cbphgs
Topic Starter
HI
Hope you can help me out.
Spotted my system slowing down this morning and then antivirus picked up (and quarantined/deleted) a large number of items. Loaded up task manager and noticed ping.exe taking up a large amount of CPU. Did an end task, and a full system scan, but still getting some errors.
———————————–
OTL log below:
OTL logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS
Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
PRC - C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
PRC - C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TBFireWall.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TbTapeBrowse.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExImage.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExchBackupSize.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\EnumTapeDevice.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\CodeLog.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtNetwork4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtGui4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtCore4.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll ()
MOD - C:\Program Files\NVIDIA Corporation\nView\nvShell.dll ()
MOD - C:\WINDOWS\system32\mkunicode.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\mmfinfo.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naXML71.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naisign.dll ()
MOD - C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\zlib1.dll ()
MOD - C:\WINDOWS\system32\redmonnt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (AMService) – File not found
SRV - (vToolbarUpdater) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (Guard Agent) – C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (EaseUS Agent) – C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (PassThru Service) – C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Response Hardware) – C:\Program Files\SMART Technologies\SMART Response\ResponseHardwareService.exe (SMART Technologies)
SRV - (SMART SNMP Agent Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe (SMART Technologies ULC)
SRV - (SMART Display Controller) – C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
SRV - (SMART Board Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe (SMART Technologies)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (RalinkRegistryWriter) – C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (StkASSrv) – C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)
========== Driver Services (SafeList) ==========
DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (htcnprot) – C:\WINDOWS\system32\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (HTCAND32) – C:\WINDOWS\system32\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s125mgmt.sys (MCCI Corporation)
DRV - (s125obex) – C:\WINDOWS\system32\drivers\s125obex.sys (MCCI Corporation)
DRV - (s125mdm) – C:\WINDOWS\system32\drivers\s125mdm.sys (MCCI Corporation)
DRV - (s125mdfl) – C:\WINDOWS\system32\drivers\s125mdfl.sys (MCCI Corporation)
DRV - (s125bus) Sony Ericsson Device 125 driver (WDM) – C:\WINDOWS\system32\drivers\s125bus.sys (MCCI Corporation)
DRV - (StkAMini) – C:\WINDOWS\system32\drivers\StkAMini.sys (Syntek America Inc.)
DRV - (StkScan) – C:\WINDOWS\system32\drivers\StkScan.sys (Syntek America Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (WLAN(WLAN)) XPC 802.11b/g Wireless Kit Driver(WLAN) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\Lhidusb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCCFLTR.SYS (Logitech, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…5&mkt;=en-gb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\WINDOWS\system32\C2MP\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/03 13:42:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/05/17 19:09:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\AVG\AVG2012\Thunderbird\ [2011/12/03 13:40:05 | 000,000,000 | —D | M]
[2011/11/03 18:30:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/05/17 19:09:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/01/20 21:36:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions\avg@toolbar
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions\avg@toolbar
[2011/12/03 14:00:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/20 14:18:19 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/03 13:08:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/24 08:45:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/01/20 22:33:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2010/04/24 08:45:17 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/16 15:52:28 | 000,258,560 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\WINDOWS\system32\C2MP\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: EModel scriptable Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2_0\
CHR - Extension: Click to call with Skype = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\
CHR - Extension: Google Maps = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.1_0\
Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Nectar Search Toolbar BHO) - {B7C2F0D8-2209-4693-A15D-5A537211D48B} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [ATICustomerCare] c:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Backup & Storage] C:\Program Files\VirginMedia\V Stuff Backup\Backup & Storage.exe (F-Secure)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
O4 - HKLM..\Run: [ProcessLassoManagementConsole] C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
O4 - HKLM..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office 2000\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\system32\wshbth.dll File not found
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{304CF739-292E-4E2A-9414-76780C32B3A3}: NameServer = 192.168.1.1,194.168.4.100,194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{394666F2-4A2B-46A1-825F-B558D84F8CFE}: NameServer = 192.168.1.1,194.168.4.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B44340C7-9743-45CE-B533-6494F1628BE7}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E008F58B-BC5F-4520-A452-4F8D42130309}: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/18 14:02:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/03 17:18:15 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 14:31:46 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/12/03 14:04:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 14:03:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/12/03 13:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/12/03 13:42:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/12/03 13:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2011/12/03 13:41:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/12/03 13:41:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/12/03 13:39:17 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/12/03 13:38:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/12/03 13:33:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/12/03 13:32:33 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/12/03 12:39:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/26 08:49:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/26 08:49:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Anvsoft
[2011/11/26 08:48:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\AnvSoft
[2011/11/13 09:47:25 | 000,184,072 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\EuFdDisk.sys
[2011/11/13 09:47:24 | 000,038,920 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eubakup.sys
[2011/11/13 09:47:24 | 000,016,008 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eudskacs.sys
[2011/11/13 09:47:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EaseUS Todo Backup 3.5
[2011/11/13 09:45:58 | 000,020,616 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\fbnative.exe
[2011/11/13 09:45:30 | 000,000,000 | —D | C] – C:\Program Files\EaseUS
[2011/11/07 17:47:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\MagicISO
[2011/11/07 17:47:23 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\VirginMedia
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/11/06 17:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\VirginMedia
[2011/11/06 17:09:11 | 004,292,096 | —- | C] (dimastr.com) – C:\WINDOWS\System32\Redemption.dll
[2011/11/06 17:09:09 | 000,000,000 | —D | C] – C:\Program Files\VirginMedia
[2011/11/03 18:54:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 16:49:11 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003UA.job
[2011/12/03 14:17:58 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/03 13:50:42 | 000,000,065 | —- | M] () – C:\WINDOWS\iTouch.ini
[2011/12/03 13:50:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/03 13:50:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/12/03 13:46:10 | 071,994,407 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/02 13:49:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003Core.job
[2011/11/30 22:08:41 | 000,001,854 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spotify.lnk
[2011/11/19 13:49:50 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/12 03:15:55 | 000,000,024 | —- | M] () – C:\Documents and Settings\Owner\.idx
[2011/11/09 03:03:03 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\debutShakeIcon.job
