Thanks again!
I ran OTL the first time without selecting all users, so I ran it a 2nd time and the 2nd time it only gave me one txt file (OTL.txt) so I pasted the 1st Extras.txt.
OTL.txt
OTL logfile created on: 11/24/2011 2:29:51 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jonathon\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.68 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 61.32% Memory free
7.35 Gb Paging File | 5.93 Gb Available in Paging File | 80.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 167.67 Gb Free Space | 58.77% Space Free | Partition Type: NTFS
Drive D: | 49.32 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 285.30 Gb Total Space | 167.67 Gb Free Space | 58.77% Space Free | Partition Type: NTFS
Computer Name: JONATHON-ACER | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/24 14:17:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jonathon\Downloads\OTL.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/20 18:34:08 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
PRC - [2009/11/01 18:40:52 | 001,100,368 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/09/30 23:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 23:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/24 18:42:32 | 000,261,888 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009/09/24 18:42:28 | 000,062,720 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009/09/11 00:42:30 | 000,349,480 | —- | M] (Egis Technology Inc.) – C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009/08/28 04:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009/08/04 16:09:34 | 000,199,464 | —- | M] (Egis Technology Inc.) – C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009/07/03 21:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/04 22:03:32 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 22:03:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
========== Modules (No Company Name) ==========
MOD - [2009/11/20 18:34:08 | 000,200,704 | —- | M] () – C:\Windows\PLFSetI.exe
MOD - [2009/02/02 20:33:56 | 000,460,199 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/11/20 14:23:46 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Disabled | Stopped] – C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE – (!SASCORE)
SRV:
64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:
64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:
64bit: - [2009/09/30 17:44:58 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe – (ePowerSvc)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:
64bit: - [2009/07/03 21:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Acer\Acer Updater\UpdaterService.exe – (Updater Service)
SRV:
64bit: - [2009/03/27 21:10:16 | 000,016,896 | —- | M] (LSI Corporation) [Auto | Running] – C:\Program Files\LSI SoftModem\agr64svc.exe – (AgereModemAudio)
SRV - [2011/09/28 03:09:58 | 001,148,632 | —- | M] (Crawler.com) [Disabled | Stopped] – C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe – (ST2012_Svc)
SRV - [2010/05/13 02:41:08 | 000,174,592 | —- | M] () [Disabled | Stopped] – C:\Program Files (x86)\Subsonic\subsonic-service.exe – (Subsonic)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 23:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 23:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/09/24 18:42:28 | 000,062,720 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/09/11 00:42:46 | 000,305,448 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe – (MWLService)
SRV - [2009/08/28 04:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 22:03:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/05/22 13:02:20 | 000,250,616 | —- | M] (WildTangent, Inc.) [Disabled | Stopped] – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe – (GameConsoleService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/11/20 07:57:45 | 000,051,496 | —- | M] (Windows ® Win 7 DDK provider) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\stflt.sys – (sp_rsdrv2)
DRV:
64bit: - [2011/08/31 19:53:22 | 012,306,848 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:
64bit: - [2011/07/22 11:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:
64bit: - [2011/07/12 16:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:
64bit: - [2011/04/29 13:34:32 | 000,100,864 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ser2pl64.sys – (Ser2pl)
DRV:
64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:
64bit: - [2009/10/30 09:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:
64bit: - [2009/10/26 15:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:
64bit: - [2009/10/16 01:33:06 | 000,050,176 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:
