/05/27 19:51:42 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AudioStreamer Pro
[2011/05/27 19:51:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioStreamer Pro
[2011/05/27 19:51:07 | 000,000,000 | —D | C] – C:\Windows\AudioStreamer Pro
[2011/05/27 19:51:07 | 000,000,000 | —D | C] – C:\Program Files\AudioStreamer Pro
[2011/05/27 06:51:34 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{77BE3100-4DB4-474B-9E93-6819EDB7D983}
[2011/05/26 11:21:31 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{53090489-3478-47CF-A211-1F420FCC7285}
[2011/05/25 23:20:57 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{545A9942-B397-4B4A-BA24-91BDB7895B59}
[2011/05/25 17:11:53 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\OpenOffice.org
[2011/05/25 17:09:14 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2011/05/25 17:08:04 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2011/05/25 17:06:57 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/05/25 17:01:42 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/05/25 17:01:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/05/25 17:01:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/05/25 11:20:22 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{41CF8AA5-286A-4A00-AD94-3F60C02106FE}
[2011/05/24 23:19:29 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{653C79F2-B59B-409B-8B2C-CA41EB43B631}
[2011/05/24 09:13:35 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/05/24 09:12:50 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/05/24 09:12:36 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\PackageAware
[2011/05/24 08:57:07 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{77E19AC9-827D-4FB6-BCDF-98158C2D5B03}
[2011/05/23 13:12:03 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\2010 Top Cafe Taxes
[2011/05/23 09:25:27 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{29F759C5-AE61-40B0-8BF4-A32C71C8C7EF}
[2011/05/22 19:53:11 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{7BFF0B7F-2992-4565-A18E-8990238DDCC5}
[2011/05/20 10:10:53 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{5D5E4CE8-8275-4F0B-B875-F257A30EADAD}
[2011/05/19 09:01:02 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{57E6B5E5-3D59-439E-ABA6-048ECF0EE4D8}
[2011/05/18 22:33:13 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{A8E16545-F068-4CAE-950F-373CFFB99743}
[2011/05/18 09:45:21 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{35FBA623-15FB-4BD7-B0FA-746CB0919F56}
[2011/05/17 21:41:58 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{BC938204-08DE-4ABB-8F58-976ED5779383}
[2011/05/17 20:26:10 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/17 09:00:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{1A06BAE7-671E-4304-8965-CB97164D3C83}
[2011/05/16 09:46:52 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/16 09:20:12 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{921B75F1-655C-4B39-BA83-52C56994DADB}
[2011/05/16 00:31:02 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{5244478C-318F-4719-8D4C-808747CBC025}
[2011/05/15 11:10:33 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{65AF53E6-8F4C-4C98-A785-AE9DCDA88B67}
[2011/05/15 07:42:45 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{4845957C-A953-4A1B-AC0A-215406F7C526}
[2011/05/14 09:56:45 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{A3CFF85F-69F9-455F-80C6-0E11DB313373}
[2011/05/13 21:56:11 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\{66300D6B-1DCA-4C69-808C-5897B80E9188}
[2011/05/13 16:42:55 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/05/13 16:42:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/05/13 10:41:23 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2011/05/13 10:41:22 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/05/12 22:08:36 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/05/10 10:48:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaGet2
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Media Get LLC
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Media Get LLC
[2011/05/10 10:48:39 | 000,000,000 | —D | C] – C:\ProgramData\Media Get LLC
[2011/05/10 10:48:23 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\MediaGet2
[2011/05/09 20:57:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/05/09 20:55:58 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/05/09 17:41:16 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2011/05/09 17:36:49 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2011/05/09 17:36:43 | 000,000,000 | —D | C] – C:\Program Files\Bing Bar Installer
[2011/05/09 17:30:09 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Windows Live
[2011/05/09 17:29:37 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2011/05/09 17:20:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/09 17:20:42 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/09 17:20:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/09 17:20:42 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/09 17:20:42 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/09 17:20:42 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/09 17:20:42 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/09 17:20:42 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/09 17:20:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/09 17:20:41 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/09 17:20:41 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/09 17:20:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/09 17:20:41 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/09 17:20:41 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/09 17:20:41 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/09 17:20:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/09 17:20:41 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/09 17:20:41 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/09 17:20:41 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/09 17:20:41 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/09 17:20:41 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/09 17:20:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/09 17:20:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/09 17:20:41 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/09 17:20:40 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/09 17:20:40 