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/03 13:46:10 | 071,994,407 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/03 13:33:13 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2011/12/03 13:25:25 | 021,067,257 | —- | C] () – C:\Documents and Settings\Owner\Desktop\McAfee8.5.zip
[2011/12/03 13:25:07 | 006,469,352 | —- | C] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/11/30 22:08:41 | 000,001,860 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Spotify.lnk
[2011/11/13 09:47:23 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/11/08 06:26:54 | 000,000,024 | —- | C] () – C:\Documents and Settings\Owner\.idx
[2011/08/12 20:30:59 | 000,314,632 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-484763869-412668190-725345543-1003-0.dat
[2011/07/26 07:57:48 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\u5xl0b2006300aa8rlh0r6
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\u5xl0b2006300aa8rlh0r6
[2011/05/02 16:04:20 | 000,212,198 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/05/02 12:06:30 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/29 14:34:32 | 000,000,087 | —- | C] () – C:\WINDOWS\bi_group.ini
[2011/04/23 07:05:44 | 000,043,136 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/21 20:40:15 | 000,037,211 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Comma Separated Values (Windows).ADR
[2011/04/08 21:14:56 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/01/27 16:58:56 | 000,000,054 | —- | C] () – C:\Documents and Settings\Owner\Application Data\tigersetting.dll
[2011/01/25 20:10:22 | 000,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2011/01/25 20:03:39 | 000,000,136 | —- | C] () – C:\WINDOWS\UNlock.dat
[2011/01/25 19:52:42 | 000,000,417 | —- | C] () – C:\WINDOWS\crackpdf.INI
[2011/01/22 14:18:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2010/12/23 13:25:28 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2010/12/23 13:25:04 | 000,014,640 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2010/12/23 13:25:04 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\drivers\rt2870.bin
[2010/12/17 13:38:04 | 000,231,792 | —- | C] () – C:\WINDOWS\libactivboardex.dll
[2010/12/17 13:37:48 | 000,257,888 | —- | C] () – C:\WINDOWS\ActivDRV.dll
[2010/10/27 07:51:54 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\init.dll
[2010/10/27 07:51:54 | 000,000,006 | —- | C] () – C:\Documents and Settings\Owner\Application Data\SYSTEM32.dll
[2010/10/27 07:51:44 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\sound.dll
[2010/10/27 07:50:14 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/10/27 07:50:03 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/09/26 16:00:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2010/09/26 15:21:08 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/24 12:39:25 | 000,000,954 | —- | C] () – C:\WINDOWS\exampro32.ini
[2010/08/24 12:39:23 | 000,536,576 | —- | C] () – C:\WINDOWS\System32\Tx32.dll
[2010/08/24 12:39:23 | 000,000,478 | —- | C] () – C:\WINDOWS\System32\ic32.ini
[2010/08/24 12:37:38 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2010/08/23 13:39:40 | 000,000,421 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/08/03 07:09:55 | 000,000,062 | —- | C] () – C:\WINDOWS\GPM2MICP.INI
[2010/08/02 20:04:51 | 000,348,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/13 14:24:04 | 000,000,297 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/03/29 17:55:44 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/03/26 18:18:10 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/03/26 18:17:54 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/03/26 18:17:54 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2010/03/26 18:17:52 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2010/03/26 18:17:52 | 000,224,342 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/03/26 18:17:52 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/02/07 16:03:31 | 000,000,449 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/02/07 16:03:30 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/02/07 16:03:12 | 000,000,088 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.inf
[2010/02/05 18:38:38 | 000,000,083 | —- | C] () – C:\WINDOWS\wwp.INI
[2010/01/24 15:00:14 | 000,058,368 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/24 14:28:06 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/24 08:28:29 | 000,000,167 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/01/21 21:04:28 | 000,000,065 | —- | C] () – C:\WINDOWS\iTouch.ini
[2010/01/21 19:59:46 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2010/01/20 21:36:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/19 22:44:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/19 22:44:07 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2010/01/12 20:18:20 | 001,409,890 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/01/12 20:18:18 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/01/12 20:18:18 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/12 20:18:16 | 004,507,983 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/12 20:18:10 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/01/12 20:18:10 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/01/12 20:18:10 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/01/12 20:18:10 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/01/12 20:18:10 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/12 20:18:10 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/01/12 20:18:08 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/01/12 20:18:08 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/01/12 20:18:08 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/01/12 20:18:08 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/01/12 20:12:36 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/01/01 00:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/01 00:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/11/14 18:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 18:33:40 | 000,357,888 | —- | C] () – C:\WINDOWS\System32\gdsmux.exe
[2009/11/14 18:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 18:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 18:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 18:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 18:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 18:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 18:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 18:11:36 | 000,136,704 | —- | C] () – C:\WINDOWS\System32\mkv2vfr.exe
[2009/11/14 18:11:36 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\dsmux.exe
[2009/11/14 18:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 18:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/11 20:21:26 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2009/01/18 14:11:06 | 000,006,136 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/01/18 14:09:28 | 002,283,526 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/01/18 14:04:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/18 14:00:43 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/18 13:54:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/18 13:51:58 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/10 22:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/12/03 22:11:50 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/06 16:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/13 22:53:22 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\JPeg32.dll
[2007/10/13 09:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/03/15 10:47:48 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\BuEResNT.dll
[2006/12/05 10:34:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/04/17 17:45:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\LEXPING.EXE
[2006/02/28 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 12:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 12:00:00 | 000,502,278 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 12:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 12:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 12:00:00 | 000,088,184 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 12:00:00 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2006/02/28 12:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 12:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 12:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 12:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 12:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 12:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/01/30 12:42:22 | 000,000,270 | —- | C] () – C:\WINDOWS\System32\lxczcoin.ini
[2003/03/24 04:03:00 | 000,279,552 | —- | C] () – C:\WINDOWS\System32\FGWVB32.DLL
[2002/11/13 07:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxczvs.dll
[2001/01/19 07:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
[1999/01/22 18:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2011/01/25 19:49:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2011/07/17 13:58:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activ Software
[2011/12/03 13:45:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/09/23 16:45:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Codemasters