64bit: - [2009/10/05 16:34:00 | 001,542,656 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:
64bit: - [2009/09/17 23:12:06 | 000,292,912 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:
64bit: - [2009/09/17 15:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:
64bit: - [2009/08/13 14:20:46 | 001,209,856 | —- | M] (LSI Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agrsm64.sys – (AgereSoftModem)
DRV:
64bit: - [2009/08/06 07:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:
64bit: - [2009/07/22 17:06:26 | 000,040,448 | —- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AmUStor.sys – (AmUStor)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/06/19 21:09:57 | 000,054,272 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\L1E62x64.sys – (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:
64bit: - [2009/06/10 15:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2009/06/04 21:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:
64bit: - [2009/06/02 22:15:30 | 000,060,464 | —- | M] (Egis Technology Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys – (mwlPSDVDisk)
DRV:
64bit: - [2009/06/02 22:15:30 | 000,022,576 | —- | M] (Egis Technology Inc.) [File_System | System | Running] – C:\Windows\SysNative\drivers\mwlPSDFilter.sys – (mwlPSDFilter)
DRV:
64bit: - [2009/06/02 22:15:30 | 000,020,016 | —- | M] (Egis Technology Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mwlPSDNserv.sys – (mwlPSDNServ)
DRV:
64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:
64bit: - [2009/05/05 19:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:
64bit: - [2009/05/05 19:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:
64bit: - [2009/02/17 11:18:48 | 000,069,192 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ftdibus.sys – (FTDIBUS)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&a…18z1i5t5971d52n
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.youtube.com/watch?v=fsEbM77DD_U&NR=1|http://forums.corvetteforum.com/c5-tech/2916387-vengeance-racing-built-1999-427-c5-corvette-videos-dyno-graph-pics-inside.html|http://www.youtube.com/watch?v=EOd9Wd9l9LA|http://www.youtube.com/watch?v=WWHPyrp7BSM&feature=related|http://ls1tech.com/forums/generation-iii-internal-engine/1469330-heads-cam-problem.html|http://ls1tech.com/forums/generation-iii-internal-engine/1469308-finally-got-my-cam.html"
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Jonathon\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/14 20:11:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/16 18:56:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/11/21 21:51:52 | 000,000,000 | —D | M]
[2010/04/17 15:31:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Extensions
[2011/09/27 21:53:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions
[2010/12/31 11:41:40 | 000,000,000 | —D | M] (Image Zoom) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010/04/17 16:04:42 | 000,000,000 | —D | M] (Media Converter) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
[2010/04/17 16:08:53 | 000,000,000 | —D | M] (IE View Lite) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2011/04/30 21:06:30 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\[removed]
[2010/12/11 22:15:38 | 000,000,000 | —D | M] (vShare) – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\extensions\vshare@toolbar
[2010/10/23 20:57:41 | 000,001,583 | —- | M] () – C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\xa1zy04v.default\searchplugins\web-search.xml
[2011/11/14 20:11:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/16 23:21:15 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) – C:\USERS\JONATHON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XA1ZY04V.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 01:53:18 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:21:03 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:21:03 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/11/24 05:59:56 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:
64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files (x86)\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4272350839-2314675571-2890082633-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3}
http://caf.oeconnection.ca/ActiveX/DMSISM.CAB (ADPConn Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{079E895E-A34A-44CA-AB30-B5385D4D0B79}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{271FAE41-A699-468D-8B03-90E11F141682}: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/21 19:34:00 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/03/23 00:21:14 | 000,000,038 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/24 14:13:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C7D6F82E-2B81-4F61-AB2F-BF01787D9563}