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/09 17:20:40 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/09 17:20:40 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/09 17:20:40 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/09 17:20:40 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/09 17:20:40 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/09 17:20:40 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/09 17:20:40 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/09 17:20:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/09 17:20:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/09 17:20:40 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/09 17:20:40 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/09 17:20:40 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/09 17:20:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/09 17:18:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2011/05/09 17:17:48 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2011/05/09 17:17:48 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2011/05/09 17:17:48 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2011/05/09 17:17:46 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2011/05/09 17:17:46 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2011/05/09 17:17:43 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2011/05/09 17:17:43 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2011/05/09 17:17:43 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2011/05/09 17:17:43 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2011/05/09 17:17:42 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2011/05/09 17:17:35 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2011/05/09 17:17:35 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2011/05/09 17:17:35 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2011/05/09 17:17:35 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2011/05/09 17:17:35 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2011/05/09 17:16:18 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/05/09 17:16:18 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/05/09 17:16:17 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/05/09 17:16:16 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/05/09 17:16:15 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/05/09 17:16:15 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/05/09 17:16:15 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/05/09 17:16:15 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/05/09 17:16:10 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/05/09 17:16:09 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/05/09 16:07:36 | 000,025,608 | —- | C] (AVG Technologies ) – C:\Windows\System32\drivers\AVGIDSEH.sys
[2011/05/09 16:07:10 | 000,285,704 | —- | C] (BitDefender S.R.L. Bucharest, ROMANIA) – C:\Windows\System32\drivers\bdfsfltr.sys
[2011/05/09 16:06:50 | 000,000,000 | —D | C] – C:\ProgramData\Raxco
[2011/05/09 16:06:50 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2011/05/09 16:06:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bell Internet Security Services
[2 C:\Users\owner\AppData\Local\*.tmp files -> C:\Users\owner\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/29 18:25:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3346605070-2425595462-292171502-1000UA.job
[2011/05/29 18:12:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/29 17:24:50 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/29 17:24:50 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/29 15:25:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3346605070-2425595462-292171502-1000Core.job
[2011/05/29 15:12:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/29 14:27:01 | 000,648,388 | —- | M] () – C:\Users\owner\Documents\Casio_PCR-T2100_E071227A.pdf
[2011/05/29 13:24:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/29 13:24:45 | 3085,410,304 | -HS- | M] () – C:\hiberfil.sys
[2011/05/29 13:24:43 | 232,244,463 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/05/28 17:10:27 | 000,327,680 | —- | M] () – C:\Users\owner\Desktop\TakeOut Menu#2 2010.pub
[2011/05/28 14:55:07 | 000,002,609 | —- | M] () – C:\Users\owner\Desktop\Microsoft Office Word 2003.lnk
[2011/05/28 10:50:32 | 000,124,928 | —- | M] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2011.pub
[2011/05/28 10:50:26 | 000,124,928 | —- | M] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2010.pub
[2011/05/28 10:31:41 | 000,002,555 | —- | M] () – C:\Users\owner\Desktop\Microsoft Office Publisher 2003.lnk
[2011/05/27 19:46:19 | 000,678,592 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/27 19:46:19 | 000,143,068 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/25 23:14:53 | 000,368,672 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/25 17:12:31 | 000,001,030 | —- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/05/25 17:09:14 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/05/18 11:50:36 | 000,053,248 | —- | M] () – C:\Users\owner\Documents\may 22 2011 catering.pub
[2011/05/17 20:26:10 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/17 11:22:34 | 000,002,305 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/16 10:07:55 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/05/10 10:48:41 | 000,000,900 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaGet.lnk
[2011/05/09 21:03:01 | 000,000,872 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/09 21:03:01 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/09 17:48:08 | 000,000,945 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/09 17:20:53 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/05/09 17:20:53 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/05/09 17:20:42 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/05/09 17:20:42 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/09 17:20:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/05/09 17:20:42 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/09 17:20:42 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/05/09 17:20:42 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/09 17:20:42 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/05/09 17:20:42 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/05/09 17:20:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/05/09 17:20:41 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/09 