[2011/12/03 13:41:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/09/26 18:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/12/23 13:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Edimax Driver
[2011/02/04 06:31:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/12/03 13:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/04/04 12:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/03/06 17:17:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PearlMountainSoft
[2011/07/17 14:19:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Promethean
[2011/04/08 21:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies
[2010/02/24 21:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies Inc
[2010/10/23 18:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/01/22 16:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2011/12/03 17:22:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/06 17:12:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/06/24 05:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\xml_param
[2011/04/08 05:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/22 07:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\4Media
[2011/07/17 13:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ACTIV Software
[2010/03/31 17:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/11/26 08:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2011/04/17 12:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ASAP Utilities
[2011/12/03 14:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 13:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:43:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DassaultSystemes
[2011/04/23 17:48:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Digiarty
[2011/03/22 21:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DocumentsToGoDesktopAndroid
[2011/11/10 19:45:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EA300
[2011/08/09 07:52:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Easy Watermark Studio
[2011/07/26 08:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EDrawings
[2011/10/30 06:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eMusic
[2010/09/02 15:11:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FCTB000061465
[2011/06/26 15:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flock
[2010/01/18 22:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2011/04/08 18:53:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2011/08/07 11:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC
[2011/08/07 11:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2010/12/04 11:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InfraRecorder
[2010/08/12 15:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mael
[2011/06/28 05:53:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MyPhoneExplorer
[2011/10/18 19:22:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2011/08/07 11:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Outlook
[2010/03/06 17:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PearlMountainSoft
[2010/09/01 08:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ProcessLasso
[2011/07/17 14:19:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Promethean
[2010/09/26 16:02:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/04/08 21:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies
[2010/02/24 21:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies Inc
[2010/11/30 15:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/12/03 13:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spotify
[2010/06/21 15:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Teleca
[2011/05/17 19:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Thunderbird
[2011/07/26 09:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/04/22 20:42:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Video DVD Maker FREE
[2010/02/09 19:04:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Voxmobili
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\debutShakeIcon.job
[2011/10/26 12:02:42 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\videopadShakeIcon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/04/28 19:04:47 | 000,001,457 | —- | M] () – C:\amg.xml
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/22 17:39:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/26 16:01:36 | 000,000,074 | —- | M] () – C:\CMLoader.log
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/08 20:43:08 | 000,129,050 | —- | M] () – C:\FlockInstaller.log
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/09/07 18:21:24 | 000,766,465 | —- | M] () – C:\Image0004.PDF
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/01/25 07:08:28 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/03 13:50:20 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/01/18 14:02:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/03/14 03:06:40 | 000,019,968 | —- | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\BuEProNT.dll
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/19 04:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 10:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/01/18 13:51:17 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/01/18 13:51:17 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/01/18 13:51:17 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/01/25 07:12:52 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/18 14:08:04 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2007/07/09 20:17:06 | 006,469,352 | —- | M] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-12 03:00:51
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB49169$] -> -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63CD0333
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
OTL Extras log
OTL Extras logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS
Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
jsfile [open] – "C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Compress folder to .wad] – "C:\Program Files\ZaZ Gp4 tools\Easywad.exe" /C "%l" (ZaZ)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5900:TCP" = 5900:TCP:LocalSubNet:Enabled:VNC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Infogrames\Grand Prix 4\GP4.exe" = C:\Program Files\Infogrames\Grand Prix 4\GP4.exe:*:Enabled:GP4 – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Team17\Worms World Party\wwp.exe" = C:\Team17\Worms World Party\wwp.exe:*:Enabled:Worms World Party – (Team17 Software Ltd)
"C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX – (Macromedia, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe" = C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe:*:Enabled:Nectar Search Toolbar (Helper) – (FreeCause Inc.)
"C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe" = C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe:*:Enabled:Nectar Search Toolbar (Update) – (FreeCause Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe" = C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe:*:Enabled:Amazon MP3 Downloader – (Amazon.com)
"C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe" = C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe:*:Enabled:SMART Response Software Service – (SMART Technologies)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe:*:Enabled:SMART Universal Controller Interface – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe:*:Enabled:SMART SNMPAgent – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe:*:Enabled:SMART Universal Controller Service – (SMART Technologies ULC)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Opera Next\opera.exe" = C:\Program Files\Opera Next\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe" = C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)
"C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B67D40E-01ED-43FC-8BD8-9CD284550766}" = SolidWorks eDrawings 2011
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{0E5DD7A3-BE29-430C-970B-C553F4A58C39}" = SMART Common Platform
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A3E23D7-7A1E-43EC-B35D-EB2A31BED943}" = Video DVD Maker v3.27.0.69
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = EDIMAX Edimax Wireless LAN
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32C747FB-2576-4503-B75D-DEE95161C60E}" = ActivInspire Core Resources (ENU) v1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{434D0831-A4CC-401A-9E74-621000018401}" = F1 2010
"{4451B8AB-D156-BA14-03EF-152E40A9DE48}" = ATI AVIVO Codecs
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C2E5A82-DA8B-4c72-91A6-EBB4E0463537}_is1" = Backup & Storage v2.3.1.37683
"{4CE6C6E8-0DAD-4757-86ED-7FB4035BA98B}" = SMART Product Drivers
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.75
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 2.5.7
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E599D8-0D7C-411F-BC18-5B80F13DF968}" = ActivInspire Help (GBR) v1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7D7715C0-9C0F-3F08-D326-1C6268AC5530}" = ATI Catalyst Install Manager
"{7F57E0DE-D0F7-47CC-A4AB-D21EB8E4BE48}" = ActivInspire v1
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8B4CE9CA-ECB7-47D1-845E-E1167FFB3F1B}" = SMART Response Software
"{8D4B716A-0ABE-4238-9090-D208E5F57A5E}" = SMART Product Update