[2011/11/24 14:13:03 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{26CD7851-8899-40C6-88A9-FAC0DEBF427C}
[2011/11/24 06:21:32 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/24 06:02:05 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/23 22:11:44 | 000,000,000 | —D | C] – C:\ComboFix
[2011/11/23 22:09:33 | 004,306,022 | R— | C] (Swearware) – C:\Users\Jonathon\Desktop\ComboFix.exe
[2011/11/23 19:27:14 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6AA4297C-E9C6-427F-9B3B-F0C6F32C9055}
[2011/11/23 19:27:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{393113E8-AECE-4319-90BF-AF3FC6459262}
[2011/11/22 19:59:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DD3E6170-5244-4968-AA33-B4C3EA46426C}
[2011/11/22 19:59:15 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{72DAF5E3-E635-4381-94F2-3BDC28AA38F1}
[2011/11/21 21:51:48 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2011/11/21 21:51:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/21 21:04:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2011/11/21 21:04:14 | 000,000,000 | —D | C] – C:\rei
[2011/11/21 21:04:03 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2011/11/21 19:33:33 | 000,000,000 | —D | C] – C:\sh4ldr
[2011/11/21 19:33:33 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2011/11/21 19:31:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2011/11/21 18:47:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{59104D40-4DDD-4E04-B96C-D8318CEC757F}
[2011/11/21 18:47:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4B05806E-3EA5-4EFE-B7B3-7227A9B872F3}
[2011/11/20 20:13:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C571EA19-CD91-4394-8FCB-292471306875}
[2011/11/20 20:13:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C48BDE04-8BE7-4AA2-A143-67494879B46A}
[2011/11/20 20:12:47 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{544BD090-ABBE-4179-83A5-0F1BEDF291D3}
[2011/11/20 20:12:37 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{192ADDE0-1229-42D2-9236-B2F696C7D2EB}
[2011/11/20 14:20:53 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/20 14:20:29 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/11/20 14:20:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/20 14:20:23 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/20 14:20:23 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/20 08:12:12 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{98F656C6-F277-4DC0-B7B0-A1CD4F6C2675}
[2011/11/20 08:12:03 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3A4D92DA-1309-4A5D-AFC9-1B91112CAB62}
[2011/11/20 08:11:53 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B7A5EBE1-71A4-484E-8DCF-D22AC55AEE67}
[2011/11/20 08:11:43 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AC801BF8-1680-444A-9EEA-5A9D43DDF989}
[2011/11/20 07:57:45 | 000,051,496 | —- | C] (Windows ® Win 7 DDK provider) – C:\Windows\SysNative\drivers\stflt.sys
[2011/11/20 07:57:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Spyware Terminator
[2011/11/20 07:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Spyware Terminator
[2011/11/20 07:57:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
[2011/11/20 07:56:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Terminator
[2011/11/19 20:11:14 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{93DADDCD-AAC2-4319-A4FE-64510192D718}
[2011/11/19 20:11:05 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5BD290F0-0FAD-4F64-973D-929A9639F61E}
[2011/11/19 20:10:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0B6981B5-28A5-4A11-9D6D-0A80F19D0942}
[2011/11/19 20:10:43 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{939604F1-D0CE-491C-AAC9-F5C536D3D90D}
[2011/11/19 08:10:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D5E3AEEC-E141-4C47-B220-C020C94EB956}
[2011/11/19 08:10:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{264A4101-A2FC-415E-B5CC-7F034D4C614A}
[2011/11/19 08:09:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4E60AE43-418A-419F-B0FC-B2AC9A88AF99}
[2011/11/19 08:08:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{76A652E4-576E-4CD8-BC0E-A57A89F6E076}
[2011/11/18 19:44:31 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C876AECA-F88F-491B-846E-1B79215C120B}
[2011/11/18 19:44:18 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8EC51DE4-F0F5-44E0-B87B-0A2A55C1E064}
[2011/11/18 19:44:04 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{74BF20F1-B07E-41A2-8D0E-A59F153B2627}
[2011/11/18 19:43:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{45E6B28D-9F87-48E6-AD10-19B8B1830246}
[2011/11/17 19:16:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{427B17F7-96C6-401F-B1E4-ABBA457BA26F}
[2011/11/17 19:16:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5C1222A0-47ED-4320-9368-AB8CBECCA924}