17:20:41 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/09 17:20:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/05/09 17:20:41 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/09 17:20:41 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/05/09 17:20:41 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/09 17:20:41 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/05/09 17:20:41 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/05/09 17:20:41 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/05/09 17:20:41 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/05/09 17:20:41 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/09 17:20:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/05/09 17:20:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/09 17:20:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/05/09 17:20:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/05/09 17:20:41 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/09 17:20:40 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/09 17:20:40 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/05/09 17:20:40 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/05/09 17:20:40 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/05/09 17:20:40 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/05/09 17:20:40 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/05/09 17:20:40 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/09 17:20:40 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/09 17:20:40 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/05/09 17:20:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/05/09 17:20:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/05/09 17:20:40 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/09 17:20:40 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/09 17:20:40 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/09 17:20:39 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/05/09 16:08:24 | 120,922,400 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2011/05/09 16:08:24 | 001,621,616 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2011/05/09 16:07:08 | 000,053,192 | —- | M] (Radialpoint Inc.) – C:\Windows\System32\drivers\rp_skt32.sys
[2011/05/09 16:06:27 | 000,002,045 | —- | M] () – C:\Users\Public\Desktop\Bell Internet Security Services.lnk
[2 C:\Users\owner\AppData\Local\*.tmp files -> C:\Users\owner\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/29 14:27:01 | 000,648,388 | —- | C] () – C:\Users\owner\Documents\Casio_PCR-T2100_E071227A.pdf
[2011/05/28 10:50:32 | 000,124,928 | —- | C] () – C:\Users\owner\Documents\NewTopsMenu_Lunch_2011.pub
[2011/05/25 17:12:31 | 000,001,030 | —- | C] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/05/25 17:09:14 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/05/18 11:50:35 | 000,053,248 | —- | C] () – C:\Users\owner\Documents\may 22 2011 catering.pub
[2011/05/13 22:12:58 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2011/05/10 10:48:41 | 000,000,900 | —- | C] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaGet.lnk
[2011/05/09 21:03:01 | 000,000,860 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/09 21:03:01 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/09 17:48:08 | 000,000,945 | —- | C] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/09 17:38:38 | 000,002,027 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/05/09 17:20:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/05/09 17:17:37 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2011/05/09 17:17:37 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2011/05/09 17:17:37 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2011/05/09 16:06:27 | 000,002,045 | —- | C] () – C:\Users\Public\Desktop\Bell Internet Security Services.lnk
[2010/12/13 17:10:54 | 000,000,000 | —- | C] () – C:\Windows\PROTOCOL.INI
[2009/10/21 13:20:08 | 000,005,504 | —- | C] () – C:\Windows\System32\drivers\StarOpen_x86.sys
[2009/09/13 22:44:08 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/13 22:44:07 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/31 23:06:23 | 120,922,400 | -HS- | C] () – C:\Windows\System32\drivers\fidbox.dat
[2009/02/16 14:47:58 | 000,053,248 | —- | C] () – C:\Windows\System32\zlib.dll
[2009/02/16 10:13:51 | 000,000,572 | —- | C] () – C:\Windows\ODBCINST.INI
[2009/02/16 10:12:41 | 000,017,920 | —- | C] () – C:\Windows\System32\Implode.dll
[2008/09/11 23:04:35 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/05/18 18:18:34 | 000,017,408 | —- | C] () – C:\Windows\System32\drivers\vburner.sys
[2008/04/30 20:41:40 | 000,016,896 | —- | C] () – C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/24 09:39:48 | 000,000,940 | —- | C] () – C:\Windows\ODBC.INI
[2008/04/22 10:41:03 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2008/04/22 09:48:49 | 000,000,136 | —- | C] () – C:\Users\owner\AppData\Roaming\wklnhst.dat
[2008/04/19 09:42:15 | 000,000,680 | —- | C] () – C:\Users\owner\AppData\Local\d3d9caps.dat
[2007/11/29 00:38:28 | 000,102,451 | —- | C] () – C:\Windows\hpqins13.dat
[2007/11/29 00:25:22 | 000,061,440 | —- | C] () – C:\Windows\System32\OsdRemove.exe
[2007/11/29 00:22:37 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2007/11/29 00:22:37 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/08/09 15:59:54 | 000,114,688 | —- | C] () – C:\Windows\System32\myodbc3i.exe
[2007/08/09 15:59:54 | 000,106,496 | —- | C] () – C:\Windows\System32\myodbc3m.exe
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,368,672 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,678,592 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,143,068 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/08/17 08:53:03 | 000,401,408 | —- | C] () – C:\Windows\System32\StepButtonS.dll
[2005/05/19 19:56:26 | 000,491,520 | —- | C] () – C:\Windows\System32\mp3lib.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
========== Files - Unicode (All) ==========
[2009/08/31 23:03:56 | 000,000,036 | —- | M] ()(C:\Windows\System32\?????????????????4????????????????????????g) – C:\Windows\System32\㩃停潲牧浡䘠汩獥䉜汥屬敂汬䤠瑮牥敮⁴敓畣楲祴匠牥楶散屳慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
[2009/08/31 23:03:56 | 000,000,036 | —- | C] ()(C:\Windows\System32\?????????????????4????????????????????????g) – C:\Windows\System32\㩃停潲牧浡䘠汩獥䉜汥屬敂汬䤠瑮牥敮⁴敓畣楲祴匠牥楶散屳慓敦潃湮捥屴潃普杩塜楖睥挮湯楦g
< End of report >