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{914CEAB8-B2B7-1CCB-D0D4-5C472EAD6AAC}" = CCC Help English
"{936E2131-D9DB-42F9-96E7-52D2050ACB09}" = ActivDriver x86 v5.7
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9550F8A6-3D21-4544-8B87-F9FE7E01B964}" = SMART Notebook
"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EDF1A5D-D8E0-413E-9782-75DD4A8C831B}" = VideoCam Suite 2.0
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AEM384L1-28E3-1232-1233-1JD74JDIEK32}_is1" = PDFTigerDriver
"{B45FABE7-D101-4D99-A671-E16DA40AF7F0}" = Microsoft Games for Windows - LIVE
"{B539E69D-DD59-457D-A926-CF01ACA6D04C}" = Microsoft Image Composite Editor
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7FB0C86-41A4-4402-9A33-912C462042A0}" = Roxio Creator 9 LE
"{BB071E36-0596-4919-A5B5-608BFFE8673A}_is1" = ZaZ GP4 Tools 1.26
"{BD31FF1E-088E-A139-C772-7A5777529042}" = Catalyst Control Center Graphics Previews Common
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2EBC2F1-B766-4AE3-A10C-6EBBC1EE3B02}" = Data Sync
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C7D27207-0F86-4B6F-859C-21800A2C592E}" = Grand Prix 4
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE246151-F0E8-ABC8-AEB2-7F3E188EFBF5}" = TweetDeck
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D1F94690-C59F-4BF1-A9C5-012DCCE8364D}_is1" = X2X Free Video Trim 2.0
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.26 Game
"{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DB078F4F-FC74-4A07-9E07-A6623A18A667}" = ActivInspire HWR Resources (ENU) v1
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DE252510-5687-4C60-A705-C43E19F12C9D}_is1" = PDFTiger Kernel
"{DEB7B7C6-C931-08C3-1059-60C0AF3FB781}" = ccc-utility
"{DEEDF1BA-ADD7-6EA0-D017-A89ACAD64E9F}" = ccc-core-static
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F943B1DF-711F-7D8E-3257-ED05026895E1}" = Catalyst Control Center InstallProxy
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon Kindle For PC" = Amazon Kindle For PC v1.1
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"AnvSoft Photo Flash Maker Professional" = AnvSoft Photo Flash Maker Professional 5.40
"Any Video Converter_is1" = Any Video Converter 3.0.4
"A-PDF Restrictions Remover_is1" = A-PDF Restrictions Remover 1.6
"Artensoft Photo Mosaic Wizard_is1" = Artensoft Photo Mosaic Wizard
"ASAP Utilities_is1" = ASAP Utilities
"Audacity_is1" = Audacity 1.2.6
"AVG" = AVG 2012
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Daniusoft MOD Converter_is1" = Daniusoft MOD Converter(Build [removed])
"Daniusoft Video Converter_is1" = Daniusoft Video Converter(Build 2.3.2.0)
"Debut" = Debut Video Capture Software
"DTGDesktop-Android" = Documents To Go Desktop for Android
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EA300 DVD-ROM" = EA300 DVD-ROM
"EaseUS Todo Backup Free 3.5_is1" = EaseUS Todo Backup Free 3.5
"Easy Watermark Studio3.1" = Easy Watermark Studio
"Exampro AA_MACO" = Exampro AQA GCE Core Mathematics
"Exampro AA_MAME" = Exampro AQA GCE Mechanics
"Exampro AA_MAST" = Exampro AQA GCE Statistics
"get_iplayer" = get_iplayer 4.2
"GPL Ghostscript 9.00" = GPL Ghostscript 9.00
"HandBrake" = HandBrake 0.9.5
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hugin" = Hugin 2010.4.0
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"InfraRecorder" = InfraRecorder
"JPG2PDF_is1" = JPG2PDF 2.2
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lexmark 1200 Series" = Lexmark 1200 Series
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicScore_is1" = MagicScore
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird (3.1.10)" = Mozilla Thunderbird (3.1.10)
"MPE" = MyPhoneExplorer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nectar Search Toolbar" = Nectar Search Toolbar
"Need For Speed High Stakes" = Need For Speed Road Challenge
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Opera 11.52.1100" = Opera 11.52
"Opera 12.00.1116" = Opera Next 12.00 alpha build 1116
"pdfsam" = pdfsam
"PDFTiger_is1" = PDFTiger
"ProcessLasso" = Process Lasso
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.3
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Shockwave" = Shockwave
"Sierra Utilities" = Sierra Utilities
"Simple Family Tree" = Simple Family Tree (remove only)
"Spotify" = Spotify
"Steam App 410" = Portal: First Slice
"Testbase UK_MT" = Testbase UKMT Challenge Questions
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 1.1.10
"Wdf01001" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 2.0.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{EE19063F-7048-4094-9A1D-D69D9C591119}_is1" = Albelli Photo books
"GeoGebra WebStart" = GeoGebra WebStart
"Google Chrome" = Google Chrome
"Spotify" = Spotify
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 03/12/2011 04:04:18 | Computer Name = DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application GPxPatch.exe, version 3.9.3.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 03/12/2011 08:48:15 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 08:49:00 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 08:58:06 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 09:03:02 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 09:47:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:03:44 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:05:11 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:14:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:18:16 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
[ OSession Events ]
Error - 02/01/2011 03:26:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 96
seconds with 60 seconds of active time. This session ended with a crash.
Error - 02/01/2011 03:27:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 29
seconds with 0 seconds of active time. This session ended with a crash.
Error - 03/06/2011 01:26:49 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 34 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 03/12/2011 13:10:40 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:10:54 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:13:34 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:14:36 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:14:38 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:16:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:17:46 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:19:31 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:21:05 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:23:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
< End of report >
Hope you can help me out.
Spotted my system slowing down this morning and then antivirus picked up (and quarantined/deleted) a large number of items. Loaded up task manager and noticed ping.exe taking up a large amount of CPU. Did an end task, and a full system scan, but still getting some errors.
———————————–
OTL log below:
OTL logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS
Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
PRC - C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
PRC - C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)
PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TBFireWall.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\TbTapeBrowse.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExImage.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\ExchBackupSize.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\EnumTapeDevice.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\CodeLog.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtNetwork4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtGui4.dll ()
MOD - C:\Program Files\SMART Technologies\SMART Product Drivers\QtCore4.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll ()
MOD - C:\Program Files\NVIDIA Corporation\nView\nvShell.dll ()
MOD - C:\WINDOWS\system32\mkunicode.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\mmfinfo.dll ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naXML71.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naisign.dll ()
MOD - C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()
MOD - C:\Program Files\EaseUS\Todo Backup\bin\zlib1.dll ()
MOD - C:\WINDOWS\system32\redmonnt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (AMService) – File not found
SRV - (vToolbarUpdater) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (Guard Agent) – C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (EaseUS Agent) – C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (CHENGDU YIWO Tech Development Co., Ltd)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (PassThru Service) – C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Response Hardware) – C:\Program Files\SMART Technologies\SMART Response\ResponseHardwareService.exe (SMART Technologies)
SRV - (SMART SNMP Agent Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe (SMART Technologies ULC)
SRV - (SMART Display Controller) – C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe (SMART Technologies ULC)
SRV - (SMART Board Service) – C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe (SMART Technologies)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (RalinkRegistryWriter) – C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe (Ralink Technology, Corp.)