[2011/11/17 19:16:06 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E52430C3-F4CA-4A88-9AC9-7A5AB2F0E3C4}
[2011/11/17 19:15:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{26DBE823-26FD-468A-BEA7-E75F7DC7D1C0}
[2011/11/16 23:26:42 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Malwarebytes
[2011/11/16 23:26:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/16 23:26:30 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/16 23:26:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/16 20:09:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{43A61615-C088-4137-95C9-C9F1CCA6165A}
[2011/11/16 20:08:49 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E251BAF5-C81A-45F1-B994-73CAA968119E}
[2011/11/16 19:33:23 | 000,254,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2011/11/16 19:32:41 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/11/16 19:32:41 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/11/16 19:24:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\Documents\tdsskiller
[2011/11/15 19:51:38 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DA48C1CE-217E-463B-ADD6-524B5BEB175A}
[2011/11/15 19:51:28 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9C3D902E-F837-4644-B51E-E9161B6E6B4E}
[2011/11/15 19:29:45 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/11/15 19:29:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\Sunbelt Software
[2011/11/15 15:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2011/11/14 22:16:45 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/14 22:16:45 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/14 22:16:45 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/14 21:08:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/11/14 20:19:29 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CBEDCB74-6865-406A-AC82-A4EA990347DB}
[2011/11/14 20:19:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{271D71BE-43CC-475D-8447-6B430C56001A}
[2011/11/13 18:25:49 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/11/13 16:35:54 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/13 16:30:29 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/13 15:13:51 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4743913C-9D55-4A9D-97F6-E50A37143A28}
[2011/11/13 15:13:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3D2FE25C-6FDF-4BA5-98DD-5E5F9516DA2B}
[2011/11/13 15:09:22 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/11/13 10:40:11 | 000,000,000 | —D | C] – C:\ProgramData\Intel
[2011/11/13 10:24:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/13 10:24:33 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/13 10:20:38 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/11/13 01:38:57 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{A04CBDE0-FDBC-4DFF-BC7D-4C8903F9E1F1}
[2011/11/13 01:38:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2E43166C-37FC-4279-84B5-98A355ECCA23}
[2011/11/12 23:14:10 | 000,000,000 | —D | C] – C:\Windows\system64
[2011/11/12 16:52:46 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{553785EC-8732-4E77-8443-5B3870BE1285}
[2011/11/12 16:52:37 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E6F922C6-CE17-4C01-BF99-130FD9411720}
[2011/11/12 16:52:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{220F0B2B-7BAC-47FC-9A58-280C0FDBB36A}
[2011/11/11 19:16:33 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CF5CF72B-2834-4F65-96C3-CE1CCFA1F40A}
[2011/11/11 19:16:22 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EE1C2132-212C-445A-ABC6-C86637477195}
[2011/11/11 19:16:08 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{72479621-AB8F-4912-92A2-BCF28A392967}
[2011/11/10 21:20:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DC1DC940-3B42-4F28-BD7D-4F5F2D1C4D58}
[2011/11/10 21:20:15 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{BE3E2140-0C50-47F6-9914-78C53735BC3B}
[2011/11/10 21:20:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{E1DFE2F8-FDF2-4926-BF66-DFCA0C4EEB2A}
[2011/11/09 22:36:25 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DCE84556-2768-4907-B665-CE7711399C41}
[2011/11/09 22:36:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{DADFF1BB-BF20-4DC3-9D2F-E268B7D2911F}
[2011/11/08 22:01:32 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{930B9656-1152-439B-A529-784549A29527}
[2011/11/08 22:01:22 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1AD79A5D-B6A1-409B-8FA5-7E89A59FFED2}
[2011/11/07 19:29:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{430DE90D-6321-480B-9BC9-B626C6C3C173}
[2011/11/07 19:29:07 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9972C1BB-7B0E-4333-9D11-6E1D65C3981A}