SRV - (bgsvcgen) – C:\WINDOWS\System32\bgsvcgen.exe (B.H.A Corporation)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (StkASSrv) – C:\WINDOWS\system32\StkASv2K.exe (Syntek America Inc.)
========== Driver Services (SafeList) ==========
DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (htcnprot) – C:\WINDOWS\system32\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (HTCAND32) – C:\WINDOWS\system32\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s125mgmt.sys (MCCI Corporation)
DRV - (s125obex) – C:\WINDOWS\system32\drivers\s125obex.sys (MCCI Corporation)
DRV - (s125mdm) – C:\WINDOWS\system32\drivers\s125mdm.sys (MCCI Corporation)
DRV - (s125mdfl) – C:\WINDOWS\system32\drivers\s125mdfl.sys (MCCI Corporation)
DRV - (s125bus) Sony Ericsson Device 125 driver (WDM) – C:\WINDOWS\system32\drivers\s125bus.sys (MCCI Corporation)
DRV - (StkAMini) – C:\WINDOWS\system32\drivers\StkAMini.sys (Syntek America Inc.)
DRV - (StkScan) – C:\WINDOWS\system32\drivers\StkScan.sys (Syntek America Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\cdrbsdrv.sys (B.H.A Corporation)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (WLAN(WLAN)) XPC 802.11b/g Wireless Kit Driver(WLAN) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (itchfltr) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\Lhidusb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
DRV - (LCcfltr) – C:\WINDOWS\system32\drivers\LCCFLTR.SYS (Logitech, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…5&mkt;=en-gb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\WINDOWS\system32\C2MP\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/03 13:42:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.6\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components [2011/06/26 15:57:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/09/20 05:12:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/05/17 19:09:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\AVG\AVG2012\Thunderbird\ [2011/12/03 13:40:05 | 000,000,000 | —D | M]
[2011/11/03 18:30:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/05/17 19:09:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/01/20 21:36:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions
[2011/12/03 13:42:12 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\0kmlj45t.default\extensions\avg@toolbar
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions
[2011/12/03 13:42:13 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fzsbi80z.default\extensions\avg@toolbar
[2011/12/03 14:00:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/20 14:18:19 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/03 13:08:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/24 08:45:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/01/20 22:33:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2010/04/24 08:45:17 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/16 15:52:28 | 000,258,560 | —- | M] (Dassault Systèmes SolidWorks Corp.) – C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\WINDOWS\system32\C2MP\npdivx32.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: EModel scriptable Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npEModelPlugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2_0\
CHR - Extension: Click to call with Skype = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\
CHR - Extension: Google Maps = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.1_0\
Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Nectar Search Toolbar BHO) - {B7C2F0D8-2209-4693-A15D-5A537211D48B} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Nectar Search Toolbar) - {8020143D-5926-4394-A04D-DD0B649DA121} - C:\Program Files\Nectar Search Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [ATICustomerCare] c:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Backup & Storage] C:\Program Files\VirginMedia\V Stuff Backup\Backup & Storage.exe (F-Secure)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum Technologies)
O4 - HKLM..\Run: [ProcessLassoManagementConsole] C:\Program Files\Process Lasso\ProcessLasso.exe (Bitsum Technologies)
O4 - HKLM..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office 2000\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\system32\wshbth.dll File not found
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{304CF739-292E-4E2A-9414-76780C32B3A3}: NameServer = 192.168.1.1,194.168.4.100,194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{394666F2-4A2B-46A1-825F-B558D84F8CFE}: NameServer = 192.168.1.1,194.168.4.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B44340C7-9743-45CE-B533-6494F1628BE7}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E008F58B-BC5F-4520-A452-4F8D42130309}: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/18 14:02:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3856dea9-e566-11dd-a677-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/03 17:18:15 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 14:31:46 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/12/03 14:04:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 14:03:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2011/12/03 13:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/12/03 13:42:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/12/03 13:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2011/12/03 13:41:56 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2011/12/03 13:41:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/12/03 13:41:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/12/03 13:39:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/12/03 13:39:17 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/12/03 13:38:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/12/03 13:33:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/12/03 13:32:33 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/12/03 12:39:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:39:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/26 08:49:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/26 08:49:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Anvsoft
[2011/11/26 08:48:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\AnvSoft
[2011/11/13 09:47:25 | 000,184,072 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\EuFdDisk.sys
[2011/11/13 09:47:24 | 000,038,920 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eubakup.sys
[2011/11/13 09:47:24 | 000,016,008 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\drivers\eudskacs.sys
[2011/11/13 09:47:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EaseUS Todo Backup 3.5
[2011/11/13 09:45:58 | 000,020,616 | —- | C] (CHENGDU YIWO Tech Development Co., Ltd) – C:\WINDOWS\System32\fbnative.exe
[2011/11/13 09:45:30 | 000,000,000 | —D | C] – C:\Program Files\EaseUS
[2011/11/07 17:47:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\MagicISO
[2011/11/07 17:47:23 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\VirginMedia
[2011/11/06 17:12:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/11/06 17:09:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\VirginMedia
[2011/11/06 17:09:11 | 004,292,096 | —- | C] (dimastr.com) – C:\WINDOWS\System32\Redemption.dll
[2011/11/06 17:09:09 | 000,000,000 | —D | C] – C:\Program Files\VirginMedia
[2011/11/03 18:54:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Downloads
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/03 16:49:11 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003UA.job
[2011/12/03 14:17:58 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/03 13:50:42 | 000,000,065 | —- | M] () – C:\WINDOWS\iTouch.ini
[2011/12/03 13:50:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/03 13:50:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/12/03 13:46:10 | 071,994,407 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/02 13:49:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-412668190-725345543-1003Core.job
[2011/11/30 22:08:41 | 000,001,854 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spotify.lnk
[2011/11/19 13:49:50 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/12 03:15:55 | 000,000,024 | —- | M] () – C:\Documents and Settings\Owner\.idx
[2011/11/09 03:03:03 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\debutShakeIcon.job
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/03 13:46:10 | 071,994,407 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/03 13:46:10 | 000,619,258 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/12/03 13:33:13 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2011/12/03 13:25:25 | 021,067,257 | —- | C] () – C:\Documents and Settings\Owner\Desktop\McAfee8.5.zip
[2011/12/03 13:25:07 | 006,469,352 | —- | C] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/11/30 22:08:41 | 000,001,860 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Spotify.lnk
[2011/11/13 09:47:23 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/11/08 06:26:54 | 000,000,024 | —- | C] () – C:\Documents and Settings\Owner\.idx
[2011/08/12 20:30:59 | 000,314,632 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-484763869-412668190-725345543-1003-0.dat
[2011/07/26 07:57:48 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\u5xl0b2006300aa8rlh0r6
[2011/06/25 10:06:12 | 000,015,060 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\u5xl0b2006300aa8rlh0r6
[2011/05/02 16:04:20 | 000,212,198 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/05/02 12:06:30 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/29 14:34:32 | 000,000,087 | —- | C] () – C:\WINDOWS\bi_group.ini
[2011/04/23 07:05:44 | 000,043,136 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/04/21 20:40:15 | 000,037,211 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Comma Separated Values (Windows).ADR
[2011/04/08 21:14:56 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/01/27 16:58:56 | 000,000,054 | —- | C] () – C:\Documents and Settings\Owner\Application Data\tigersetting.dll
[2011/01/25 20:10:22 | 000,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2011/01/25 20:03:39 | 000,000,136 | —- | C] () – C:\WINDOWS\UNlock.dat
[2011/01/25 19:52:42 | 000,000,417 | —- | C] () – C:\WINDOWS\crackpdf.INI
[2011/01/22 14:18:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2010/12/23 13:25:28 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2010/12/23 13:25:04 | 000,014,640 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2010/12/23 13:25:04 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\drivers\rt2870.bin
[2010/12/17 13:38:04 | 000,231,792 | —- | C] () – C:\WINDOWS\libactivboardex.dll
[2010/12/17 13:37:48 | 000,257,888 | —- | C] () – C:\WINDOWS\ActivDRV.dll
[2010/10/27 07:51:54 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\init.dll
[2010/10/27 07:51:54 | 000,000,006 | —- | C] () – C:\Documents and Settings\Owner\Application Data\SYSTEM32.dll
[2010/10/27 07:51:44 | 000,000,701 | —- | C] () – C:\Documents and Settings\Owner\Application Data\sound.dll
[2010/10/27 07:50:14 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/10/27 07:50:03 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/09/26 16:00:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2010/09/26 15:21:08 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/24 12:39:25 | 000,000,954 | —- | C] () – C:\WINDOWS\exampro32.ini
[2010/08/24 12:39:23 | 000,536,576 | —- | C] () – C:\WINDOWS\System32\Tx32.dll
[2010/08/24 12:39:23 | 000,000,478 | —- | C] () – C:\WINDOWS\System32\ic32.ini
[2010/08/24 12:37:38 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2010/08/23 13:39:40 | 000,000,421 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/08/03 07:09:55 | 000,000,062 | —- | C] () – C:\WINDOWS\GPM2MICP.INI
[2010/08/02 20:04:51 | 000,348,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/13 14:24:04 | 000,000,297 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/03/29 17:55:44 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/03/26 18:18:10 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/03/26 18:17:54 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/03/26 18:17:54 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2010/03/26 18:17:52 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2010/03/26 18:17:52 | 000,224,342 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/03/26 18:17:52 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/02/07 16:03:31 | 000,000,449 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/02/07 16:03:30 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/02/07 16:03:12 | 000,000,088 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.inf
[2010/02/05 18:38:38 | 000,000,083 | —- | C] () – C:\WINDOWS\wwp.INI
[2010/01/24 15:00:14 | 000,058,368 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/24 14:28:06 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/24 08:28:29 | 000,000,167 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/01/21 21:04:28 | 000,000,065 | —- | C] () – C:\WINDOWS\iTouch.ini
[2010/01/21 19:59:46 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2010/01/20 21:36:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/01/19 22:44:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/19 22:44:07 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2010/01/12 20:18:20 | 001,409,890 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/01/12 20:18:18 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/01/12 20:18:18 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/12 20:18:16 | 004,507,983 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/12 20:18:10 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/01/12 20:18:10 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/01/12 20:18:10 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/01/12 20:18:10 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/01/12 20:18:10 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/12 20:18:10 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/01/12 20:18:08 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/01/12 20:18:08 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/01/12 20:18:08 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/01/12 20:18:08 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/01/12 20:12:36 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/01/01 00:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/01 00:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/11/14 18:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 18:33:40 | 000,357,888 | —- | C] () – C:\WINDOWS\System32\gdsmux.exe
[2009/11/14 18:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 18:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 18:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 18:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 18:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 18:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 18:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 18:11:36 | 000,136,704 | —- | C] () – C:\WINDOWS\System32\mkv2vfr.exe
[2009/11/14 18:11:36 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\dsmux.exe
[2009/11/14 18:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 18:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/11 20:21:26 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2009/01/18 14:11:06 | 000,006,136 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/01/18 14:09:28 | 002,283,526 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/01/18 14:04:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/18 14:00:43 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/01/18 13:54:33 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/18 13:51:58 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/10 22:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/12/03 22:11:50 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/06 16:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/13 22:53:22 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\JPeg32.dll
[2007/10/13 09:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/03/15 10:47:48 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\BuEResNT.dll
[2006/12/05 10:34:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/04/17 17:45:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\LEXPING.EXE
[2006/02/28 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 12:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 12:00:00 | 000,502,278 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 12:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 12:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 12:00:00 | 000,088,184 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 12:00:00 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2006/02/28 12:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 12:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 12:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 12:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 12:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 12:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/01/30 12:42:22 | 000,000,270 | —- | C] () – C:\WINDOWS\System32\lxczcoin.ini
[2003/03/24 04:03:00 | 000,279,552 | —- | C] () – C:\WINDOWS\System32\FGWVB32.DLL
[2002/11/13 07:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxczvs.dll
[2001/01/19 07:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