[2011/11/06 21:33:20 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{57BD25F9-B4E7-45A5-8BB9-DA1533133D1E}
[2011/11/06 21:33:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4A33B707-5575-4A56-9F01-EF545BB32AF6}
[2011/11/06 21:33:01 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0D4CAD39-2BCD-41BC-9C2F-A3F7B3ACCCE8}
[2011/11/06 09:32:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AA5883A8-F72B-43A1-AF98-26DD9F0FDC3C}
[2011/11/06 09:32:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1D423E37-0ACE-430C-AD41-A72DDAA36B11}
[2011/11/06 09:32:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{841578C6-C738-464E-8849-1916130A2A79}
[2011/11/06 09:32:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{1B93BDE7-C294-450D-B2F6-F0D588B7F948}
[2011/11/05 21:31:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8248DC40-C05E-4589-99CA-EAB985EFF3F2}
[2011/11/05 21:31:36 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{0FBBD112-EAF4-4742-8D33-B29521B7CEA3}
[2011/11/05 21:31:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{859D8FA1-C098-4190-9537-FDFAA383972C}
[2011/11/05 07:56:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{74C3BA76-B617-4167-A805-42CA3933844A}
[2011/11/05 07:56:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6E98FBA0-F729-44B2-8A5F-5F05FF5607A3}
[2011/11/05 07:55:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D76FCB28-5479-486E-A98C-8863933F0293}
[2011/11/04 18:53:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EA5E3D54-0589-4220-A7C2-8FD6BE6FC67B}
[2011/11/04 18:53:01 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4A628A31-91CB-4246-B8C7-6AEF6E1E76ED}
[2011/11/04 18:52:50 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{396E8248-DE05-4FD9-BEFE-B714C70900A7}
[2011/11/03 18:49:54 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{913B6D51-6CDA-44B2-9F51-821A7E52BFE0}
[2011/11/03 18:49:44 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{70CE2689-DEBA-46AA-9FF7-A257B06769A6}
[2011/11/03 18:49:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9A6CD843-BE87-49AF-AE56-BD5607612BB3}
[2011/11/02 19:59:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3C794409-991C-4B72-97F3-01DA099BAFF4}
[2011/11/02 19:59:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{65223751-37A3-4741-9B6A-BCD261C94B66}
[2011/11/02 19:59:00 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F6C9D7AD-540C-4A20-AA25-66C76081C9E8}
[2011/11/02 19:58:47 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{7CA377D2-AF29-400E-9641-ED173A35D655}
[2011/11/01 18:33:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2251D5DE-58EF-436A-B335-95D840A6726A}
[2011/11/01 18:33:31 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F257E7F1-79B5-4B0A-B777-2C57CEAEC35C}
[2011/11/01 18:33:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{FD8FF9CF-A7A8-4DFF-B45B-F8D9C98E7B97}
[2011/11/01 18:33:11 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4898FE18-7D24-4106-A756-1AF50E8E7048}
[2011/10/31 18:25:56 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{20BAA1B1-0E01-49BB-998A-DD7B9555F27F}
[2011/10/31 18:25:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{00992023-066D-4EF7-899C-B698DCCCB780}
[2011/10/31 18:25:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{6FBB1D93-6DC1-47F8-AAFD-518A9AED6B78}
[2011/10/30 19:49:57 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{9DE798BD-1AC4-4EE1-A75C-4E45F67A98E8}
[2011/10/30 19:49:48 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{42FB7ED7-FC9F-4408-A4EE-67578ECD080D}
[2011/10/30 19:49:38 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5320BEF9-180C-4422-ADF0-64DECBBCEB8F}
[2011/10/30 18:50:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/10/30 07:49:17 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{83480B49-70E5-4DC9-A4CB-59F5896875DD}
[2011/10/30 07:49:07 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{A6C31C21-333B-4860-ADC1-5F5B57108604}
[2011/10/30 07:48:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{866A3738-DA0B-454B-B875-B6EFDA3EB0D3}
[2011/10/30 07:48:48 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{188914E9-3B80-4EFB-B55D-9ECAC68CBBF5}
[2011/10/29 19:48:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B590FA27-F45F-43B7-85B6-31D9D4F167BB}
[2011/10/29 19:48:10 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{D77B0EBC-1732-4046-B5E1-78C2D8ED6F63}
[2011/10/29 07:47:45 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{8428CA4A-A5B7-4DDA-A398-925874063E14}
[2011/10/29 07:47:35 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{5365644F-9B35-4E34-9C20-A0BE9CB04C54}
[2011/10/28 18:47:26 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{59477A08-BE31-4A3A-A0B6-45BBCCFABA61}
[2011/10/28 18:47:16 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{7BE2E7FD-E1B9-49A7-80AE-DCF1BEDCAA99}
[2011/10/27 18:15:19 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{CBDF218C-94D7-447A-8D95-9F22DD13B929}
[2011/10/27 18:15:09 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{AC2463B6-3AB2-4E01-8852-17CCE4C35952}
[2011/10/27 18:14:58 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{F5FDDFD6-245E-414C-BFF9-568D73C99D23}
[2011/10/26 18:30:02 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{401813B7-E637-4517-B4E6-DB72B66CC5E2}
[2011/10/26 18:29:51 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{B3724040-D8B9-4AF2-9C53-A3BA41C53995}
[2011/10/26 18:29:41 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{3663F61A-5078-4327-847D-0A067D6E9991}
[2011/10/26 18:29:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{4913299F-743E-4FA5-A13B-2212DB714297}
[2011/10/25 18:38:49 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{C6392C3E-F668-4ACD-B930-6A7CDA21F024}
[2011/10/25 18:38:40 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2E4F20A6-FCC1-403B-85E6-665C1AF05722}
[2011/10/25 18:38:30 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{EBBFF44C-EBD0-48CA-9187-A545A14ECB59}
[2011/10/25 18:38:21 | 000,000,000 | —D | C] – C:\Users\Jonathon\AppData\Local\{2DC16E38-F65A-4AA3-9964-DE6C0D693771}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/24 14:16:05 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/24 14:12:54 | 000,006,784 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/24 14:12:54 | 000,006,784 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/24 14:08:21 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/24 14:05:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/24 14:05:33 | 2960,506,880 | -HS- | M] () – C:\hiberfil.sys
[2011/11/24 05:59:56 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/23 22:09:44 | 004,306,022 | R— | M] (Swearware) – C:\Users\Jonathon\Desktop\ComboFix.exe
[2011/11/23 20:26:55 | 000,000,512 | —- | M] () – C:\Users\Jonathon\Desktop\MBR.dat
[2011/11/22 19:47:07 | 000,002,991 | —- | M] () – C:\Users\Jonathon\Desktop\HiJackThis.lnk
[2011/11/22 19:30:50 | 000,000,272 | —- | M] () – C:\Windows\reimage.ini
[2011/11/21 21:04:15 | 000,001,908 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2011/11/21 19:34:00 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2011/11/20 14:20:28 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 14:12:39 | 000,226,756 | —- | M] () – C:\Users\Jonathon\AppData\Local\census.cache
[2011/11/20 14:12:36 | 000,105,390 | —- | M] () – C:\Users\Jonathon\AppData\Local\ars.cache
[2011/11/20 07:57:45 | 000,051,496 | —- | M] (Windows ® Win 7 DDK provider) – C:\Windows\SysNative\drivers\stflt.sys
[2011/11/20 07:57:40 | 000,001,049 | —- | M] () – C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2011/11/20 00:46:52 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/11/20 00:46:52 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/11/19 20:28:35 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2011/11/16 23:26:32 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/15 16:48:46 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/11/15 06:33:31 | 000,007,591 | —- | M] () – C:\Users\Jonathon\AppData\Local\Resmon.ResmonCfg
[2011/11/14 21:08:24 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2011/11/14 21:08:05 | 000,735,726 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/14 21:08:05 | 000,631,002 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/14 21:08:05 | 000,112,054 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/14 20:11:41 | 000,002,056 | —- | M] () – C:\Users\Jonathon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/14 20:11:23 | 000,001,145 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/14 03:05:31 | 000,343,552 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/13 15:06:15 | 000,000,036 | —- | M] () – C:\Users\Jonathon\AppData\Local\housecall.guid.cache
[2011/11/10 22:24:36 | 000,093,844 | —- | M] () – C:\Users\Jonathon\Desktop\papa.jpg
[2011/11/10 22:22:24 | 000,490,924 | —- | M] () – C:\Users\Jonathon\Desktop\IMG_0862.JPG
[2011/11/06 20:14:24 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/30 18:50:29 | 000,002,219 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/23 20:26:55 | 000,000,512 | —- | C] () – C:\Users\Jonathon\Desktop\MBR.dat
[2011/11/22 19:47:07 | 000,002,991 | —- | C] () – C:\Users\Jonathon\Desktop\HiJackThis.lnk
[2011/11/21 21:05:27 | 000,000,272 | —- | C] () – C:\Windows\reimage.ini
[2011/11/21 21:04:15 | 000,001,908 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2011/11/21 19:34:00 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2011/11/20 14:20:28 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 07:57:40 | 000,001,049 | —- | C] () – C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