[1999/01/22 18:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2011/01/25 19:49:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2011/07/17 13:58:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activ Software
[2011/12/03 13:45:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/09/23 16:45:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Codemasters
[2011/12/03 13:41:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/09/26 18:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/12/23 13:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Edimax Driver
[2011/02/04 06:31:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/12/03 13:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/04/04 12:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/03/06 17:17:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PearlMountainSoft
[2011/07/17 14:19:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Promethean
[2011/04/08 21:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies
[2010/02/24 21:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies Inc
[2010/10/23 18:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/01/22 16:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2011/12/03 17:22:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/06 17:12:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirginMedia
[2011/06/24 05:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\xml_param
[2011/04/08 05:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/22 07:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\4Media
[2011/07/17 13:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ACTIV Software
[2010/03/31 17:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/11/26 08:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2011/04/17 12:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ASAP Utilities
[2011/12/03 14:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/12/03 13:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG Secure Search
[2011/12/03 13:43:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG2012
[2011/07/26 07:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DassaultSystemes
[2011/04/23 17:48:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Digiarty
[2011/03/22 21:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DocumentsToGoDesktopAndroid
[2011/11/10 19:45:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EA300
[2011/08/09 07:52:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Easy Watermark Studio
[2011/07/26 08:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EDrawings
[2011/10/30 06:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eMusic
[2010/09/02 15:11:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FCTB000061465
[2011/06/26 15:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flock
[2010/01/18 22:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2011/04/08 18:53:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2011/08/07 11:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC
[2011/08/07 11:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2010/12/04 11:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InfraRecorder
[2010/08/12 15:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mael
[2011/06/28 05:53:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MyPhoneExplorer
[2011/10/18 19:22:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2011/08/07 11:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Outlook
[2010/03/06 17:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2011/04/27 16:56:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PearlMountainSoft
[2010/09/01 08:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ProcessLasso
[2011/07/17 14:19:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Promethean
[2010/09/26 16:02:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/04/08 21:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies
[2010/02/24 21:37:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SMART Technologies Inc
[2010/11/30 15:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/12/03 13:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spotify
[2010/06/21 15:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Teleca
[2011/05/17 19:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Thunderbird
[2011/07/26 09:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/04/22 20:42:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Video DVD Maker FREE
[2010/02/09 19:04:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Voxmobili
[2011/11/07 13:39:01 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\debutShakeIcon.job
[2011/10/26 12:02:42 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\videopadShakeIcon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/04/28 19:04:47 | 000,001,457 | —- | M] () – C:\amg.xml
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/22 17:39:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/26 16:01:36 | 000,000,074 | —- | M] () – C:\CMLoader.log
[2009/01/18 14:02:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/08 20:43:08 | 000,129,050 | —- | M] () – C:\FlockInstaller.log
[2011/12/03 13:50:25 | 3220,557,824 | -HS- | M] () – C:\hiberfil.sys
[2011/09/07 18:21:24 | 000,766,465 | —- | M] () – C:\Image0004.PDF
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/18 14:02:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/01/25 07:08:28 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/03 13:50:20 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/01/18 14:02:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/03/14 03:06:40 | 000,019,968 | —- | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\BuEProNT.dll
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/19 04:33:38 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 10:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/01/18 13:51:17 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/01/18 13:51:17 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/01/18 13:51:17 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/01/25 07:12:52 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/18 14:08:04 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2007/07/09 20:17:06 | 006,469,352 | —- | M] () – C:\Documents and Settings\Owner\Desktop\avgas-setup-7.5.0.50.exe
[2011/12/03 17:18:15 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/03 17:14:18 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-12 03:00:51
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB49169$] -> -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63CD0333
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
OTL Extras log
OTL Extras logfile created on: 03/12/2011 17:16:35 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 70.12% Memory free
4.25 Gb Paging File | 3.17 Gb Available in Paging File | 74.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 51.44 Gb Free Space | 34.51% Space Free | Partition Type: NTFS
Computer Name: DESKTOP | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
jsfile [open] – "C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Compress folder to .wad] – "C:\Program Files\ZaZ Gp4 tools\Easywad.exe" /C "%l" (ZaZ)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5900:TCP" = 5900:TCP:LocalSubNet:Enabled:VNC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Infogrames\Grand Prix 4\GP4.exe" = C:\Program Files\Infogrames\Grand Prix 4\GP4.exe:*:Enabled:GP4 – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Team17\Worms World Party\wwp.exe" = C:\Team17\Worms World Party\wwp.exe:*:Enabled:Worms World Party – (Team17 Software Ltd)
"C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX – (Macromedia, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe" = C:\Program Files\Nectar Search Toolbar\TroubleShooter.exe:*:Enabled:Nectar Search Toolbar (Helper) – (FreeCause Inc.)
"C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe" = C:\Program Files\Nectar Search Toolbar\ToolbarUpdate.exe:*:Enabled:Nectar Search Toolbar (Update) – (FreeCause Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe" = C:\Program Files\Amazon\MP3 Downloader\AmazonMP3Downloader.exe:*:Enabled:Amazon MP3 Downloader – (Amazon.com)
"C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe" = C:\Program Files\SMART Technologies\SMART Response\ResponseSoftwareService.exe:*:Enabled:SMART Response Software Service – (SMART Technologies)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCGui.exe:*:Enabled:SMART Universal Controller Interface – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe:*:Enabled:SMART SNMPAgent – (SMART Technologies ULC)
"C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe" = C:\Program Files\SMART Technologies\SMART Product Drivers\UCService.exe:*:Enabled:SMART Universal Controller Service – (SMART Technologies ULC)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Opera Next\opera.exe" = C:\Program Files\Opera Next\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe" = C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)
"C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Owner\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B67D40E-01ED-43FC-8BD8-9CD284550766}" = SolidWorks eDrawings 2011
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{0E5DD7A3-BE29-430C-970B-C553F4A58C39}" = SMART Common Platform
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A3E23D7-7A1E-43EC-B35D-EB2A31BED943}" = Video DVD Maker v3.27.0.69
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = EDIMAX Edimax Wireless LAN
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32C747FB-2576-4503-B75D-DEE95161C60E}" = ActivInspire Core Resources (ENU) v1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{434D0831-A4CC-401A-9E74-621000018401}" = F1 2010
"{4451B8AB-D156-BA14-03EF-152E40A9DE48}" = ATI AVIVO Codecs
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C2E5A82-DA8B-4c72-91A6-EBB4E0463537}_is1" = Backup & Storage v2.3.1.37683
"{4CE6C6E8-0DAD-4757-86ED-7FB4035BA98B}" = SMART Product Drivers
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.75
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 2.5.7
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E599D8-0D7C-411F-BC18-5B80F13DF968}" = ActivInspire Help (GBR) v1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7D7715C0-9C0F-3F08-D326-1C6268AC5530}" = ATI Catalyst Install Manager
"{7F57E0DE-D0F7-47CC-A4AB-D21EB8E4BE48}" = ActivInspire v1
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8B4CE9CA-ECB7-47D1-845E-E1167FFB3F1B}" = SMART Response Software
"{8D4B716A-0ABE-4238-9090-D208E5F57A5E}" = SMART Product Update
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{914CEAB8-B2B7-1CCB-D0D4-5C472EAD6AAC}" = CCC Help English
"{936E2131-D9DB-42F9-96E7-52D2050ACB09}" = ActivDriver x86 v5.7
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9550F8A6-3D21-4544-8B87-F9FE7E01B964}" = SMART Notebook
"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EDF1A5D-D8E0-413E-9782-75DD4A8C831B}" = VideoCam Suite 2.0
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AEM384L1-28E3-1232-1233-1JD74JDIEK32}_is1" = PDFTigerDriver
"{B45FABE7-D101-4D99-A671-E16DA40AF7F0}" = Microsoft Games for Windows - LIVE
"{B539E69D-DD59-457D-A926-CF01ACA6D04C}" = Microsoft Image Composite Editor
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7FB0C86-41A4-4402-9A33-912C462042A0}" = Roxio Creator 9 LE
"{BB071E36-0596-4919-A5B5-608BFFE8673A}_is1" = ZaZ GP4 Tools 1.26
"{BD31FF1E-088E-A139-C772-7A5777529042}" = Catalyst Control Center Graphics Previews Common
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2EBC2F1-B766-4AE3-A10C-6EBBC1EE3B02}" = Data Sync
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C7D27207-0F86-4B6F-859C-21800A2C592E}" = Grand Prix 4
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE246151-F0E8-ABC8-AEB2-7F3E188EFBF5}" = TweetDeck
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D1F94690-C59F-4BF1-A9C5-012DCCE8364D}_is1" = X2X Free Video Trim 2.0
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.26 Game
"{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DB078F4F-FC74-4A07-9E07-A6623A18A667}" = ActivInspire HWR Resources (ENU) v1
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DE252510-5687-4C60-A705-C43E19F12C9D}_is1" = PDFTiger Kernel
"{DEB7B7C6-C931-08C3-1059-60C0AF3FB781}" = ccc-utility
"{DEEDF1BA-ADD7-6EA0-D017-A89ACAD64E9F}" = ccc-core-static
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F943B1DF-711F-7D8E-3257-ED05026895E1}" = Catalyst Control Center InstallProxy
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon Kindle For PC" = Amazon Kindle For PC v1.1
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"AnvSoft Photo Flash Maker Professional" = AnvSoft Photo Flash Maker Professional 5.40
"Any Video Converter_is1" = Any Video Converter 3.0.4
"A-PDF Restrictions Remover_is1" = A-PDF Restrictions Remover 1.6
"Artensoft Photo Mosaic Wizard_is1" = Artensoft Photo Mosaic Wizard
"ASAP Utilities_is1" = ASAP Utilities
"Audacity_is1" = Audacity 1.2.6
"AVG" = AVG 2012
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Daniusoft MOD Converter_is1" = Daniusoft MOD Converter(Build [removed])
"Daniusoft Video Converter_is1" = Daniusoft Video Converter(Build 2.3.2.0)
"Debut" = Debut Video Capture Software
"DTGDesktop-Android" = Documents To Go Desktop for Android
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EA300 DVD-ROM" = EA300 DVD-ROM
"EaseUS Todo Backup Free 3.5_is1" = EaseUS Todo Backup Free 3.5
"Easy Watermark Studio3.1" = Easy Watermark Studio
"Exampro AA_MACO" = Exampro AQA GCE Core Mathematics
"Exampro AA_MAME" = Exampro AQA GCE Mechanics
"Exampro AA_MAST" = Exampro AQA GCE Statistics
"get_iplayer" = get_iplayer 4.2
"GPL Ghostscript 9.00" = GPL Ghostscript 9.00
"HandBrake" = HandBrake 0.9.5
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Hugin" = Hugin 2010.4.0
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"InfraRecorder" = InfraRecorder
"JPG2PDF_is1" = JPG2PDF 2.2
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lexmark 1200 Series" = Lexmark 1200 Series
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicScore_is1" = MagicScore
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Thunderbird (3.1.10)" = Mozilla Thunderbird (3.1.10)
"MPE" = MyPhoneExplorer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nectar Search Toolbar" = Nectar Search Toolbar
"Need For Speed High Stakes" = Need For Speed Road Challenge
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Opera 11.52.1100" = Opera 11.52
"Opera 12.00.1116" = Opera Next 12.00 alpha build 1116
"pdfsam" = pdfsam
"PDFTiger_is1" = PDFTiger
"ProcessLasso" = Process Lasso
"RealPlayer 12.0" = RealPlayer
"RealVNC_is1" = VNC Free Edition 4.1.3
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Shockwave" = Shockwave
"Sierra Utilities" = Sierra Utilities
"Simple Family Tree" = Simple Family Tree (remove only)
"Spotify" = Spotify
"Steam App 410" = Portal: First Slice
"Testbase UK_MT" = Testbase UKMT Challenge Questions
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 1.1.10
"Wdf01001" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 2.0.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{EE19063F-7048-4094-9A1D-D69D9C591119}_is1" = Albelli Photo books
"GeoGebra WebStart" = GeoGebra WebStart
"Google Chrome" = Google Chrome
"Spotify" = Spotify
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 03/12/2011 04:04:18 | Computer Name = DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application GPxPatch.exe, version 3.9.3.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 03/12/2011 08:48:15 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 08:49:00 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 08:58:06 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 09:03:02 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 09:47:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:03:44 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:05:11 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:14:59 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
Error - 03/12/2011 10:18:16 | Computer Name = DESKTOP | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Professional – Error 1706. No
valid source could be found for product Microsoft Office 2000 SR-1 Professional.
The Windows installer cannot continue.
[ OSession Events ]
Error - 02/01/2011 03:26:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 96
seconds with 60 seconds of active time. This session ended with a crash.
Error - 02/01/2011 03:27:38 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 29
seconds with 0 seconds of active time. This session ended with a crash.
Error - 03/06/2011 01:26:49 | Computer Name = USER-56FF5E3CA5 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 34 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 03/12/2011 13:10:40 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:10:54 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:13:34 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:14:36 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:14:38 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:16:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:17:46 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:19:31 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:21:05 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
Error - 03/12/2011 13:23:12 | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127
< End of report >