[2011/11/20 00:46:52 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/11/20 00:46:52 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/11/16 23:26:32 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/16 19:33:23 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2011/11/14 23:06:55 | 000,006,784 | -H– | C] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 23:06:55 | 000,006,784 | -H– | C] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/14 22:16:45 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/14 22:16:45 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/14 22:16:45 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/14 22:16:45 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/14 22:16:45 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/14 21:08:24 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2011/11/14 21:08:05 | 000,735,726 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/14 21:08:00 | 000,001,904 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/14 20:11:23 | 000,001,145 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/13 15:14:44 | 000,226,756 | —- | C] () – C:\Users\Jonathon\AppData\Local\census.cache
[2011/11/13 15:14:31 | 000,105,390 | —- | C] () – C:\Users\Jonathon\AppData\Local\ars.cache
[2011/11/13 15:06:15 | 000,000,036 | —- | C] () – C:\Users\Jonathon\AppData\Local\housecall.guid.cache
[2011/11/10 22:24:35 | 000,093,844 | —- | C] () – C:\Users\Jonathon\Desktop\papa.jpg
[2011/11/10 22:23:35 | 000,490,924 | —- | C] () – C:\Users\Jonathon\Desktop\IMG_0862.JPG
[2011/10/30 18:50:29 | 000,002,219 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2011/08/31 19:51:16 | 000,867,020 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/08/31 19:51:16 | 000,128,204 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/08/31 19:51:16 | 000,105,608 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/08/31 19:26:20 | 013,903,872 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011/06/29 06:26:41 | 000,126,769 | —- | C] () – C:\Windows\LogWorks3 Uninstaller.exe
[2011/04/03 21:01:11 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/09/11 21:53:10 | 000,007,591 | —- | C] () – C:\Users\Jonathon\AppData\Local\Resmon.ResmonCfg
[2010/08/06 19:27:21 | 000,114,685 | —- | C] () – C:\Windows\LogWorks Uninstaller.exe
[2010/06/03 17:16:32 | 000,020,534 | —- | C] () – C:\Windows\SysWow64\cwbunplp.exe
[2010/06/03 17:16:29 | 000,172,032 | —- | C] () – C:\Windows\SysWow64\cwbrw.dll
[2010/06/03 17:16:29 | 000,126,976 | —- | C] () – C:\Windows\cwbzip.exe
[2010/06/03 17:16:29 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\cwbsv.dll
[2010/06/03 17:16:29 | 000,020,529 | —- | C] () – C:\Windows\SysWow64\cwbwiz.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbsy.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbnl.dll
[2010/06/03 17:16:29 | 000,020,480 | —- | C] () – C:\Windows\SysWow64\cwbco.dll
[2010/06/03 17:16:29 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\cwbnldlg.dll
[2010/06/03 17:16:29 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\cwbad.dll
[2010/04/17 17:47:39 | 000,000,376 | —- | C] () – C:\Users\Jonathon\AppData\Roaming\wklnhst.dat
[2010/04/17 17:19:31 | 000,004,608 | —- | C] () – C:\Users\Jonathon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/17 15:31:12 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009/12/14 10:49:26 | 000,626,688 | —- | C] () – C:\Windows\Image.dll
[2009/12/14 10:49:26 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2009/12/14 10:49:26 | 000,020,480 | —- | C] () – C:\Windows\USB_VIDEO_REG.exe
[2009/12/14 10:49:26 | 000,000,323 | —- | C] () – C:\Windows\PidList.ini
[2009/12/14 10:32:09 | 000,001,233 | —- | C] () – C:\Windows\WPatchProgress.ini
[2009/11/04 19:21:23 | 000,000,193 | —- | C] () – C:\Windows\Prelaunch.ini
[2009/11/04 19:21:23 | 000,000,169 | —- | C] () – C:\Windows\WisLangCode.ini
[2009/11/04 19:21:23 | 000,000,147 | —- | C] () – C:\Windows\WisPriority.ini
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 000,982,196 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 16:59:36 | 000,139,824 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 16:59:36 | 000,097,448 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 16:59:35 | 000,417,344 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/06/12 19:45:08 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\DiskAid
[2011/04/29 22:10:14 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\DriverFinder
[2010/06/27 18:30:28 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Facebook
[2011/05/09 18:34:55 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\navionicsChartInstaller.Air.A3B2DB703D5E0A7ECA24FBD4B07176191EDD3C63.1
[2011/11/20 07:57:44 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Spyware Terminator
[2010/04/17 17:47:41 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Template
[2010/04/17 19:33:48 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\WildTangent
[2010/10/23 23:32:17 | 000,000,000 | —D | M] – C:\Users\Jonathon\AppData\Roaming\Windows Live Writer
[2011/10/08 07:54:39 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\system64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\ERDNT\cache86\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\ERDNT\cache64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\system64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\system64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< C:\Windows\assembly\tmp\U\*.* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\ZX14 105in 107ex:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\Spyder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\SKEETER:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\New Folder1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\JNG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Jonathon\Documents\APEX:Roxio EMC Stream
< End of report >
Extras.txt
OTL Extras logfile created on: 11/24/2011 2:21:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jonathon\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.68 Gb Total Physical Memory | 2.51 Gb Available Physical Memory | 68.29% Memory free
7.35 Gb Paging File | 6.08 Gb Available in Paging File | 82.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 168.37 Gb Free Space | 59.02% Space Free | Partition Type: NTFS
Drive D: | 49.32 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 285.30 Gb Total Space | 168.37 Gb Free Space | 59.02% Space Free | Partition Type: NTFS
Computer Name: JONATHON-ACER | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{2677AAE2-D8F8-40AE-9149-67618ED43EFD}_is1" = Trinity USB Drivers 1.1.1.1
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}" = Broadcom Gigabit NetLink Controller
"{B84E3B73-8A6D-434A-B656-327A560BDE24}" = cwbin64a
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"73FC7E42C8F05A3B5235FB18804B1F5C84709230" = Windows Driver Package - Innovate Motorsports Innovate USB Driver (10/12/2009 1.4.1.0)
"B1A8F7E99596998546E45BBBFC8B527A13989809" = Windows Driver Package - DIABLO (usbser) Ports (01/30/2009 1.1.1.1)
"LSI Soft Modem" = LSI HDA Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Reimage Repair" = Reimage Repair
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{021AC692-8CAC-43B3-8A10-EC6DEC3F9333}_is1" = version 1.0.4.0
"{08F32589-5E39-42B8-8BC5-6A8126ED2A70}" = Microsoft Visual C++ 2008 Redistributable Package
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{56736259-613E-4A3B-B428-6235F2E76F44}_is1" = Spyware Terminator 2012
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5EC8AAFD-0D89-958A-520B-E2B80B7FD016}" = Navionics Chart Installer
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{746104AD-F13F-4A32-8A03-2F6506C2E58E}" = Easy MSI Editor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7760D94E-B1B5-40A0-9AA0-ABF942108755}" = Acer Crystal Eye Webcam
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0568C61-9443-43F3-9938-E573A3BEFB7B}" = WinPEP 7
"{A723530D-EB71-47E6-BDCB-BAFF3C8FE329}" = DSLogRedux
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.6 MUI
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}" = iPhoneBrowser
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C82185E8-C27B-4EF4-2010-4444BC2C2B6D}" = Microsoft Streets & Trips 2010
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E7C669-B395-483C-9375-187CA8AE3340}" = HP Tuners VCM Suite 2.22
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"AC3Filter_is1" = AC3Filter 1.63b
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CleanUp!" = CleanUp!
"ClientAccessExpress" = IBM iSeries Access for Windows
"DSDownloader_is1" = DSDownloader [removed]
"Dynojet Display File Manager_is1" = Dynojet Display File Manager 1.0.3.2
"GridVista" = Acer GridVista
"HijackThis" = HijackThis 1.99.1
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{A0568C61-9443-43F3-9938-E573A3BEFB7B}" = WinPEP 7
"InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"LogonStudio" = LogonStudio
"LogWorks" = LogWorks
"LogWorks3" = LogWorks3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Power Commander 3 Usb_is1" = Power Commander Control Center 3.2.0 (Test Build 1)
"RADVideo" = RAD Video Tools
"Subsonic" = Subsonic
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.8
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"YTdetect" = Yahoo! Detect
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >